OpenAPITools / OpenAPITools/openapi-generator

[Virus] SHA256 hash not matching?

Open
#13,033 3 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Issue: Bug
Dominant language
Java
Stars
26.8k
Forks
7.7k
PR merge metrics
PR metrics pending

Description

I just tried to build openapi tools and gradel prompted me if I wanted to trust downloading a file.

e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855

When checking this hash in google it comes up with hits related to ransomware.
Virus total says it isn't a hit but looking through comments and related posts it is related to ransome ware

https://otx.alienvault.com/indicator/file/e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855

https://www.virustotal.com/gui/file/e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855/community

I can see that the file on VT is 0kb is this fine a false negative?
Sorry couldn't use the template as this issue doesn't match the normal format

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No file or test is identified. Start by reproducing the OpenAPI Generator build and identifying the download associated with the reported SHA256 hash, then verify the downloaded file's size and source. Done means determining whether the zero-byte hash is expected or indicates a compromised artifact, and documenting the evidence.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, openapi
Domain
build-system, security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.