pypa / pypa/setuptools

[BUG] Virus alarm for the .exe in the project

Open
#4,063 6 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug Needs Triage
Dominant language
Python
Stars
2.9k
Forks
1.4k
Avg merge
1d 1h
Merged PRs (30d)
1

Description

setuptools version

68.2.2

Python version

Python 3.11

OS

Windows

Additional environment information

No response

Description

When i scan the downloaded zip from master or last release 68.2.2 and scan the zip package or the different cli-.exe and gui-.exe directly, i have virus detection with virustotal.com, here are the results:
https://www.virustotal.com/gui/file/7b2e59ba9dab730c6aaa28ffb1f7a3a198e2bbb4330a974609b5193f1baeb212?nocache=1
https://www.virustotal.com/gui/file/32acc1bc543116cbe2cff10cb867772df2f254ff2634c870aef0b46c4b696fdb

I'm not so experienced with this case and worry now if the project/files are secure to execute?

Expected behavior

Expected no virus alarm.

How to Reproduce

Reproducable by re-scanning.

Output

Scanns:
https://www.virustotal.com/gui/file/7b2e59ba9dab730c6aaa28ffb1f7a3a198e2bbb4330a974609b5193f1baeb212?nocache=1
https://www.virustotal.com/gui/file/32acc1bc543116cbe2cff10cb867772df2f254ff2634c870aef0b46c4b696fdb

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the two VirusTotal reports and compare them against the downloaded master/release ZIP and the cli-.exe and gui-.exe artifacts. Trace how those Windows executables are produced or packaged in the setuptools release process. Done means the cause is identified and a safe-release change or confirmed false positive is recorded.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
release, security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.