Skip to content

Installation & uninstall updates - #89

Merged
Pasha Zayko (pasha-zayko) merged 4 commits into
publicfrom
main
Sep 15, 2026
Merged

Pasha Zayko (pasha-zayko) merged 4 commits into
publicfrom
main

Conversation

@jtdauria-shi

Copy link
Copy Markdown
Contributor

changelog:

  • Updated the installation guide and resources.
  • Added general uninstall procedure and moved Deploy uninstall guide.
  • Reorganized Break Glass documentation and navigation.

…v, & moved breakglass files into a break glass folder
…tallation-and-uninstall

installation updates, added uninstall guide, and other improvements
Copilot AI lite review requested due to automatic review settings September 15, 2026 19:59
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedzensical@​0.0.56 ⏵ 0.0.609710010010080

View full report

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
License policy violation: pypi zensical

License: Font-Awesome-Free-License-6.x - The applicable license policy does not permit this license (5) (zensical-0.0.60/python/zensical/templates/.icons/fontawesome/LICENSE.txt)

From: requirements.txt → pypi/zensical@0.0.60

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/zensical@0.0.60. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: pypi zensical

License: Font-Awesome-Free-License-6.x - The applicable license policy does not permit this license (5) (zensical/templates/.icons/fontawesome/LICENSE.txt)

From: requirements.txt → pypi/zensical@0.0.60

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/zensical@0.0.60. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: pypi zensical

License: Font-Awesome-Free-License-6.x - The applicable license policy does not permit this license (5) (zensical/templates/.icons/fontawesome/LICENSE.txt)

From: requirements.txt → pypi/zensical@0.0.60

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/zensical@0.0.60. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: pypi zensical

License: Font-Awesome-Free-License-6.x - The applicable license policy does not permit this license (5) (zensical/templates/.icons/fontawesome/LICENSE.txt)

From: requirements.txt → pypi/zensical@0.0.60

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/zensical@0.0.60. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: pypi zensical

License: Font-Awesome-Free-License-6.x - The applicable license policy does not permit this license (5) (zensical/templates/.icons/fontawesome/LICENSE.txt)

From: requirements.txt → pypi/zensical@0.0.60

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/zensical@0.0.60. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: pypi zensical

License: Font-Awesome-Free-License-6.x - The applicable license policy does not permit this license (5) (zensical/templates/.icons/fontawesome/LICENSE.txt)

From: requirements.txt → pypi/zensical@0.0.60

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/zensical@0.0.60. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: pypi zensical

License: Font-Awesome-Free-License-6.x - The applicable license policy does not permit this license (5) (zensical/templates/.icons/fontawesome/LICENSE.txt)

From: requirements.txt → pypi/zensical@0.0.60

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/zensical@0.0.60. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: pypi zensical

License: Font-Awesome-Free-License-6.x - The applicable license policy does not permit this license (5) (zensical/templates/.icons/fontawesome/LICENSE.txt)

From: requirements.txt → pypi/zensical@0.0.60

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/zensical@0.0.60. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: pypi zensical under unrecognized license

License: unrecognized license - This license was not allowed or given any lesser classification by the applicable policy (zensical/templates/assets/javascripts/LICENSE)

License: Font-Awesome-Free-License-6.x - The applicable license policy does not permit this license (5) (zensical/templates/.icons/fontawesome/LICENSE.txt)

From: requirements.txt → pypi/zensical@0.0.60

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/zensical@0.0.60. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: pypi zensical under unrecognized license

License: unrecognized license - This license was not allowed or given any lesser classification by the applicable policy (zensical/templates/assets/javascripts/LICENSE)

License: Font-Awesome-Free-License-6.x - The applicable license policy does not permit this license (5) (zensical/templates/.icons/fontawesome/LICENSE.txt)

From: requirements.txt → pypi/zensical@0.0.60

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/zensical@0.0.60. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Potential security risk (AI signal): pypi zensical is 74.0% likely risky

Notes: No explicit malware/backdoor/network exfiltration appears in this fragment. The primary supply-chain/security risk is configuration-driven dynamic importing and callable invocation (_resolve + resolve* helpers), which can become arbitrary code execution if an attacker can control configuration/theme settings. Additionally, YAML parsing uses yaml.load with a non-explicit safe loader (yaml.Loader), increasing risk from malicious YAML features/tags. Overall: likely dangerous in untrusted-config scenarios; otherwise, the risk is primarily build-time/code execution via config.

