-
Notifications
You must be signed in to change notification settings - Fork 1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Deleted package detected #7
Comments
Thanks, But I Already have Secure the vidiopy project name on pypi. There fore it Could not be used by another. |
Deleted package names become available for use. An attacker can exploit this vulnerability and register a malicious package. |
Oh ok. This makes sense. Thanks for providing the details! I will close this issue. |
I'm a Cyber Security researcher and developer of PackjGuard [1] to address open-source software supply chain attacks.
Issue
During my research, I detected a deleted package in this repository.
Details
Specifically, the package
vidiopy
mentioned in fileREADME
at line 10 does not exist on the public PyPI registry. A bad actor can hijack this package to propagate malicious code.Impact
Not only your apps/services using
https://github.com/SohamTilekar/vidiopy
repo code are vulnerable to this attack, but the users of your open-source Github repo could also fall victim.You could read more about such attacks here: https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610
Remediation
Please highlight this in file README and register a placeholder package for
vidiopy
on public PyPI soon to remediate.To automatically fix such issues in future, please install PackjGuard Github app [1].
Thanks!
The text was updated successfully, but these errors were encountered: