{"id":52757,"date":"2019-11-16T00:00:00","date_gmt":"2019-11-15T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po"},"modified":"2020-02-18T14:00:33","modified_gmt":"2020-02-18T11:00:33","slug":"github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/novosti-interneta\/github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po","title":{"rendered":"GitHub hat ein gemeinsames Projekt zur Identifizierung von Schwachstellen in Open-Source-Software gestartet","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>GitHub <noindex><a rel=\"nofollow\" href=\"https:\/\/github.blog\/2019-11-14-announcing-github-security-lab-securing-the-worlds-code-together\/\">trat<\/a><\/noindex> mit der Initiative  <noindex><a rel=\"nofollow\" href=\"https:\/\/securitylab.github.com\/\">GitHub Security Lab<\/a><\/noindex>, die darauf abzielt, die Zusammenarbeit von Sicherheitsexperten aus verschiedenen Unternehmen und Organisationen zu f\u00f6rdern, um Schwachstellen zu identifizieren und bei deren Behebung im Code von Open-Source-Projekten zu helfen.  <\/p>\n<p>Alle interessierten Unternehmen und Einzelpersonen im Bereich der Computersicherheit sind eingeladen, sich an der Initiative zu beteiligen. F\u00fcr die Entdeckung von Schwachstellen  <noindex><a rel=\"nofollow\" href=\"https:\/\/securitylab.github.com\/bounties\">wird<\/a><\/noindex> eine Belohnung von bis zu 3000 Dollar ausgezahlt, abh\u00e4ngig von der Schwere des Problems und der Qualit\u00e4t des Berichts. Um Informationen \u00fcber Probleme einzureichen, wird ein Tool vorgeschlagen <noindex><a rel=\"nofollow\" href=\"https:\/\/securitylab.github.com\/tools\/codeql\">CodeQL<\/a><\/noindex>, das es erm\u00f6glicht, Vorlagen f\u00fcr anf\u00e4lligen Code zu erstellen, um \u00e4hnliche Schwachstellen im Code anderer Projekte zu erkennen (CodeQL bietet die M\u00f6glichkeit, semantische Analysen des Codes durchzuf\u00fchren und Abfragen zur Suche nach bestimmten Konstruktionen zu erstellen).<\/p>\n<p>An der Initiative haben bereits Sicherheitsexperten von Unternehmen wie F5, Google, HackerOne, Intel, IOActive, J.P. Morgan, LinkedIn, Microsoft, Mozilla, NCC Group, Oracle, Trail of Bits, Uber und<br \/>\nVMware teilgenommen, die in den letzten zwei Jahren <noindex><a rel=\"nofollow\" href=\"https:\/\/securitylab.github.com\/disclosures\">haben<\/a><\/noindex> und <noindex><a rel=\"nofollow\" href=\"https:\/\/securitylab.github.com\/research\">105 Schwachstellen in Projekten wie Chromium, libssh2, dem Linux-Kernel, Memcached, UBoot, VLC, Apport, HHVM, Exiv2, FFmpeg, Fizz, libav, Ansible, npm, XNU, Ghostscript, Icecast, Apache Struts, strongSwan, Apache Ignite, rsyslog, Apache Geode und Hadoop behoben haben.<\/a><\/noindex> Der von GitHub vorgeschlagene Lebenszyklus zur Sicherstellung der Code-Sicherheit sieht vor, dass die Teilnehmer des GitHub Security Lab Schwachstellen identifizieren, danach wird die Probleminformation an die Maintainern und Entwickler weitergegeben, die L\u00f6sungen entwickeln, den Zeitpunkt der Offenlegung der Probleminformationen festlegen und abh\u00e4ngige Projekte \u00fcber die Notwendigkeit informieren, Versionen mit behobenen Schwachstellen zu installieren. In der Datenbank werden CodeQL-Vorlagen bereitgestellt, um die Wiederholung behobener Probleme im auf GitHub vorhandenen Code zu verhindern. <\/p>\n<p>\u00dcber die GitHub-Oberfl\u00e4che kann jetzt<br \/>\n<center><noindex><a rel=\"nofollow\" href=\"https:\/\/github.blog\/wp-content\/uploads\/2019\/11\/Screen-Shot-2019-11-13-at-12.33.17-PM.png\"><img decoding=\"async\" alt=\"GitHub hat ein gemeinsames Projekt zur Identifizierung von Schwachstellen in Open-Source-Software gestartet\" src=\"\/wp-content\/uploads\/2019\/11\/f605545e88da52ebd21d412dc7518a71.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p>eine CVE-ID f\u00fcr das identifizierte Problem erstellt und ein Bericht vorbereitet werden, w\u00e4hrend GitHub die notwendigen Benachrichtigungen versendet und deren koordinierte Behebung organisiert. Dar\u00fcber hinaus versendet GitHub nach der Behebung des Problems automatisch Pull-Requests zur Aktualisierung der Abh\u00e4ngigkeiten, die mit dem anf\u00e4lligen Projekt verbunden sind. <noindex><a rel=\"nofollow\" href=\"https:\/\/github.blog\/changelog\/2019-11-11-security-advisories-generally-available-can-request-cves\/\">die<\/a><\/noindex> GitHub hat au\u00dferdem ein neues Verzeichnis von Schwachstellen eingef\u00fchrt<\/p>\n<p>, in dem Informationen \u00fcber Schwachstellen ver\u00f6ffentlicht werden, die Projekte auf GitHub betreffen, sowie Informationen zur Nachverfolgung anf\u00e4lliger Pakete und Repositories. Die in Kommentaren bei GitHub erw\u00e4hnten CVE-IDs verlinken jetzt automatisch auf detaillierte Informationen zur Schwachstelle in dieser Datenbank. Um die Arbeit mit der Datenbank zu automatisieren, wurde ein separates <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/advisories\">GitHub Advisory Database<\/a><\/noindex>Au\u00dferdem wird \u00fcber ein Update berichtet <noindex><a rel=\"nofollow\" href=\"https:\/\/developer.github.com\/v4\/object\/securityadvisory\/\">API<\/a><\/noindex>.<\/p>\n<p>zum Schutz vor <noindex><a rel=\"nofollow\" href=\"https:\/\/developer.github.com\/partnerships\/token-scanning\/\">einem Dienst<\/a><\/noindex> vertraulichen Daten wie Authentifizierungstoken und Zugangsschl\u00fcsseln in \u00f6ffentlich zug\u00e4nglichen Repositories. Beim Commits \u00fcberpr\u00fcft der Scanner typischen Formate von Schl\u00fcsseln und Tokens, die <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50374\">dem Auftreten<\/a><\/noindex>  von 20 Cloud-Anbietern und -Diensten verwendet werden<br \/>\n, darunter API Alibaba Cloud, Amazon Web Services (AWS), Azure, Google Cloud, Slack und Stripe. Bei der Entdeckung eines Tokens wird ein Anfrage an den Dienstanbieter gesendet, um die Leckage zu best\u00e4tigen und kompromittierte Tokens zur\u00fcckzuziehen. Seit gestern, neben den zuvor unterst\u00fctzten Formaten, wurde die Unterst\u00fctzung zur Identifizierung von Tokens von GoCardless, HashiCorp, Postman und Tencent hinzugef\u00fcgt. <noindex><a rel=\"nofollow\" href=\"https:\/\/help.github.com\/en\/github\/administering-a-repository\/about-token-scanning\">GitHub hat die Initiative GitHub Security Lab ins Leben gerufen, die darauf abzielt, die Zusammenarbeit von Sicherheitsexperten aus verschiedenen Unternehmen und Organisationen zu f\u00f6rdern, um Schwachstellen zu identifizieren und bei deren Behebung im Code von Open-Source-Projekten zu helfen. Alle interessierten Unternehmen und Einzelpersonen im Bereich der Computersicherheit sind eingeladen, sich an der Initiative zu beteiligen. F\u00fcr die Entdeckung von Schwachstellen wird eine Belohnung von bis zu 3000<\/a><\/noindex>\ud83e\udd47GitHub hat ein gemeinsames Projekt zur Identifizierung von Schwachstellen in Open-Source-Software gestartet | ProHoster<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Quelle: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51867\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>GitHub \u0432\u044b\u0441\u0442\u0443\u043f\u0438\u043b \u0441 \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u043e\u0439 GitHub Security Lab, \u043d\u0430\u0446\u0435\u043b\u0435\u043d\u043d\u043e\u0439 \u043d\u0430 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u044e \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u043d\u043e\u0439 \u0440\u0430\u0431\u043e\u0442\u044b \u044d\u043a\u0441\u043f\u0435\u0440\u0442\u043e\u0432 \u043f\u043e \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0439 \u0438 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0439 \u0434\u043b\u044f \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0438 \u0441\u043e\u0434\u0435\u0439\u0441\u0442\u0432\u0438\u044e \u043f\u043e \u0438\u0445 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u044e \u0432 \u043a\u043e\u0434\u0435 \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u0445 \u043f\u0440\u043e\u0435\u043a\u0442\u043e\u0432. \u0414\u043b\u044f \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u043a \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u0435 \u043f\u0440\u0438\u0433\u043b\u0430\u0448\u0430\u044e\u0442\u0441\u044f \u0432\u0441\u0435 \u0437\u0430\u0438\u043d\u0442\u0435\u0440\u0435\u0441\u043e\u0432\u0430\u043d\u043d\u044b\u0435 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 \u0438 \u0438\u043d\u0434\u0438\u0432\u0438\u0434\u0443\u0430\u043b\u044c\u043d\u044b\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u0438\u0441\u0442\u044b \u043f\u043e \u043a\u043e\u043c\u043f\u044c\u044e\u0442\u0435\u0440\u043d\u043e\u0439 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438. \u0417\u0430 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u0440\u0435\u0434\u0443\u0441\u043c\u043e\u0442\u0440\u0435\u043d\u0430 \u0432\u044b\u043f\u043b\u0430\u0442\u0430 \u0432\u043e\u0437\u043d\u0430\u0433\u0440\u0430\u0436\u0434\u0435\u043d\u0438\u044f \u0440\u0430\u0437\u043c\u0435\u0440\u043e\u043c \u0434\u043e 3000 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":52758,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-52757","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-novosti-interneta"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"GitHub \u0432\u044b\u0441\u0442\u0443\u043f\u0438\u043b \u0441 \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u043e\u0439\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/novosti-interneta\/github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47GitHub \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u043b \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u043d\u044b\u0439 \u043f\u0440\u043e\u0435\u043a\u0442 \u0434\u043b\u044f \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u043c \u041f\u041e | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"GitHub \u0432\u044b\u0441\u0442\u0443\u043f\u0438\u043b \u0441 \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u043e\u0439\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/novosti-interneta\/github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-11-15T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:00:33+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47GitHub hat ein gemeinsames Projekt zur Identifizierung von Sicherheitsanf\u00e4lligkeiten in Open-Source-Software gestartet | ProHoster","description":"GitHub hat eine Initiative ins Leben gerufen","canonical_url":"https:\/\/prohoster.info\/de\/blog\/novosti-interneta\/github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47GitHub \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u043b \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u043d\u044b\u0439 \u043f\u0440\u043e\u0435\u043a\u0442 \u0434\u043b\u044f \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u043c \u041f\u041e | ProHoster","og:description":"GitHub \u0432\u044b\u0441\u0442\u0443\u043f\u0438\u043b \u0441 \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u043e\u0439","og:url":"https:\/\/prohoster.info\/de\/blog\/novosti-interneta\/github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-11-15T21:00:00+00:00","article:modified_time":"2020-02-18T11:00:33+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"52757","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 04:44:21","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 12:18:18","updated":"2026-01-24 04:44:21","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/52757","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=52757"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/52757\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media\/52758"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=52757"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=52757"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=52757"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}