False positive: GHSA-hpcx-pg6g-x697 flags legitimate astro@7.1.0 as malware
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 45/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Tranquilla
- Stack tecnologico
- javascript
- Ambito
- security
Direzione di ricerca
Inizia esaminando il record GHSA, la PR 1383 collegata di malicious-packages e le prove di provenienza per astro@7.1.0, incluso .github/workflows/release.yml. Il lavoro è completato quando il database degli advisory conferma il falso positivo e ritira l’advisory come richiesto.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
GHSA-hpcx-pg6g-x697 classifies the official astro@7.1.0 release as registry
impersonation malware. This is a false positive, and the upstream source has
already retracted it.
Evidence:
-
The source entry (OSSF malicious-packages MAL-2026-10726) was removed as a
false positive on 2026-07-22 via
https://github.com/ossf/malicious-packages/pull/1383 — five days before this
GHSA was published. -
astro@7.1.0 carries valid SLSA provenance tying the tarball to the
withastro/astro GitHub Actions release workflow
(.github/workflows/release.yml), published by the project's actual
maintainers on 2026-07-16. The astro@7.1.0 git tag exists upstream. -
The advisory's own premise is outdated: it states Astro "is on the v5.x
line". That was true in early 2025. Astro is currently on 7.1.x, with 7.1.6
published as of 2026-07-29. -
The flagged dependencies are not typosquats. piccolore is maintained by
delucis (Chris Swithinbank, Astro core maintainer, Starlight lead) and obug
by sxzz (Kevin Deng, Vue core team). Both are clean: no network, no
filesystem access, no child_process, no install scripts. -
npm has not unpublished or deprecated the package, and six further releases
have shipped since.
Requesting this advisory be withdrawn to match the upstream retraction.
- Lingua principale
- Nessun dato sulla lingua
- Stelle
- 2.5k
- Fork
- 772
- Merge medio
- 3g 18h
- PR unite (30g)
- 48
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di github/advisory-database
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
github/advisory-database#9255 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
github/advisory-database#9164 · 1 reazione ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
github/advisory-database#8994 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
github/advisory-database#8898 · 4 commenti · 1 reazione ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
github/advisory-database#8841 ·
Tutte le issue di github/advisory-database
Issue simili
-
enhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
canonical/paas-charm#368 · 1 commento ·
-
enhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
palladius/rails8-app-on-gcp#142 ·
-
addition to tracking list Aperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
StevenBlack/hosts#3256 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
corsairdev/corsair#1764 ·
-
oblt-aw/detector/security
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100