You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This came up in guacsec/guac#2366. This repo is not clear on the meaning of an empty version list. My colleague interpreted it as "there are no known malicious versions of this package." I understand it to mean "all versions are known malicious," for example the Python aiohtttps package, which is a typosquat. An explicit explanation would help consumers of this repo.
The text was updated successfully, but these errors were encountered:
These cases come from the earliest days of the project when version info wasn't attached to the sample names. Around 250 PyPI packages are affected. In these cases, your interpretation is correct: all versions should be considered malicious.
I have clarified this in the README in the linked PR.
This came up in guacsec/guac#2366. This repo is not clear on the meaning of an empty version list. My colleague interpreted it as "there are no known malicious versions of this package." I understand it to mean "all versions are known malicious," for example the Python aiohtttps package, which is a typosquat. An explicit explanation would help consumers of this repo.
The text was updated successfully, but these errors were encountered: