Ecosyste.ms: Issues

An open API service for providing issue and pull request metadata for open source projects.

GitHub / SAP/risk-explorer-for-software-supply-chains issues and pull requests

#51 - Revert "Bump hermes-engine and react-native"

Pull Request - State: closed - Opened by piergiorgioladisa about 2 years ago

#51 - Revert "Bump hermes-engine and react-native"

Pull Request - State: closed - Opened by piergiorgioladisa about 2 years ago

#50 - Bump hermes-engine and react-native

Pull Request - State: closed - Opened by piergiorgioladisa about 2 years ago

#50 - Bump hermes-engine and react-native

Pull Request - State: closed - Opened by piergiorgioladisa about 2 years ago

#49 - Added protestware reference

Pull Request - State: closed - Opened by henrikplate about 2 years ago

#49 - Added protestware reference

Pull Request - State: closed - Opened by henrikplate about 2 years ago

#48 - Feature: Change attack tree nodes according to the number of respective attacks

Issue - State: closed - Opened by henrikplate about 2 years ago - 1 comment
Labels: enhancement

#47 - Created new node Change Ethos

Pull Request - State: closed - Opened by henrikplate about 2 years ago - 1 comment

#47 - Created new node Change Ethos

Pull Request - State: closed - Opened by henrikplate about 2 years ago - 1 comment

#46 - Review classification of protestware

Issue - State: closed - Opened by henrikplate about 2 years ago - 2 comments

#46 - Review classification of protestware

Issue - State: closed - Opened by henrikplate about 2 years ago - 2 comments

#45 - Add new examples discussed in issue #39

Pull Request - State: closed - Opened by piergiorgioladisa about 2 years ago

#45 - Add new examples discussed in issue #39

Pull Request - State: closed - Opened by piergiorgioladisa about 2 years ago

#44 - Feature: Guided procedure to classify new attacks

Issue - State: open - Opened by henrikplate over 2 years ago
Labels: enhancement

#44 - Feature: Guided procedure to classify new attacks

Issue - State: open - Opened by henrikplate over 2 years ago
Labels: enhancement

#43 - Feature: Search for attacked packages

Issue - State: open - Opened by henrikplate over 2 years ago
Labels: enhancement

#43 - Feature: Search for attacked packages

Issue - State: open - Opened by henrikplate over 2 years ago
Labels: enhancement

#42 - Added phishing attack on PyPI to refs

Pull Request - State: closed - Opened by henrikplate over 2 years ago

#42 - Added phishing attack on PyPI to refs

Pull Request - State: closed - Opened by henrikplate over 2 years ago

#41 - Bump hermes-engine and react-native

Pull Request - State: closed - Opened by dependabot[bot] over 2 years ago - 1 comment
Labels: dependencies

#41 - Bump hermes-engine and react-native

Pull Request - State: closed - Opened by dependabot[bot] over 2 years ago - 1 comment
Labels: dependencies

#40 - Update references.json

Pull Request - State: closed - Opened by piergiorgioladisa over 2 years ago - 2 comments
Labels: documentation

#40 - Update references.json

Pull Request - State: closed - Opened by piergiorgioladisa over 2 years ago - 2 comments
Labels: documentation

#39 - Add new examples

Issue - State: closed - Opened by piergiorgioladisa over 2 years ago - 5 comments
Labels: documentation

#39 - Add new examples

Issue - State: closed - Opened by piergiorgioladisa over 2 years ago - 5 comments
Labels: documentation

#38 - Revert "Bump hermes-engine and react-native"

Pull Request - State: closed - Opened by piergiorgioladisa over 2 years ago

#38 - Revert "Bump hermes-engine and react-native"

Pull Request - State: closed - Opened by piergiorgioladisa over 2 years ago

#37 - Bump hermes-engine and react-native

Pull Request - State: closed - Opened by dependabot[bot] over 2 years ago
Labels: dependencies

#37 - Bump hermes-engine and react-native

Pull Request - State: closed - Opened by dependabot[bot] over 2 years ago
Labels: dependencies

#36 - Revert "Bump hermes-engine and react-native"

Pull Request - State: closed - Opened by piergiorgioladisa over 2 years ago

#36 - Revert "Bump hermes-engine and react-native"

Pull Request - State: closed - Opened by piergiorgioladisa over 2 years ago

#35 - Bump shell-quote from 1.6.1 to 1.7.3

Pull Request - State: closed - Opened by dependabot[bot] over 2 years ago - 1 comment
Labels: dependencies

#35 - Bump shell-quote from 1.6.1 to 1.7.3

Pull Request - State: closed - Opened by dependabot[bot] over 2 years ago - 1 comment
Labels: dependencies

#34 - Bump hermes-engine and react-native

Pull Request - State: closed - Opened by dependabot[bot] over 2 years ago
Labels: dependencies

#34 - Bump hermes-engine and react-native

Pull Request - State: closed - Opened by dependabot[bot] over 2 years ago
Labels: dependencies

#33 - Add Legend in the taxonomy

Pull Request - State: closed - Opened by piergiorgioladisa over 2 years ago - 1 comment
Labels: enhancement, wip

#33 - Add Legend in the taxonomy

Pull Request - State: closed - Opened by piergiorgioladisa over 2 years ago - 1 comment
Labels: enhancement, wip

#32 - Color coding of risk tree is unclear

Issue - State: closed - Opened by stephenjust over 2 years ago - 1 comment
Labels: enhancement, wip

#32 - Color coding of risk tree is unclear

Issue - State: closed - Opened by stephenjust over 2 years ago - 1 comment
Labels: enhancement, wip

#31 - Bump terser from 5.12.1 to 5.14.2

Pull Request - State: closed - Opened by dependabot[bot] over 2 years ago
Labels: dependencies

#31 - Bump terser from 5.12.1 to 5.14.2

Pull Request - State: closed - Opened by dependabot[bot] over 2 years ago
Labels: dependencies

#30 - Adding IconBurst NPM software supply chain attack example

Pull Request - State: closed - Opened by piergiorgioladisa over 2 years ago

#30 - Adding IconBurst NPM software supply chain attack example

Pull Request - State: closed - Opened by piergiorgioladisa over 2 years ago

#29 - Added new AV-208, Omitting scope or namespace

Pull Request - State: closed - Opened by henrikplate over 2 years ago

#29 - Added new AV-208, Omitting scope or namespace

Pull Request - State: closed - Opened by henrikplate over 2 years ago

#27 - The Debian OpenSSL Bug: Backdoor or Security Accident?

Issue - State: closed - Opened by henrikplate over 2 years ago - 1 comment

#27 - The Debian OpenSSL Bug: Backdoor or Security Accident?

Issue - State: closed - Opened by henrikplate over 2 years ago - 1 comment

#26 - New or existing attack vector "Omit scope/namespace"

Issue - State: closed - Opened by henrikplate over 2 years ago - 3 comments

#26 - New or existing attack vector "Omit scope/namespace"

Issue - State: closed - Opened by henrikplate over 2 years ago - 3 comments

#25 - Example for vulnerable Jenkins servers

Issue - State: closed - Opened by henrikplate over 2 years ago - 2 comments

#25 - Example for vulnerable Jenkins servers

Issue - State: closed - Opened by henrikplate over 2 years ago - 2 comments

#24 - Added more attacks on npm, Rust and PHP

Pull Request - State: closed - Opened by henrikplate over 2 years ago

#24 - Added more attacks on npm, Rust and PHP

Pull Request - State: closed - Opened by henrikplate over 2 years ago

#23 - Vulnerability in Git client

Issue - State: closed - Opened by henrikplate over 2 years ago - 2 comments

#23 - Vulnerability in Git client

Issue - State: closed - Opened by henrikplate over 2 years ago - 2 comments

#22 - Analyze and categorize attack on PyPI package ctx

Issue - State: closed - Opened by henrikplate over 2 years ago - 1 comment

#22 - Analyze and categorize attack on PyPI package ctx

Issue - State: closed - Opened by henrikplate over 2 years ago - 1 comment

#21 - Add new example of attack based on resurrection of accounts both for …

Pull Request - State: closed - Opened by piergiorgioladisa over 2 years ago - 2 comments

#21 - Add new example of attack based on resurrection of accounts both for …

Pull Request - State: closed - Opened by piergiorgioladisa over 2 years ago - 2 comments

#20 - Bump ejs from 3.1.6 to 3.1.8

Pull Request - State: closed - Opened by dependabot[bot] over 2 years ago
Labels: dependencies

#20 - Bump ejs from 3.1.6 to 3.1.8

Pull Request - State: closed - Opened by dependabot[bot] over 2 years ago
Labels: dependencies

#19 - Add Red-Lili example to attack tree

Pull Request - State: closed - Opened by piergiorgioladisa over 2 years ago

#19 - Add Red-Lili example to attack tree

Pull Request - State: closed - Opened by piergiorgioladisa over 2 years ago

#18 - Added ref to StarJacking

Pull Request - State: closed - Opened by henrikplate over 2 years ago

#18 - Added ref to StarJacking

Pull Request - State: closed - Opened by henrikplate over 2 years ago

#17 - Starjacking

Issue - State: closed - Opened by AnthonyHerman over 2 years ago - 2 comments

#17 - Starjacking

Issue - State: closed - Opened by AnthonyHerman over 2 years ago - 2 comments

#16 - Updated SG-032 (Isolation of Builds)

Pull Request - State: closed - Opened by henrikplate over 2 years ago

#16 - Updated SG-032 (Isolation of Builds)

Pull Request - State: closed - Opened by henrikplate over 2 years ago

#15 - Corrected typo in repo name

Pull Request - State: closed - Opened by henrikplate over 2 years ago

#15 - Corrected typo in repo name

Pull Request - State: closed - Opened by henrikplate over 2 years ago

#14 - Reuse compliance

Pull Request - State: closed - Opened by henrikplate over 2 years ago

#13 - Improved safeguard descriptions

Pull Request - State: closed - Opened by henrikplate over 2 years ago
Labels: wip

#13 - Improved safeguard descriptions

Pull Request - State: closed - Opened by henrikplate over 2 years ago
Labels: wip

#12 - Bump plist from 3.0.4 to 3.0.5

Pull Request - State: closed - Opened by dependabot[bot] over 2 years ago
Labels: dependencies

#12 - Bump plist from 3.0.4 to 3.0.5

Pull Request - State: closed - Opened by dependabot[bot] over 2 years ago
Labels: dependencies

#11 - Bump minimist from 1.2.5 to 1.2.6

Pull Request - State: closed - Opened by dependabot[bot] over 2 years ago
Labels: dependencies

#11 - Bump minimist from 1.2.5 to 1.2.6

Pull Request - State: closed - Opened by dependabot[bot] over 2 years ago
Labels: dependencies

#10 - Bump node-forge from 1.2.1 to 1.3.0

Pull Request - State: closed - Opened by dependabot[bot] over 2 years ago - 1 comment
Labels: dependencies

#10 - Bump node-forge from 1.2.1 to 1.3.0

Pull Request - State: closed - Opened by dependabot[bot] over 2 years ago - 1 comment
Labels: dependencies

#9 - Solved most of the warnings

Pull Request - State: closed - Opened by piergiorgioladisa over 2 years ago

#9 - Solved most of the warnings

Pull Request - State: closed - Opened by piergiorgioladisa over 2 years ago

#8 - Solved most of the warnings

Pull Request - State: closed - Opened by piergiorgioladisa over 2 years ago

#8 - Solved most of the warnings

Pull Request - State: closed - Opened by piergiorgioladisa over 2 years ago

#7 - Solved most of the warnings

Pull Request - State: closed - Opened by piergiorgioladisa over 2 years ago

#6 - Improved descr. of SG-004

Pull Request - State: closed - Opened by henrikplate over 2 years ago

#5 - More content improvements

Pull Request - State: closed - Opened by henrikplate over 2 years ago

#4 - Removed link column from ref table and small content improvements

Pull Request - State: closed - Opened by henrikplate over 2 years ago - 2 comments

#3 - Improved SG-040,041,043 and refs page

Pull Request - State: closed - Opened by henrikplate over 2 years ago - 1 comment

#2 - Typos and SG-038

Pull Request - State: closed - Opened by henrikplate over 2 years ago

#1 - Updated README, completed REUSE

Pull Request - State: closed - Opened by henrikplate over 2 years ago