Skip to content

Commit 732dc08

Browse files
author
github-actions
committed
Ingest OSV - Cloud Storage
1 parent 61a26be commit 732dc08

4 files changed

Lines changed: 124 additions & 1 deletion

File tree

config/start-keys.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ kam193:
55
pypi/packages/pentest/osv/: 0d65fa30569acb74a4cd2f6968297f9cf794b510
66
pypi/packages/probably_pentest/osv/: 3c0b4471068a099c7f364abeff0bb1d3a9a3a6fd
77
ossf-package-analysis:
8-
confident/: confident/20260831/091413-npm-fuels-typegen-1.0.0.json
8+
confident/: confident/20260831/091417-npm-generate-schema-viem-1.0.0.json
99
reversing-labs:
1010
RLMA-: RLMA-2026-05643.json
1111
RLUA-: RLUA-2026-05628.json
Lines changed: 41 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,41 @@
1+
{
2+
"schema_version": "1.7.4",
3+
"published": "2026-08-31T18:05:48Z",
4+
"modified": "2026-08-31T18:05:48Z",
5+
"summary": "Malicious code in evilpostinstall (npm)",
6+
"details": "The OpenSSF Package Analysis project identified 'evilpostinstall' @ 0.2.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package executes one or more commands associated with malicious behavior.\n",
7+
"affected": [
8+
{
9+
"package": {
10+
"name": "evilpostinstall",
11+
"ecosystem": "npm"
12+
},
13+
"versions": [
14+
"0.2.0"
15+
]
16+
}
17+
],
18+
"database_specific": {
19+
"malicious-packages-origins": [
20+
{
21+
"import_time": "2026-09-01T00:57:09.116943582Z",
22+
"modified_time": "2026-08-31T18:05:48Z",
23+
"sha256": "29ef31366374537cb5c06da575916f1a0a0494e63df3ce4ea9d06a685f4f3bb1",
24+
"source": "ossf-package-analysis",
25+
"versions": [
26+
"0.2.0"
27+
]
28+
}
29+
]
30+
},
31+
"credits": [
32+
{
33+
"name": "OpenSSF: Package Analysis",
34+
"contact": [
35+
"https://github.com/ossf/package-analysis",
36+
"https://openssf.slack.com/channels/package_analysis"
37+
],
38+
"type": "FINDER"
39+
}
40+
]
41+
}
Lines changed: 41 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,41 @@
1+
{
2+
"schema_version": "1.7.4",
3+
"published": "2026-08-31T18:25:54Z",
4+
"modified": "2026-08-31T18:25:54Z",
5+
"summary": "Malicious code in evilpostinstall (npm)",
6+
"details": "The OpenSSF Package Analysis project identified 'evilpostinstall' @ 0.6.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package executes one or more commands associated with malicious behavior.\n",
7+
"affected": [
8+
{
9+
"package": {
10+
"name": "evilpostinstall",
11+
"ecosystem": "npm"
12+
},
13+
"versions": [
14+
"0.6.0"
15+
]
16+
}
17+
],
18+
"database_specific": {
19+
"malicious-packages-origins": [
20+
{
21+
"import_time": "2026-09-01T00:57:09.187843174Z",
22+
"modified_time": "2026-08-31T18:25:54Z",
23+
"sha256": "63c1e371381b8007f9f6c3347d20061d0d2e4d391ad366c6478c153056f49e32",
24+
"source": "ossf-package-analysis",
25+
"versions": [
26+
"0.6.0"
27+
]
28+
}
29+
]
30+
},
31+
"credits": [
32+
{
33+
"name": "OpenSSF: Package Analysis",
34+
"contact": [
35+
"https://github.com/ossf/package-analysis",
36+
"https://openssf.slack.com/channels/package_analysis"
37+
],
38+
"type": "FINDER"
39+
}
40+
]
41+
}
Lines changed: 41 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,41 @@
1+
{
2+
"schema_version": "1.7.4",
3+
"published": "2026-08-31T15:40:53Z",
4+
"modified": "2026-08-31T15:40:53Z",
5+
"summary": "Malicious code in evilpostinstall (npm)",
6+
"details": "The OpenSSF Package Analysis project identified 'evilpostinstall' @ 4127000.0.1 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package executes one or more commands associated with malicious behavior.\n",
7+
"affected": [
8+
{
9+
"package": {
10+
"name": "evilpostinstall",
11+
"ecosystem": "npm"
12+
},
13+
"versions": [
14+
"4127000.0.1"
15+
]
16+
}
17+
],
18+
"database_specific": {
19+
"malicious-packages-origins": [
20+
{
21+
"import_time": "2026-09-01T00:57:09.042147024Z",
22+
"modified_time": "2026-08-31T15:40:53Z",
23+
"sha256": "c4f0004a363677a7dc0429c4cf4bacafcd3bbdab0c95e1e7851d44b543d7e486",
24+
"source": "ossf-package-analysis",
25+
"versions": [
26+
"4127000.0.1"
27+
]
28+
}
29+
]
30+
},
31+
"credits": [
32+
{
33+
"name": "OpenSSF: Package Analysis",
34+
"contact": [
35+
"https://github.com/ossf/package-analysis",
36+
"https://openssf.slack.com/channels/package_analysis"
37+
],
38+
"type": "FINDER"
39+
}
40+
]
41+
}

0 commit comments

Comments
 (0)