Skip to content

Qinusty/package-analysis

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

97 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Package Analysis

This repo contains a few subprojects to aid in the analysis of open source packages, in particular to look for malicious software. This code is designed to work with the Package Feeds project, and originally started there.

These are:

Analysis to collect package behavior data and make it available publicly for researchers.

Scheduler to create jobs for Analysis based on the data from Feeds.

The goal is for all of these components to work together and provide extensible, community-run infrastructure to study behavior of open source packages and to look for malicious software. We also hope that the components can be used independently, to provide package feeds or runtime behavior data for anyone interested.

Contributing

If you want to get involved or have ideas you'd like to chat about, we discuss this project in the OSSF Securing Critical Projects Working Group meetings.

See the Community Calendar for the schedule and meeting invitations.

About

Open Source Package Analysis

Resources

License

Code of conduct

Security policy

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • Go 69.5%
  • Dockerfile 8.8%
  • Python 7.3%
  • Ruby 5.4%
  • Shell 5.1%
  • JavaScript 3.9%