What offends me is a "security scanner" for "ground truth" using fake checksums to verify integrity of its dependencies ;-)
https://github.com/TheAuditorTool/Auditor/commit/f77173a5517...
https://github.com/TheAuditorTool/Auditor/commit/f77173a5517...
That said? Did you the hash fail? Yes it did, security working as intended... Anything more to add? :)