Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Question] Malware in com.google.external-dependency-manager? #525

Closed
Nezz opened this issue Jun 21, 2022 · 2 comments
Closed

[Question] Malware in com.google.external-dependency-manager? #525

Nezz opened this issue Jun 21, 2022 · 2 comments
Labels
needs-info Need information for the developer type: question

Comments

@Nezz
Copy link
Contributor

Nezz commented Jun 21, 2022

[READ] For Firebase Unity SDK question, please report to Firebase Unity Sample

Once you've read this section and determined that your issue is appropriate for this repository, please delete this section.

[REQUIRED] Please fill in the following fields:

  • Unity editor version: N/A
  • External Dependency Manager version: N/A
  • Source you installed EDM4U: Unity Package Manager
  • Features in External Dependency Manager in use: N/A
  • Plugins SDK in use: N/A
  • Platform you are using the Unity editor on: N/A

[REQUIRED] Please describe the question here:

We received the following security advisory:
GHSA-8h79-4gqv-44x8

Is this valid or a false positive?

@Nezz Nezz added new to be triaged type: question labels Jun 21, 2022
@paulinon paulinon removed the new to be triaged label Jun 21, 2022
@chkuang-g
Copy link
Collaborator

chkuang-g commented Jun 21, 2022

@Nezz

Thank you for reporting this.

First of all, I think this alert is for packages hosted on npm and we never officially push EDM4U to npm before.
I found these two packages:
https://www.npmjs.com/package/com.google.external-dependency-manager
https://www.npmjs.com/package/@playwind/com.google.external-dependency-manager
They are very likely published by third-party. I would not recommend to download packages from this channel unless you trust the publisher and accept the risk. The proper channel to download EDM4U is through this repo, or through Google API for Unity.

Secondly, it seems like this Github advisory database has a number of false-positive cases. github/advisory-database#419

In conclusion, if you are using the EDM4U from this repo, Google API for Unity or those included as part of Google SDKs, you should be good.

Does this answer your question?

@chkuang-g chkuang-g added the needs-info Need information for the developer label Jun 21, 2022
@Nezz
Copy link
Contributor Author

Nezz commented Jun 22, 2022

Thank you, that's the conclusion we came to as well.

@Nezz Nezz closed this as completed Jun 22, 2022
@googlesamples googlesamples locked and limited conversation to collaborators Jul 23, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
needs-info Need information for the developer type: question
Projects
None yet
Development

No branches or pull requests

3 participants