Skip to content
This repository was archived by the owner on Aug 26, 2025. It is now read-only.

include CM1002#13

Merged
matt-phylum merged 2 commits intomainfrom
matt/mal
Feb 11, 2025
Merged

include CM1002#13
matt-phylum merged 2 commits intomainfrom
matt/mal

Conversation

@matt-phylum
Copy link
Copy Markdown
Contributor

Since the latest release of the API, if a package is marked as malware by the OSSF MAL database we add an issue with a CM1002 tag. This has roughly the same meaning as CM0037, our internal tag for when we've marked something as malware, so I put it into the same rule.

Copy link
Copy Markdown
Contributor

@furi0us333 furi0us333 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I talked to research and we have reasonable confidence in the OSV data, so I think it makes sense to add it to this policy. However, I am noticing now that the original tag/metadata is incorrect. CM0037 is actually the malware binary and CM0038 is the verified malware. Can you please include the new tag with CM0038 and fix the metadata in this PR?

@furi0us333
Copy link
Copy Markdown
Contributor

Will we need to do anything to cause this to update across the platform?

@matt-phylum
Copy link
Copy Markdown
Contributor Author

Yes, because we never completed #8 somebody will need to run the deployment manually.

@matt-phylum matt-phylum merged commit 2e0eaab into main Feb 11, 2025
1 check passed
@matt-phylum
Copy link
Copy Markdown
Contributor Author

Deployed on prod:
image

@maxrake maxrake deleted the matt/mal branch February 11, 2025 15:27
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants