EleutherAI / EleutherAI/minetest-baselines
Dependency confusion supply-chain vulnerability detected
- Dominant language
- Python
- Stars
- 9
- Forks
- 2
- PR merge metrics
- No merged PRs in 30d
Description
Hi,
I'm a Cybersecurity researcher developing PackjGuard [1]. Our tool has detected a dependency confusion vulnerability in this repository. In order for me to disclose it, kindly enable GitHub Private vulnerability reporting, which allows security research to responsibly disclose a security vulnerability.
Thanks!
PackjGuard is a Github app that monitors repos for malicious, vulnerable, abandoned, and other "risky" dependencies and mitigates attacks by creating pull requests for automatic remediation https://github.com/marketplace/packjguard
Contributor guide
No contributing guide indexed for this repository
Research direction
No source file, test, or code entry point is named. Start by reviewing the dependency-confusion report and the repository's GitHub security settings; the issue is done only when private vulnerability reporting is enabled so the researcher can disclose the details.
Written by the indexing model from the issue text.
Assessment
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- Under an hour
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 15/100