Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Risk audit improvements #313

Merged
merged 14 commits into from
Jun 16, 2024
Merged

Risk audit improvements #313

merged 14 commits into from
Jun 16, 2024

Conversation

prabhu
Copy link
Member

@prabhu prabhu commented Jun 11, 2024

Based on #311 but supports more.

Detecting slsa attestations

biome

binary blob detection for npm

sqlite3-2
sqlite3
fsevents-binary

Signed-off-by: Prabhu Subramanian <prabhu@appthreat.com>
Signed-off-by: Prabhu Subramanian <prabhu@appthreat.com>
@prabhu prabhu marked this pull request as draft June 11, 2024 15:53
prabhu added 10 commits June 12, 2024 09:55
Signed-off-by: Prabhu Subramanian <prabhu@appthreat.com>
Signed-off-by: Prabhu Subramanian <prabhu@appthreat.com>
Signed-off-by: Prabhu Subramanian <prabhu@appthreat.com>
Signed-off-by: Prabhu Subramanian <prabhu@appthreat.com>
Signed-off-by: Prabhu Subramanian <prabhu@appthreat.com>
Signed-off-by: Prabhu Subramanian <prabhu@appthreat.com>
Signed-off-by: Prabhu Subramanian <prabhu@appthreat.com>
Signed-off-by: Prabhu Subramanian <prabhu@appthreat.com>
Signed-off-by: Prabhu Subramanian <prabhu@appthreat.com>
Signed-off-by: Prabhu Subramanian <prabhu@appthreat.com>
@prabhu prabhu marked this pull request as ready for review June 13, 2024 10:55
@prabhu prabhu requested a review from cerrussell June 13, 2024 10:56
@prabhu prabhu changed the title Feature/default risk audit v6 Risk audit improvements Jun 13, 2024
Signed-off-by: Prabhu Subramanian <prabhu@appthreat.com>
@prabhu
Copy link
Member Author

prabhu commented Jun 13, 2024

More test cases

pkg:npm/mknod@1.1.0
pkg:npm/zmq-prebuilt@2.1.0
pkg:npm/zeromq@6.0.0-beta.19
pkg:npm/node-duckdb@0.0.79
pkg:npm/registry-js@1.3.3-patch1
pkg:npm/node-libcurl@4.0.0
pkg:npm/gpt4all@4.0.0

Signed-off-by: Prabhu Subramanian <prabhu@appthreat.com>
@prabhu prabhu merged commit 8a3cb9c into master Jun 16, 2024
25 checks passed
@prabhu prabhu deleted the feature/default-risk-audit-v6 branch June 16, 2024 11:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant