From df08242029c4a0ab1ceeb60c5e03ef5c1290d48b Mon Sep 17 00:00:00 2001 From: github-actions Date: Sun, 24 Nov 2024 10:39:01 +0000 Subject: [PATCH] Assign IDs --- osv/malicious/.id-allocator | 2 +- ...analysis-0202389971fffa39.json => MAL-2024-10895.json} | 8 ++++---- 2 files changed, 5 insertions(+), 5 deletions(-) rename osv/malicious/pypi/some-random-package-33/{MAL-0000-ossf-package-analysis-0202389971fffa39.json => MAL-2024-10895.json} (65%) diff --git a/osv/malicious/.id-allocator b/osv/malicious/.id-allocator index 351b26779..56e5b06e1 100644 --- a/osv/malicious/.id-allocator +++ b/osv/malicious/.id-allocator @@ -1 +1 @@ -16988a45ad6e8dea78221d385cf2b8ad8e13aae91f8688eda776756e72357494 \ No newline at end of file +2e8d86e3c59f9463837b2b641aef9725886b5a4c981de1e33e7ef70dd9457f50 \ No newline at end of file diff --git a/osv/malicious/pypi/some-random-package-33/MAL-0000-ossf-package-analysis-0202389971fffa39.json b/osv/malicious/pypi/some-random-package-33/MAL-2024-10895.json similarity index 65% rename from osv/malicious/pypi/some-random-package-33/MAL-0000-ossf-package-analysis-0202389971fffa39.json rename to osv/malicious/pypi/some-random-package-33/MAL-2024-10895.json index a9445f518..536c25106 100644 --- a/osv/malicious/pypi/some-random-package-33/MAL-0000-ossf-package-analysis-0202389971fffa39.json +++ b/osv/malicious/pypi/some-random-package-33/MAL-2024-10895.json @@ -2,9 +2,9 @@ "modified": "2024-11-24T10:05:46Z", "published": "2024-11-24T10:05:46Z", "schema_version": "1.5.0", - "id": "", + "id": "MAL-2024-10895", "summary": "Malicious code in some-random-package-33 (PyPI)", - "details": "The OpenSSF Package Analysis project identified 'some-random-package-33' @ 2.3.100 (pypi) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n", + "details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: ossf-package-analysis (0202389971fffa3954690cc01ec76374424a1edd87f08ee6f80999f756cb13f6)\nThe OpenSSF Package Analysis project identified 'some-random-package-33' @ 2.3.100 (pypi) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n", "affected": [ { "package": { @@ -29,10 +29,10 @@ "database_specific": { "malicious-packages-origins": [ { - "source": "ossf-package-analysis", - "sha256": "0202389971fffa3954690cc01ec76374424a1edd87f08ee6f80999f756cb13f6", "import_time": "2024-11-24T10:37:24.312802987Z", "modified_time": "2024-11-24T10:05:46Z", + "sha256": "0202389971fffa3954690cc01ec76374424a1edd87f08ee6f80999f756cb13f6", + "source": "ossf-package-analysis", "versions": [ "2.3.100" ]