Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Consider adding sqlite, libpng, zlib, libjpeg, libarchive, zstd, openssh and busybox #42

Closed
bureado opened this issue Jan 11, 2022 · 2 comments

Comments

@bureado
Copy link

bureado commented Jan 11, 2022

I couldn't find any of these keywords in the "Critical Projects" sheet of the current spreadsheet, my apologies if I missed any.

  • SQLite has a longstanding claim to being the most widely deployed database and to being one of the most widely deployed components of any kind (they helpfully list libpng, zlib and libjpeg)
  • zstd and libarchive (which includes bsdtar, I believe) due to their centrality when it comes to the underlying archive manipulation of package managers and transports
  • I also couldn't find OpenSSH and would suggest that it is, not least by virtue of ssh signing: Add commit & tag signing/verification via SSH keys using ssh-keygen git/git#1041
  • busybox is a commonly found component not only in embedded but also in container images that can easily be overlooked

My rationale for suggesting this includes popularity and footprint across different scenarios (from embedded and mobile to legacy applications) as well as the centrality of these components in performing actions critical to trust.

@emaste
Copy link

emaste commented Feb 11, 2022

These all seem to me to be "obvious" candidates for inclusion. libarchive should also be a candidate based on previous vulnerabilities/exploits, see e.g. https://www.cvedetails.com/product/26168/Libarchive-Libarchive.html?vendor_id=12872, https://blog.malwarebytes.com/exploits-and-vulnerabilities/2022/01/update-now-microsoft-patches-97-bugs-including-6-zero-days-and-a-wormable-one/, etc.

@Amir-Montazery
Copy link
Contributor

These projects have been added to the candidates set for consideration. Voting, discussion, and feedback is open until 3/23/2023 for more suggestions. Thank you!
link: https://docs.google.com/spreadsheets/d/1ONZ4qeMq8xmeCHX03lIgIYE4MEXVfVL6oj05lbuXTDM/edit#gid=991730401

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants