Skip to content

Commit

Permalink
Ingest OSV - Cloud Storage
Browse files Browse the repository at this point in the history
  • Loading branch information
github-actions committed Jan 22, 2025
1 parent 3ee9c01 commit 66cef72
Show file tree
Hide file tree
Showing 3 changed files with 85 additions and 1 deletion.
2 changes: 1 addition & 1 deletion config/start-keys.yaml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
ossf-package-analysis:
confident/: confident/20250120/050044-npm-bridge-transaction-parser-9.9.9.json
confident/: confident/20250120/121600-npm-showcase-server-9.9.9.json
reversing-labs:
RLMA-: RLMA-2024-11212.json
RLUA-: RLUA-2024-11114.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
{
"modified": "2025-01-22T13:56:11Z",
"published": "2025-01-22T13:56:11Z",
"schema_version": "1.5.0",
"id": "",
"summary": "Malicious code in canva-connect-api-starter-kit (npm)",
"details": "The OpenSSF Package Analysis project identified 'canva-connect-api-starter-kit' @ 9.0.8 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n",
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "canva-connect-api-starter-kit"
},
"versions": [
"9.0.8"
]
}
],
"credits": [
{
"name": "OpenSSF: Package Analysis",
"type": "FINDER",
"contact": [
"https://github.com/ossf/package-analysis",
"https://openssf.slack.com/channels/package_analysis"
]
}
],
"database_specific": {
"malicious-packages-origins": [
{
"source": "ossf-package-analysis",
"sha256": "fc0fdf9e640936880bce8400bdedeea86c50a3f199a443bec4c89154160e8f1d",
"import_time": "2025-01-22T14:05:39.154338515Z",
"modified_time": "2025-01-22T13:56:11Z",
"versions": [
"9.0.8"
]
}
]
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
{
"modified": "2025-01-22T13:56:01Z",
"published": "2025-01-22T13:56:01Z",
"schema_version": "1.5.0",
"id": "",
"summary": "Malicious code in mathworks.github.io (npm)",
"details": "The OpenSSF Package Analysis project identified 'mathworks.github.io' @ 9.9.9 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n",
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "mathworks.github.io"
},
"versions": [
"9.9.9"
]
}
],
"credits": [
{
"name": "OpenSSF: Package Analysis",
"type": "FINDER",
"contact": [
"https://github.com/ossf/package-analysis",
"https://openssf.slack.com/channels/package_analysis"
]
}
],
"database_specific": {
"malicious-packages-origins": [
{
"source": "ossf-package-analysis",
"sha256": "9c6573d76d8f5fdba92522227a99054a97637830368a2d6db580668ea6f38f22",
"import_time": "2025-01-22T14:05:38.950562063Z",
"modified_time": "2025-01-22T13:56:01Z",
"versions": [
"9.9.9"
]
}
]
}
}

0 comments on commit 66cef72

Please sign in to comment.