From 6063a67b3818b16e06da0ab2f811b5c2020d547e Mon Sep 17 00:00:00 2001 From: github-actions Date: Mon, 6 Jan 2025 13:37:51 +0000 Subject: [PATCH] Assign IDs --- osv/malicious/.id-allocator | 2 +- ...ge-analysis-e9549d02a8179fe5.json => MAL-2025-21.json} | 8 ++++---- 2 files changed, 5 insertions(+), 5 deletions(-) rename osv/malicious/npm/tree-sitter-strings/{MAL-0000-ossf-package-analysis-e9549d02a8179fe5.json => MAL-2025-21.json} (69%) diff --git a/osv/malicious/.id-allocator b/osv/malicious/.id-allocator index f01fade58e..c25e35f848 100644 --- a/osv/malicious/.id-allocator +++ b/osv/malicious/.id-allocator @@ -1 +1 @@ -7ae3684e58511847ae20d3e0f99adce337f6edb32ee257290a734c3b04545cbb \ No newline at end of file +d292498d06ba2719d209a841509fcb4ece1a83d77532db39e987eafaf872f563 \ No newline at end of file diff --git a/osv/malicious/npm/tree-sitter-strings/MAL-0000-ossf-package-analysis-e9549d02a8179fe5.json b/osv/malicious/npm/tree-sitter-strings/MAL-2025-21.json similarity index 69% rename from osv/malicious/npm/tree-sitter-strings/MAL-0000-ossf-package-analysis-e9549d02a8179fe5.json rename to osv/malicious/npm/tree-sitter-strings/MAL-2025-21.json index 4068092547..f6de874d9c 100644 --- a/osv/malicious/npm/tree-sitter-strings/MAL-0000-ossf-package-analysis-e9549d02a8179fe5.json +++ b/osv/malicious/npm/tree-sitter-strings/MAL-2025-21.json @@ -2,9 +2,9 @@ "modified": "2025-01-06T13:36:13Z", "published": "2025-01-06T13:36:13Z", "schema_version": "1.5.0", - "id": "", + "id": "MAL-2025-21", "summary": "Malicious code in tree-sitter-strings (npm)", - "details": "The OpenSSF Package Analysis project identified 'tree-sitter-strings' @ 1.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n", + "details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: ossf-package-analysis (e9549d02a8179fe5a070281158b47ab35e7872770f13ca3de6929171c342ff5e)\nThe OpenSSF Package Analysis project identified 'tree-sitter-strings' @ 1.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n", "affected": [ { "package": { @@ -29,10 +29,10 @@ "database_specific": { "malicious-packages-origins": [ { - "source": "ossf-package-analysis", - "sha256": "e9549d02a8179fe5a070281158b47ab35e7872770f13ca3de6929171c342ff5e", "import_time": "2025-01-06T13:36:44.477552861Z", "modified_time": "2025-01-06T13:36:13Z", + "sha256": "e9549d02a8179fe5a070281158b47ab35e7872770f13ca3de6929171c342ff5e", + "source": "ossf-package-analysis", "versions": [ "1.0.0" ]