Confidence: 0.74

Severity: 0.78

From: requirements.txt → pypi/zensical@0.0.60

ℹ Read more on: This package | This alert | What are AI-detected potential security risks?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system identified potential security problems in this package. It is advised to review the package thoroughly and assess the potential risks before installation. You may also consider reporting the issue to the package maintainer or seeking alternative solutions with a stronger security posture.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/zensical@0.0.60. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Potential security risk (AI signal): pypi zensical is 74.0% likely risky

Notes: No explicit malware/backdoor/network exfiltration appears in this fragment. The primary supply-chain/security risk is configuration-driven dynamic importing and callable invocation (_resolve + resolve* helpers), which can become arbitrary code execution if an attacker can control configuration/theme settings. Additionally, YAML parsing uses yaml.load with a non-explicit safe loader (yaml.Loader), increasing risk from malicious YAML features/tags. Overall: likely dangerous in untrusted-config scenarios; otherwise, the risk is primarily build-time/code execution via config.

Confidence: 0.74

Severity: 0.78

From: requirements.txt → pypi/zensical@0.0.60

ℹ Read more on: This package | This alert | What are AI-detected potential security risks?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system identified potential security problems in this package. It is advised to review the package thoroughly and assess the potential risks before installation. You may also consider reporting the issue to the package maintainer or seeking alternative solutions with a stronger security posture.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/zensical@0.0.60. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Potential security risk (AI signal): pypi zensical is 74.0% likely risky

Notes: No explicit malware/backdoor/network exfiltration appears in this fragment. The primary supply-chain/security risk is configuration-driven dynamic importing and callable invocation (_resolve + resolve* helpers), which can become arbitrary code execution if an attacker can control configuration/theme settings. Additionally, YAML parsing uses yaml.load with a non-explicit safe loader (yaml.Loader), increasing risk from malicious YAML features/tags. Overall: likely dangerous in untrusted-config scenarios; otherwise, the risk is primarily build-time/code execution via config.

Confidence: 0.74

Severity: 0.78

From: requirements.txt → pypi/zensical@0.0.60

ℹ Read more on: This package | This alert | What are AI-detected potential security risks?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system identified potential security problems in this package. It is advised to review the package thoroughly and assess the potential risks before installation. You may also consider reporting the issue to the package maintainer or seeking alternative solutions with a stronger security posture.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/zensical@0.0.60. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Potential security risk (AI signal): pypi zensical is 74.0% likely risky

Notes: No explicit malware/backdoor/network exfiltration appears in this fragment. The primary supply-chain/security risk is configuration-driven dynamic importing and callable invocation (_resolve + resolve* helpers), which can become arbitrary code execution if an attacker can control configuration/theme settings. Additionally, YAML parsing uses yaml.load with a non-explicit safe loader (yaml.Loader), increasing risk from malicious YAML features/tags. Overall: likely dangerous in untrusted-config scenarios; otherwise, the risk is primarily build-time/code execution via config.

Confidence: 0.74

Severity: 0.78

From: requirements.txt → pypi/zensical@0.0.60

ℹ Read more on: This package | This alert | What are AI-detected potential security risks?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system identified potential security problems in this package. It is advised to review the package thoroughly and assess the potential risks before installation. You may also consider reporting the issue to the package maintainer or seeking alternative solutions with a stronger security posture.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/zensical@0.0.60. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates SHIELD installation, uninstall, Break Glass, navigation, and Microsoft Insights documentation.

