ossf / ossf/osv-schema

Entries about malicious packages not in "MAL-" namespace

Open
#348 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Go
Stars
271
Forks
129
Avg merge
3h 46m
Merged PRs (30d)
4

Description

Hello, and first of all, thanks for all the amazing work you do for the community.

I identified several entries related to malicious PyPI packages that are not in the "MAL-" namespace:

PYSEC-2025-3
PYSEC-2025-4
PYSEC-2025-5
PYSEC-2025-6
PYSEC-2025-7
PYSEC-2025-8
PYSEC-2022-199
PYSEC-2024-152

It is a bit tricky to keep track of this unique type of vulnerability entries (Malicious packages) when they are not in that namespace.
Should these entries have assigned a new "MAL-" ID? Or should a new field be added to the schema indicating this type of risk?

Looking forward you thoughts!

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the eight listed PYSEC entries and the existing schema conventions for vulnerability identifiers and metadata. Compare the proposed MAL- namespace with adding a field for malicious-package risk. Done means the project has a decided, documented representation and the affected entries follow it.

Written by the indexing model from the issue text.

Assessment

Domain
backend-api-design, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.