Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

False positive: GHSA-hpcx-pg6g-x697 flags legitimate astro@7.1.0 as malware

オープン
#8,871 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
45/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
静か
技術スタック
javascript
領域
security

調査の方向性

まず、GHSAレコード、リンクされているmalicious-packagesのPR 1383、およびastro@7.1.0のプロヴェナンス証拠(.github/workflows/release.ymlを含む)を確認します。アドバイザリデータベースが誤検知を確認し、要求どおりアドバイザリを撤回した時点で完了です。

索引モデルが issue の本文から書いたものです。

説明

GHSA-hpcx-pg6g-x697 classifies the official astro@7.1.0 release as registry
impersonation malware. This is a false positive, and the upstream source has
already retracted it.

Evidence:

  1. The source entry (OSSF malicious-packages MAL-2026-10726) was removed as a
    false positive on 2026-07-22 via
    https://github.com/ossf/malicious-packages/pull/1383 — five days before this
    GHSA was published.

  2. astro@7.1.0 carries valid SLSA provenance tying the tarball to the
    withastro/astro GitHub Actions release workflow
    (.github/workflows/release.yml), published by the project's actual
    maintainers on 2026-07-16. The astro@7.1.0 git tag exists upstream.

  3. The advisory's own premise is outdated: it states Astro "is on the v5.x
    line". That was true in early 2025. Astro is currently on 7.1.x, with 7.1.6
    published as of 2026-07-29.

  4. The flagged dependencies are not typosquats. piccolore is maintained by
    delucis (Chris Swithinbank, Astro core maintainer, Starlight lead) and obug
    by sxzz (Kevin Deng, Vue core team). Both are clean: no network, no
    filesystem access, no child_process, no install scripts.

  5. npm has not unpublished or deprecated the package, and six further releases
    have shipped since.

Requesting this advisory be withdrawn to match the upstream retraction.

主要言語
言語のデータがありません
スター
2.5k
フォーク
772
平均マージ
3日 15時間
マージ済み PR(30日)
46

コントリビューションガイド

コントリビューションガイドを開く

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

github/advisory-database のほかの issue

github/advisory-database の issue をすべて見る

似ている issue

Security の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。