aboutcode-org / aboutcode-org/fetchcode

Report if a package is malicious or its version has been yanked

未關閉
#123 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
enhancement
主要語言
HTML
星號
13
分支
24
PR 合併指標
30 天內沒有已合併 PR

描述

### PyPI

- PyPI removes all traces of the `malicious` package.
- If a package version is deleted, it is properly marked as `yanked`. See the example https://pypi.org/pypi/apache-superset/json where version `2.1.1rc1` is marked as yanked.
- Discussion on an index for packages that have been entirely removed from PyPI: https://discuss.python.org/t/an-index-for-deleted-pypi-packages-versions/50515

### NPM

- Npm removes all versions of a `malicious` package from the index and provides a placeholder package version `0.0.1-security`. See the example https://registry.npmjs.org/gxm-reference-web-auth-server.
- Npm also allows unpublishing (yanking) a package version within 72 hours see https://docs.npmjs.com/unpublishing-packages-from-the-registry.

Related: https://github.com/aboutcode-org/vulnerablecode/pull/1533#discussion_r1716728423, https://github.com/aboutcode-org/vulnerablecode/pull/1533#discussion_r1724863110

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。