aboutcode-org / aboutcode-org/scancode.io

Add security-focused pipeline to scan for effective potential malware detection

Open
#1,070 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
215
Forks
203
Avg merge
4d 8h
Merged PRs (30d)
6

Description

Checking for the possible malware in the actual code would be awesome. This will complement the back-to-source binary analysis of software packages.

There are a few nice things we could add to such a pipeline:
- clamav of course
- https://github.com/DataDog/guarddog by @christophetd and team and is also behind this dataset https://github.com/nexB/vulnerablecode/issues/1406
- https://github.com/intel/cve-bin-tool by @terriko though this is more about package detection but it could complement nicely the work in VulnerableCode
- and likely a few more

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.