Urgent.News

What's breaking now, across thousands of outlets.

Tech

How we took malware advisories beyond npm

GitHub malware advisories no longer stop at npm. Here's how we wired OpenSSF's malicious-packages data into the Advisory Database, and why we built the pipeline paranoid. The post How we took malware advisories beyond npm appeared first on The GitHub Blog .

GitHub has expanded malware advisories from npm to eight ecosystems by leveraging OpenSSF's malicious-packages data. Dependabot, the supply chain security tool, now flags malware in dependencies across npm, PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer. This expansion happened quickly thanks to OpenSSF's existing malicious-packages repository, which provides structured, openly available malicious package data.

The GitHub Advisory Database was updated to ingest this data, enabling the creation of malware advisories for all eight ecosystems. The import process involves validating OSV records against a strict schema and mapping required fields. The importer also handles various challenges such as differing ecosystem naming conventions, inconsistent version range formats, and empty details fields.

To prevent inadvertent reimportation of its own data, the importer skips records tagged from GitHub's own efforts. The ingestion pipeline includes safeguards for handling potential bad data, such as batch caps to halt runs with unusually high advisory volumes and provenance tracking for each advisory to trace back to its original upstream data source.

Written by urgent.news from GitHub Blog's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at github.blog →

More in Tech

BMW Executive in 2023: No Plans to Sell in-Vehicle Ads

Tanya Gazdik, reporting for MediaPost back in December 2023: Despite the ever-expanding screens in its vehicles, including an available 31-inch backseat theatre screen, BMW has no plans to sell…

  • BMW executive Stephan Durach states no plans to sell in-vehicle ads.
  • Car should remain private space, not for intrusive radio commercials.
  • Selling screen space for ads against core purpose of a car.

More from Thursday 6 August →