aboutcode-org / aboutcode-org/scancode.io
Add security-focused pipeline to scan for effective potential malware detection
Aberta
- Linguagem predominante
- Python
- Estrelas
- 215
- Forks
- 203
- Merge médio
- 4d 8h
- PRs com merge (30d)
- 6
Descrição
Checking for the possible malware in the actual code would be awesome. This will complement the back-to-source binary analysis of software packages.
There are a few nice things we could add to such a pipeline:
- clamav of course
- https://github.com/DataDog/guarddog by @christophetd and team and is also behind this dataset https://github.com/nexB/vulnerablecode/issues/1406
- https://github.com/intel/cve-bin-tool by @terriko though this is more about package detection but it could complement nicely the work in VulnerableCode
- and likely a few more
Guia de contribuição
Avaliação
Esta issue ainda não foi avaliada.