Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Corrections Needed for Several Malware Attributions #2729

Closed
behnazh-w opened this issue Oct 9, 2024 · 4 comments
Closed

Corrections Needed for Several Malware Attributions #2729

behnazh-w opened this issue Oct 9, 2024 · 4 comments
Labels
data quality Issues with data quality

Comments

@behnazh-w
Copy link

Describe the bug
As part of the Macaron package, we have identified several malicious Python packages in your records that have been incorrectly attributed to ReversingLabs as the FINDER. Two examples are the manyhttps and multiconnection packages. We are happy to provide confirmation emails from the PyPI security team for our reports. How can we share this information to update your records?

@hogo6002
Copy link
Contributor

hogo6002 commented Oct 9, 2024

Hi @behnazh-w, thanks for reporting!

OSV gets all malicious package information from upstream. To correct the record, could you please raise an issue there to provide feedback directly to the record's originator?

FAQ: https://google.github.io/osv.dev/faq/#ive-found-something-wrong-with-the-data

@hogo6002 hogo6002 added the data quality Issues with data quality label Oct 9, 2024
Copy link

github-actions bot commented Oct 9, 2024

✨ Thank you for your interest in OSV.dev's data quality! ✨

Please review our FAQ entry on how to most efficiently have this addressed.

@behnazh-w
Copy link
Author

Thank you, @hogo6002. I have opened an issue in the upstream repository: ossf/malicious-packages#660.

@hogo6002
Copy link
Contributor

hogo6002 commented Oct 9, 2024

Thanks Behnaz! Close this issue for now, feel free to reopen it if you have any other issues.

@hogo6002 hogo6002 closed this as completed Oct 9, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
data quality Issues with data quality
Projects
None yet
Development

No branches or pull requests

2 participants