- Wollongong, Australia
-
16:39
- 11h ahead - @calebbrown
- in/calebbrown0
Pinned Loading
-
-
ossf/malicious-packages
ossf/malicious-packages PublicA repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) format.
-
google/osv-scanner
google/osv-scanner PublicVulnerability scanner written in Go which uses the data provided by https://osv.dev
390 contributions in the last year
Day of Week | March Mar | April Apr | May May | June Jun | July Jul | August Aug | September Sep | October Oct | November Nov | December Dec | January Jan | February Feb | March Mar | ||||||||||||||||||||||||||||||||||||||||
Sunday Sun | |||||||||||||||||||||||||||||||||||||||||||||||||||||
Monday Mon | |||||||||||||||||||||||||||||||||||||||||||||||||||||
Tuesday Tue | |||||||||||||||||||||||||||||||||||||||||||||||||||||
Wednesday Wed | |||||||||||||||||||||||||||||||||||||||||||||||||||||
Thursday Thu | |||||||||||||||||||||||||||||||||||||||||||||||||||||
Friday Fri | |||||||||||||||||||||||||||||||||||||||||||||||||||||
Saturday Sat |
Less
No contributions.
Low contributions.
Medium-low contributions.
Medium-high contributions.
High contributions.
More
Contribution activity
March 2025
Created 5 commits in 1 repository
Opened 2 pull requests in 1 repository
ossf/malicious-packages
2
merged
-
Add reports from Socket on Maven and Go malicious packages.
This contribution was made on Mar 20
-
Manually merge MAL-2023-41 merge since upstream was withdrawn.
This contribution was made on Mar 6
Reviewed 4 pull requests in 1 repository
ossf/malicious-packages
4 pull requests
-
Add two more black spammer PyPI packages
This contribution was made on Mar 25
-
Add black spammer packages
This contribution was made on Mar 21
-
Add report for 1 malicious PyPI package
This contribution was made on Mar 14
-
Report nyc-config package
This contribution was made on Mar 11
Created an issue in astral-sh/uv that received 1 comment
uv pip install does not conform to PEP-721
Summary
I was testing the behaviour of pip
and uv
when extracting a sdist package containing a symlink with an absolute path outside the destination.
1
comment