Changes:

  • Adds general and Deploy-specific uninstall guidance.
  • Reorganizes Break Glass documentation and navigation.
  • Updates installation content, links, formatting, and the Zensical dependency.

Reviewed changes

Copilot reviewed 6 out of 9 changed files in this pull request and generated 3 comments.

Show a summary per file
File Summary
zensical.toml Updates documentation navigation.
requirements.txt Updates the Zensical dependency.
docs/SHIELD/Reference/Uninstall.md Adds general SHIELD cleanup steps.
docs/SHIELD/Reference/Break-Glass/Register-Break-Glass.md Updates Break Glass guidance and wording.
docs/SHIELD/Reference/Break-Glass/Break-Glass-Overview.md Reorganizes and expands Break Glass guidance.
docs/SHIELD/Prerequisites/Installation.md Refreshes installation instructions.
docs/SHIELD/Deploy/Troubleshooting.md Updates the uninstall guide link.
docs/SHIELD/Deploy/Reference/Uninstall.md Adds the Deploy uninstall procedure.
docs/Microsoft-Insights/Usage-Guide.md Adjusts list formatting.
Suppressed comments (5)

docs/SHIELD/Deploy/Reference/Uninstall.md:17

  • This reminder says redeployment will not lose Microsoft cloud data, but the procedure below explicitly removes Entra groups and Intune scope tags. Clarify that redeployment preserves the stateless app only; the SHIELD-managed tenant objects are deleted by this cleanup.
    SHIELD's application server is stateless. You can safely redeploy the app after cleanup without losing data stored in the Microsoft cloud (e.g., Intune tags, Entra groups).

docs/SHIELD/Deploy/Reference/Uninstall.md:45

  • The script requires PowerShell Core (#Requires -PSEdition Core) and is documented as tested with PowerShell 7, but this procedure never tells the operator which runtime to use. Running it from Windows PowerShell 5.1 will fail before cleanup starts; call out PowerShell 7 before this step.
1. **Run the uninstall script** to remove SHIELD-deployed infrastructure.

docs/SHIELD/Reference/Break-Glass/Register-Break-Glass.md:17

  • “Before preceding with the below” is a typo and makes the warning awkward to follow; it should say “before proceeding with the steps below.”
    docs/SHIELD/Reference/Uninstall.md:75
  • The introduction promises validation that all applications and groups were removed, but the final checklist only verifies applications and Azure resources. It does not verify the tenant-level groups, Intune scope tags, or Conditional Access policies removed by the linked Deploy uninstall procedure; add those checks or narrow the promise.

- Confirm the SHIELD resource group is fully removed
- Confirm the SHIELD web app no longer exists in Azure App Services
- Confirm the Azure Subscription dedicated for SHIELD has been canceled
- Confirm there are no SHIELD‑related applications in Entra ID

docs/SHIELD/Reference/Uninstall.md:64

  • This section says uninstalling SHIELD Desktop is an optional step, but it only lists where the app may be installed and provides no uninstall procedure or link for either a local machine or an Azure VM. Add the platform-specific steps or link to them so readers can complete and verify this part of the decommissioning flow.
If you installed SHIELD using the SHIELD Desktop application, you can uninstall it after SHIELD Discover is complete. SHIELD Desktop is no longer required after reporting is finalized. This applies whether the app was installed on:

- A local machine
- An Azure VM

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread docs/SHIELD/Deploy/Reference/Uninstall.md
Comment thread docs/SHIELD/Reference/Uninstall.md
Comment thread docs/SHIELD/Reference/Uninstall.md
@pasha-zayko
Pasha Zayko (pasha-zayko) merged commit 8fd38d4 into public Sep 15, 2026
12 checks passed

This branch was successfully deployed

1 active deployment
Azure-Alpha — 9a803903 Deployed Sep 14, 2026 by pasha-zayko via Deploy to Azure Static App #26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants