Skip to content

Commit

Permalink
Assign IDs
Browse files Browse the repository at this point in the history
  • Loading branch information
github-actions committed Dec 23, 2024
1 parent 098a6f7 commit 13e0359
Show file tree
Hide file tree
Showing 6 changed files with 67 additions and 131 deletions.
2 changes: 1 addition & 1 deletion osv/malicious/.id-allocator
Original file line number Diff line number Diff line change
@@ -1 +1 @@
0c0bcb6aba2e2893c7ae771e571ca34b4bc89846d342a356862a6bb6980760a6
e25c76020aa8b688ee402530f2679d2a1bc1874bf34c960d6f7e2d46604e156b

This file was deleted.

This file was deleted.

This file was deleted.

Original file line number Diff line number Diff line change
@@ -0,0 +1,62 @@
{
"modified": "2024-12-23T14:36:24Z",
"published": "2024-12-23T14:11:09Z",
"schema_version": "1.5.0",
"id": "MAL-2024-12107",
"summary": "Malicious code in bridge-transaction-parser-hop400 (npm)",
"details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: ossf-package-analysis (325dbc5a09889ad05c3dde97ba599380fb5066f5f321ca96aac263cda2f534d0)\nThe OpenSSF Package Analysis project identified 'bridge-transaction-parser-hop400' @ 1.2.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n",
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "bridge-transaction-parser-hop400"
},
"versions": [
"1.2.0",
"1.3.0",
"1.1.0"
]
}
],
"credits": [
{
"name": "OpenSSF: Package Analysis",
"type": "FINDER",
"contact": [
"https://github.com/ossf/package-analysis",
"https://openssf.slack.com/channels/package_analysis"
]
}
],
"database_specific": {
"malicious-packages-origins": [
{
"import_time": "2024-12-23T14:35:55.248088361Z",
"modified_time": "2024-12-23T14:18:26Z",
"sha256": "325dbc5a09889ad05c3dde97ba599380fb5066f5f321ca96aac263cda2f534d0",
"source": "ossf-package-analysis",
"versions": [
"1.2.0"
]
},
{
"import_time": "2024-12-23T14:35:55.389565898Z",
"modified_time": "2024-12-23T14:21:04Z",
"sha256": "9151894b697d03637e7a8a709911cdefdfbe7e12cf77e6b2187e9470eef75b5a",
"source": "ossf-package-analysis",
"versions": [
"1.3.0"
]
},
{
"import_time": "2024-12-23T14:35:55.243382223Z",
"modified_time": "2024-12-23T14:11:09Z",
"sha256": "ab233560a5bc73750c3e8c018a1ed9689cd7aa567918390c84db7c888f075dc8",
"source": "ossf-package-analysis",
"versions": [
"1.1.0"
]
}
]
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@
"modified": "2024-12-23T14:26:10Z",
"published": "2024-12-23T14:26:10Z",
"schema_version": "1.5.0",
"id": "",
"id": "MAL-2024-12108",
"summary": "Malicious code in wdio-common (npm)",
"details": "The OpenSSF Package Analysis project identified 'wdio-common' @ 1.1.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n",
"details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: ossf-package-analysis (00f5382329364054261d57de97042899750dc2b5fc91046c15c818fc794728df)\nThe OpenSSF Package Analysis project identified 'wdio-common' @ 1.1.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n",
"affected": [
{
"package": {
Expand All @@ -29,10 +29,10 @@
"database_specific": {
"malicious-packages-origins": [
{
"source": "ossf-package-analysis",
"sha256": "00f5382329364054261d57de97042899750dc2b5fc91046c15c818fc794728df",
"import_time": "2024-12-23T14:35:55.529455973Z",
"modified_time": "2024-12-23T14:26:10Z",
"sha256": "00f5382329364054261d57de97042899750dc2b5fc91046c15c818fc794728df",
"source": "ossf-package-analysis",
"versions": [
"1.1.0"
]
Expand Down

0 comments on commit 13e0359

Please sign in to comment.