-
Notifications
You must be signed in to change notification settings - Fork 502
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Detected as a virus in sandboxes #287
Comments
This program may have several features that could potentially be flagged as a virus:
In general, considering the above information, it's normal for this program to be falsely flagged as a virus. And as a non-profit project, without any income to support purchasing a certificate for trust establishment, I can only inform users that the code is fully open-source, you are free to review it, and Windows Defender scanning confirms that this program is not a virus. Additionally, the files uploaded to GitHub Release are generated by GitHub Workflow in the cloud. |
Thank you for such a detailed response! I need to learn to understand what all the av "signatures" mean so i can make decisions. |
Actually, I'm also quite confused about the certificate issue. Considering that Microsoft has acquired GitHub, I think some well-known GitHub repos, which use GitHub workflow to build programs, should receive certificates automatically signed by Microsoft. However, the reality is that currently, developers have to bear this cost themselves. This is also why there are many open-source programs on GitHub that, when downloaded, are flagged as risky and require confirmation. You can find similar discussions on some developer forums like Stack Overflow: https://stackoverflow.com/questions/77332719/how-do-i-get-a-valid-microsoft-store-code-signing-certificate. It's widely acknowledged that purchasing a certificate is necessary. Here's a certificate supplier website for reference: https://signmycode.com/authenticode-signing. In fact, many businesses rely on selling or acting as agents for certificates as their main source of profit. |
Ran the file through virustotal and had what seemed to be false-positives or heuristic detection so i ran it through sandboxes and both came back positive, but I'm no expert so they may just be necessary to build the application
https://www.hybrid-analysis.com/sample/54c633e07a285ef07fe4b68fb318738bdc84df36ea406cb0c454468958d92b5b/65c279928a733702df0f0d9b
https://metadefender.opswat.com/results/file/bzI0MDIxMXgxNHU5cDZpN0VMU2g3bURLTGRw/regular/sandbox/summary
The text was updated successfully, but these errors were encountered: