aboutcode-org / aboutcode-org/scancode.io

Add security-focused pipeline to scan for effective potential malware detection

未關閉
#1,070 2 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
Python
星號
215
分支
203
平均合併
4 天 8 小時
30 天內合併 PR
6

描述

Checking for the possible malware in the actual code would be awesome. This will complement the back-to-source binary analysis of software packages.

There are a few nice things we could add to such a pipeline:
- clamav of course
- https://github.com/DataDog/guarddog by @christophetd and team and is also behind this dataset https://github.com/nexB/vulnerablecode/issues/1406
- https://github.com/intel/cve-bin-tool by @terriko though this is more about package detection but it could complement nicely the work in VulnerableCode
- and likely a few more

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。