lllyasviel / lllyasviel/FramePack

In case anyone was wondering about the sussy base85 encoded content in get-pip.py

Open
#51 5 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
17.3k
Forks
1.7k
PR merge metrics
No merged PRs in 30d

Description

It seems to come from this legitimate repo https://github.com/pypa/get-pip
However I was not able to match any of the files in the repo with the sha256 checksum from the file in this repo.
So I decoded it.

Here it is:
https://www.virustotal.com/gui/file/fa7dea492a3c169b677d332ef1b5b3924bcf5828308be5d1c5bcb23110a00eb7/details

[extracted_pip.zip](https://github.com/user-attachments/files/19809856/extracted_pip.zip)

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with get-pip.py and the linked pypa/get-pip repository, then inspect the reported SHA-256 mismatch and the extracted_pip.zip attachment. Compare the encoded content with the referenced repository and document whether the file is expected or requires a security response.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.