bazelbuild / bazelbuild/bazelisk

Windows detects bazelisk as a virus (again) in 1.21.0 for windows amd64

Open
#607 0 comments 0 reactions 0 assignees View on GitHub
P2
Dominant language
Go
Stars
2.7k
Forks
424
PR merge metrics
No merged PRs in 30d

Description

As before in #217 Windows is detecting "Trojan:Win32/Glupteba!ml" in bazelisk-windows-amd64.exe from https://github.com/bazelbuild/bazelisk/releases/tag/v1.21.0

SHA1: 054fb070c4644d85150155213992128fbd10bcea
MD5: 9b404e57d6f3c8a132a273ea84904573

VirusTotal reports that it's clean: https://www.virustotal.com/gui/url/9ed517065f2588d58fb75aca69e03a1761caa6bf370828c0565af8f0515c74d5?nocache=1

I tried reporting it at https://www.microsoft.com/en-us/wdsi/filesubmission but failed because I don't have enterprise support or something. It would be great if someone can push MS to update that threat signature to avoid this cropping up again and again.

Contributor guide

Open the contributing guide

Research direction

Review the prior report in #217 and the v1.21.0 release artifact bazelisk-windows-amd64.exe, starting with the supplied SHA1, MD5, and VirusTotal report. Confirm whether the detection is a false positive and whether the Microsoft submission route can be used; done means the Windows detection is addressed or the maintainer documents the concrete next step.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
devtools, release, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.