aboutcode-org / aboutcode-org/scancode.io
Add security-focused pipeline to scan for effective potential malware detection
Ouverte
- Langage dominant
- Python
- Étoiles
- 215
- Forks
- 203
- Merge moyen
- 4 j 8 h
- PR mergées (30 j)
- 6
Description
Checking for the possible malware in the actual code would be awesome. This will complement the back-to-source binary analysis of software packages.
There are a few nice things we could add to such a pipeline:
- clamav of course
- https://github.com/DataDog/guarddog by @christophetd and team and is also behind this dataset https://github.com/nexB/vulnerablecode/issues/1406
- https://github.com/intel/cve-bin-tool by @terriko though this is more about package detection but it could complement nicely the work in VulnerableCode
- and likely a few more
Guide de contribution
Ouvrir le guide de contribution
Évaluation
Cette issue n'a pas encore été évaluée.