{"id":52757,"date":"2019-11-16T00:00:00","date_gmt":"2019-11-15T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po"},"modified":"2020-02-18T14:00:33","modified_gmt":"2020-02-18T11:00:33","slug":"github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/news\/github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po","title":{"rendered":"GitHub hat ein gemeinsames Projekt zur Identifizierung von Schwachstellen in Open Source Software gestartet.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>GitHub <noindex><a rel=\"nofollow\" href=\"https:\/\/github.blog\/2019-11-14-announcing-github-security-lab-securing-the-worlds-code-together\/\">trat auf<\/a><\/noindex> mit der Initiative  <noindex><a rel=\"nofollow\" href=\"https:\/\/securitylab.github.com\/\">GitHub Sicherheitslabor<\/a><\/noindex>, das darauf abzielt, die Zusammenarbeit von Sicherheitsexperten aus verschiedenen Unternehmen und Organisationen zu organisieren, um Schwachstellen zu identifizieren und deren Behebung in den Codes \u00f6ffentlicher Projekte zu unterst\u00fctzen.  <\/p>\n<p>Alle interessierten Unternehmen und Einzelpersonen aus der Computersicherheitsbranche sind eingeladen, sich an der Initiative zu beteiligen. F\u00fcr die Identifizierung von Schwachstellen  <noindex><a rel=\"nofollow\" href=\"https:\/\/securitylab.github.com\/bounties\">ist eine<\/a><\/noindex> Belohnung von bis zu 3000 US-Dollar vorgesehen, abh\u00e4ngig von der Schwere des Problems und der Qualit\u00e4t des Berichts. F\u00fcr die \u00dcbermittlung von Fehlern wird vorgeschlagen, das Werkzeug <noindex><a rel=\"nofollow\" href=\"https:\/\/securitylab.github.com\/tools\/codeql\">CodeQL<\/a><\/noindex>, das es erm\u00f6glicht, eine Vorlage f\u00fcr verwundbaren Code zu erstellen, um das Vorhandensein solcher Schwachstellen im Code anderer Projekte zu erkennen (CodeQL erm\u00f6glicht die semantische Analyse von Code und das Erstellen von Abfragen zur Suche nach bestimmten Konstruktionen).<\/p>\n<p>Sicherheitsforscher von Unternehmen wie F5, Google, HackerOne, Intel, IOActive, J.P. Morgan, LinkedIn, Microsoft, Mozilla, NCC Group, Oracle, Trail of Bits, Uber und<br \/>\nVMWare haben sich bereits der Initiative angeschlossen und in den letzten zwei Jahren <noindex><a rel=\"nofollow\" href=\"https:\/\/securitylab.github.com\/disclosures\">entdeckten<\/a><\/noindex> und <noindex><a rel=\"nofollow\" href=\"https:\/\/securitylab.github.com\/research\">bei der Behebung von<\/a><\/noindex> 105 Schwachstellen in Projekten wie Chromium, libssh2, dem Linux-Kernel, Memcached, UBoot, VLC, Apport, HHVM, Exiv2, FFmpeg, Fizz, libav, Ansible, npm, XNU, Ghostscript, Icecast, Apache Struts, strongSwan, Apache Ignite, rsyslog, Apache Geode und Hadoop geholfen. <\/p>\n<p>Der von GitHub vorgeschlagene Lebenszyklus zur Sicherstellung der Sicherheit von Code sieht vor, dass die Teilnehmer des GitHub Sicherheitslabors Schwachstellen identifizieren, woraufhin die Informationen \u00fcber Probleme an die Maintainer und Entwickler weitergegeben werden, die dann L\u00f6sungen erarbeiten, den Zeitpunkt der Offenlegung der Probleme koordinieren und abh\u00e4ngige Projekte \u00fcber die Notwendigkeit informieren, eine Version mit behobenen Schwachstellen zu installieren. In der Datenbank werden CodeQL-Vorlagen ver\u00f6ffentlicht, um das Wiederauftreten behobener Probleme im auf GitHub vorhandenen Code zu verhindern.<br \/>\n<center><noindex><a rel=\"nofollow\" href=\"https:\/\/github.blog\/wp-content\/uploads\/2019\/11\/Screen-Shot-2019-11-13-at-12.33.17-PM.png\"><img decoding=\"async\" alt=\"GitHub hat ein gemeinsames Projekt zur Identifizierung von Schwachstellen in Open Source Software gestartet.\" src=\"\/wp-content\/uploads\/2019\/11\/f605545e88da52ebd21d412dc7518a71.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p>\u00dcber die GitHub-Oberfl\u00e4che k\u00f6nnen jetzt <noindex><a rel=\"nofollow\" href=\"https:\/\/github.blog\/changelog\/2019-11-11-security-advisories-generally-available-can-request-cves\/\">erhalten<\/a><\/noindex> CVE-Identifikatoren f\u00fcr identifizierte Probleme erstellt und Berichte vorbereitet werden, w\u00e4hrend GitHub bereits selbst die notwendigen Benachrichtigungen versendet und deren koordinierte Behebung organisiert. Dar\u00fcber hinaus wird GitHub nach der Behebung des Problems automatisch Pull-Requests f\u00fcr die Aktualisierung von Abh\u00e4ngigkeiten, die mit dem verwundbaren Projekt verbunden sind, versenden.<\/p>\n<p>GitHub hat auch ein Verzeichnis von Schwachstellen eingef\u00fchrt. <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/advisories\">GitHub Advisory Database<\/a><\/noindex>, in dem Informationen \u00fcber Schwachstellen ver\u00f6ffentlicht werden, die Projekte auf GitHub betreffen, sowie Informationen zur Verfolgung betroffener Pakete und Repositories. Die in den Kommentaren auf GitHub genannten CVE-Identifikatoren verweisen jetzt automatisch auf detaillierte Informationen zu den Schwachstellen in der bereitgestellten Datenbank. Zur Automatisierung der Arbeit mit der Datenbank wurde ein separates <noindex><a rel=\"nofollow\" href=\"https:\/\/developer.github.com\/v4\/object\/securityadvisory\/\">API<\/a><\/noindex>.<\/p>\n<p>Update wird ebenfalls gemeldet <noindex><a rel=\"nofollow\" href=\"https:\/\/developer.github.com\/partnerships\/token-scanning\/\">Dienst<\/a><\/noindex> zum Schutz vor <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50374\">dem Entstehen<\/a><\/noindex>  in \u00f6ffentlich zug\u00e4nglichen Repositories<br \/>\nvertraulichen Daten wie Authentifizierungstoken und Zugangsschl\u00fcsseln. W\u00e4hrend des Commits \u00fcberpr\u00fcft der Scanner die typischen Formate von Schl\u00fcsseln und Token, die verwendet werden, <noindex><a rel=\"nofollow\" href=\"https:\/\/help.github.com\/en\/github\/administering-a-repository\/about-token-scanning\">von 20 Cloud-Anbietern und -Diensten<\/a><\/noindex>, darunter API Alibaba Cloud, Amazon Web Services (AWS), Azure, Google Cloud, Slack und Stripe. Bei der Entdeckung eines Tokens wird eine Anfrage an den Dienstanbieter gesendet, um den Leak zu best\u00e4tigen und kompromittierte Tokens zur\u00fcckzuziehen. Seit gestern wurde neben den bereits unterst\u00fctzten Formaten auch die Unterst\u00fctzung zur Erkennung von Tokens von GoCardless, HashiCorp, Postman und Tencent hinzugef\u00fcgt.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Quelle: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51867\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>GitHub \u0432\u044b\u0441\u0442\u0443\u043f\u0438\u043b \u0441 \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u043e\u0439 GitHub Security Lab, \u043d\u0430\u0446\u0435\u043b\u0435\u043d\u043d\u043e\u0439 \u043d\u0430 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u044e \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u043d\u043e\u0439 \u0440\u0430\u0431\u043e\u0442\u044b \u044d\u043a\u0441\u043f\u0435\u0440\u0442\u043e\u0432 \u043f\u043e \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0439 \u0438 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0439 \u0434\u043b\u044f \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0438 \u0441\u043e\u0434\u0435\u0439\u0441\u0442\u0432\u0438\u044e \u043f\u043e \u0438\u0445 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u044e \u0432 \u043a\u043e\u0434\u0435 \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u0445 \u043f\u0440\u043e\u0435\u043a\u0442\u043e\u0432. \u0414\u043b\u044f \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u043a \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u0435 \u043f\u0440\u0438\u0433\u043b\u0430\u0448\u0430\u044e\u0442\u0441\u044f \u0432\u0441\u0435 \u0437\u0430\u0438\u043d\u0442\u0435\u0440\u0435\u0441\u043e\u0432\u0430\u043d\u043d\u044b\u0435 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 \u0438 \u0438\u043d\u0434\u0438\u0432\u0438\u0434\u0443\u0430\u043b\u044c\u043d\u044b\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u0438\u0441\u0442\u044b \u043f\u043e \u043a\u043e\u043c\u043f\u044c\u044e\u0442\u0435\u0440\u043d\u043e\u0439 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438. \u0417\u0430 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u0440\u0435\u0434\u0443\u0441\u043c\u043e\u0442\u0440\u0435\u043d\u0430 \u0432\u044b\u043f\u043b\u0430\u0442\u0430 \u0432\u043e\u0437\u043d\u0430\u0433\u0440\u0430\u0436\u0434\u0435\u043d\u0438\u044f \u0440\u0430\u0437\u043c\u0435\u0440\u043e\u043c \u0434\u043e 3000 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":52758,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-52757","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"GitHub \u0432\u044b\u0441\u0442\u0443\u043f\u0438\u043b \u0441 \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u043e\u0439\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/news\/github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47GitHub \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u043b \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u043d\u044b\u0439 \u043f\u0440\u043e\u0435\u043a\u0442 \u0434\u043b\u044f \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u043c \u041f\u041e | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"GitHub \u0432\u044b\u0441\u0442\u0443\u043f\u0438\u043b \u0441 \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u043e\u0439\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/news\/github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-11-15T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:00:33+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47GitHub hat ein gemeinsames Projekt zur Identifizierung von Schwachstellen in Open Source-Software ins Leben gerufen | ProHoster","description":"GitHub hat eine Initiative gestartet","canonical_url":"https:\/\/prohoster.info\/de\/blog\/news\/github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47GitHub \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u043b \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u043d\u044b\u0439 \u043f\u0440\u043e\u0435\u043a\u0442 \u0434\u043b\u044f \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u043c \u041f\u041e | ProHoster","og:description":"GitHub \u0432\u044b\u0441\u0442\u0443\u043f\u0438\u043b \u0441 \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u043e\u0439","og:url":"https:\/\/prohoster.info\/de\/blog\/news\/github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-11-15T21:00:00+00:00","article:modified_time":"2020-02-18T11:00:33+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"52757","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 04:44:21","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 12:18:18","updated":"2026-01-24 04:44:21","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/52757","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=52757"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/52757\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media\/52758"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=52757"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=52757"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=52757"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}