Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Issue: Typosquatting #71526

Closed
YoSTEALTH mannequin opened this issue Jun 16, 2016 · 2 comments
Closed

Security Issue: Typosquatting #71526

YoSTEALTH mannequin opened this issue Jun 16, 2016 · 2 comments

Comments

@YoSTEALTH
Copy link
Mannequin

YoSTEALTH mannequin commented Jun 16, 2016

BPO 27339
Nosy @vstinner, @YoSTEALTH

Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.

Show more details

GitHub fields:

assignee = None
closed_at = <Date 2016-06-16.21:43:14.845>
created_at = <Date 2016-06-16.20:16:06.722>
labels = []
title = 'Security Issue: Typosquatting'
updated_at = <Date 2016-06-16.21:43:14.843>
user = 'https://github.com/YoSTEALTH'

bugs.python.org fields:

activity = <Date 2016-06-16.21:43:14.843>
actor = 'vstinner'
assignee = 'none'
closed = True
closed_date = <Date 2016-06-16.21:43:14.845>
closer = 'vstinner'
components = []
creation = <Date 2016-06-16.20:16:06.722>
creator = 'YoSTEALTH'
dependencies = []
files = []
hgrepos = []
issue_num = 27339
keywords = []
message_count = 2.0
messages = ['268692', '268701']
nosy_count = 2.0
nosy_names = ['vstinner', 'YoSTEALTH']
pr_nums = []
priority = 'normal'
resolution = 'third party'
stage = None
status = 'closed'
superseder = None
type = None
url = 'https://bugs.python.org/issue27339'
versions = []

@YoSTEALTH
Copy link
Mannequin Author

YoSTEALTH mannequin commented Jun 16, 2016

I read this new article that explains Typosquatting well: http://incolumitas.com/2016/06/08/typosquatting-package-managers/ making it known here so python developers can address this issue accordingly!

@vstinner
Copy link
Member

Hum, I guess that you are talking about https://pypi.python.org/pypi ? If yes, you should open an issue in their bug tracker:
https://bitbucket.org/pypa/pypi/issues

By the way, I don't see any obvious fix for typo squatting.

@ezio-melotti ezio-melotti transferred this issue from another repository Apr 10, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant