{"id":52757,"date":"2019-11-16T00:00:00","date_gmt":"2019-11-15T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po"},"modified":"2020-02-18T14:00:33","modified_gmt":"2020-02-18T11:00:33","slug":"github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po","title":{"rendered":"GitHub a lanc\u00e9 un projet collaboratif pour identifier les vuln\u00e9rabilit\u00e9s dans les logiciels open source.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>GitHub <noindex><a rel=\"nofollow\" href=\"https:\/\/github.blog\/2019-11-14-announcing-github-security-lab-securing-the-worlds-code-together\/\">a pris la parole<\/a><\/noindex> pour une initiative  <noindex><a rel=\"nofollow\" href=\"https:\/\/securitylab.github.com\/\">GitHub Security Lab<\/a><\/noindex>, visant \u00e0 organiser la collaboration entre des experts en s\u00e9curit\u00e9 provenant de diff\u00e9rentes entreprises et organisations pour identifier les vuln\u00e9rabilit\u00e9s et faciliter leur r\u00e9solution dans le code des projets open source.  <\/p>\n<p>Toutes les entreprises et les sp\u00e9cialistes en cybers\u00e9curit\u00e9 int\u00e9ress\u00e9s sont invit\u00e9s \u00e0 rejoindre cette initiative. Pour chaque vuln\u00e9rabilit\u00e9 d\u00e9tect\u00e9e,  <noindex><a rel=\"nofollow\" href=\"https:\/\/securitylab.github.com\/bounties\">une r\u00e9compense<\/a><\/noindex> de jusqu'\u00e0 3000 dollars sera vers\u00e9e, en fonction de la gravit\u00e9 du probl\u00e8me et de la qualit\u00e9 du rapport soumis. Pour soumettre des informations sur les probl\u00e8mes, il est propos\u00e9 d'utiliser des outils <noindex><a rel=\"nofollow\" href=\"https:\/\/securitylab.github.com\/tools\/codeql\">CodeQL<\/a><\/noindex>, permettant de cr\u00e9er un mod\u00e8le de code vuln\u00e9rable pour d\u00e9tecter la pr\u00e9sence de vuln\u00e9rabilit\u00e9s similaires dans le code d'autres projets (CodeQL permet d'effectuer une analyse s\u00e9mantique du code et de formuler des requ\u00eates pour rechercher des constructions sp\u00e9cifiques).<\/p>\n<p>Des chercheurs en s\u00e9curit\u00e9 de F5, Google, HackerOne, Intel, IOActive, J.P. Morgan, LinkedIn, Microsoft, Mozilla, NCC Group, Oracle, Trail of Bits, Uber et<br \/>\nVMWare ont d\u00e9j\u00e0 rejoint l'initiative, ayant aid\u00e9 \u00e0 corriger <noindex><a rel=\"nofollow\" href=\"https:\/\/securitylab.github.com\/disclosures\">ont identifi\u00e9<\/a><\/noindex> et <noindex><a rel=\"nofollow\" href=\"https:\/\/securitylab.github.com\/research\">105 vuln\u00e9rabilit\u00e9s au cours des deux derni\u00e8res ann\u00e9es<\/a><\/noindex> dans des projets tels que Chromium, libssh2, le noyau Linux, Memcached, UBoot, VLC, Apport, HHVM, Exiv2, FFmpeg, Fizz, libav, Ansible, npm, XNU, Ghostscript, Icecast, Apache Struts, strongSwan, Apache Ignite, rsyslog, Apache Geode et Hadoop. <\/p>\n<p>Le cycle de vie de la s\u00e9curit\u00e9 du code propos\u00e9 par GitHub implique que les participants de GitHub Security Lab identifient les vuln\u00e9rabilit\u00e9s, apr\u00e8s quoi les informations sur les probl\u00e8mes seront transmises aux mainteneurs et aux d\u00e9veloppeurs, qui travailleront sur des corrections, d\u00e9finiront un calendrier de divulgation des informations sur les probl\u00e8mes et informeront les projets d\u00e9pendants de la n\u00e9cessit\u00e9 de mettre \u00e0 jour vers une version corrig\u00e9e. Des mod\u00e8les CodeQL seront disponibles afin d'\u00e9viter la r\u00e9apparition des probl\u00e8mes corrig\u00e9s dans le code pr\u00e9sent sur GitHub.<br \/>\n<center><noindex><a rel=\"nofollow\" href=\"https:\/\/github.blog\/wp-content\/uploads\/2019\/11\/Screen-Shot-2019-11-13-at-12.33.17-PM.png\"><img decoding=\"async\" alt=\"GitHub a lanc\u00e9 un projet collaboratif pour identifier les vuln\u00e9rabilit\u00e9s dans les logiciels open source.\" src=\"\/wp-content\/uploads\/2019\/11\/f605545e88da52ebd21d412dc7518a71.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p>Via l'interface GitHub, il est d\u00e9sormais possible de <noindex><a rel=\"nofollow\" href=\"https:\/\/github.blog\/changelog\/2019-11-11-security-advisories-generally-available-can-request-cves\/\">obtenir<\/a><\/noindex> un identifiant CVE pour le probl\u00e8me d\u00e9tect\u00e9 et de pr\u00e9parer un rapport, tandis que GitHub enverra automatiquement les notifications n\u00e9cessaires et organisera leur correction coordonn\u00e9e. De plus, apr\u00e8s la correction du probl\u00e8me, GitHub enverra automatiquement des pull requests pour mettre \u00e0 jour les d\u00e9pendances li\u00e9es au projet vuln\u00e9rable.<\/p>\n<p>GitHub a \u00e9galement introduit un r\u00e9pertoire de vuln\u00e9rabilit\u00e9s. <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/advisories\">la GitHub Advisory Database<\/a><\/noindex>, qui publie des informations sur les vuln\u00e9rabilit\u00e9s impactant les projets sur GitHub, ainsi que des informations pour le suivi des paquets et des d\u00e9p\u00f4ts concern\u00e9s. Les identifiants CVE mentionn\u00e9s dans les commentaires sur GitHub font d\u00e9sormais r\u00e9f\u00e9rence automatiquement aux d\u00e9tails des vuln\u00e9rabilit\u00e9s dans la base de donn\u00e9es pr\u00e9sent\u00e9e. Un module distinct a \u00e9t\u00e9 propos\u00e9 pour automatiser les op\u00e9rations avec la base de donn\u00e9es <noindex><a rel=\"nofollow\" href=\"https:\/\/developer.github.com\/v4\/object\/securityadvisory\/\">API<\/a><\/noindex>.<\/p>\n<p>Une mise \u00e0 jour est \u00e9galement signal\u00e9e <noindex><a rel=\"nofollow\" href=\"https:\/\/developer.github.com\/partnerships\/token-scanning\/\">du service<\/a><\/noindex> pour se prot\u00e9ger contre <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50374\">la fuite<\/a><\/noindex>  dans les d\u00e9p\u00f4ts accessibles au public<br \/>\ndes donn\u00e9es sensibles telles que des jetons d'authentification et des cl\u00e9s d'acc\u00e8s. Lors du commit, le scanner v\u00e9rifie les formats types de cl\u00e9s et de jetons utilis\u00e9s <noindex><a rel=\"nofollow\" href=\"https:\/\/help.github.com\/en\/github\/administering-a-repository\/about-token-scanning\">par 20 fournisseurs de cloud et services<\/a><\/noindex>, y compris l'API Alibaba Cloud, Amazon Web Services (AWS), Azure, Google Cloud, Slack et Stripe. En cas de d\u00e9tection d'un jeton, une requ\u00eate est envoy\u00e9e au fournisseur de service pour confirmer la fuite et r\u00e9voquer les jetons compromis. Depuis hier, en plus des formats pr\u00e9c\u00e9demment pris en charge, la prise en charge de la d\u00e9tection des jetons GoCardless, HashiCorp, Postman et Tencent a \u00e9t\u00e9 ajout\u00e9e.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source : <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51867\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>GitHub \u0432\u044b\u0441\u0442\u0443\u043f\u0438\u043b \u0441 \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u043e\u0439 GitHub Security Lab, \u043d\u0430\u0446\u0435\u043b\u0435\u043d\u043d\u043e\u0439 \u043d\u0430 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u044e \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u043d\u043e\u0439 \u0440\u0430\u0431\u043e\u0442\u044b \u044d\u043a\u0441\u043f\u0435\u0440\u0442\u043e\u0432 \u043f\u043e \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0439 \u0438 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0439 \u0434\u043b\u044f \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0438 \u0441\u043e\u0434\u0435\u0439\u0441\u0442\u0432\u0438\u044e \u043f\u043e \u0438\u0445 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u044e \u0432 \u043a\u043e\u0434\u0435 \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u0445 \u043f\u0440\u043e\u0435\u043a\u0442\u043e\u0432. \u0414\u043b\u044f \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u043a \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u0435 \u043f\u0440\u0438\u0433\u043b\u0430\u0448\u0430\u044e\u0442\u0441\u044f \u0432\u0441\u0435 \u0437\u0430\u0438\u043d\u0442\u0435\u0440\u0435\u0441\u043e\u0432\u0430\u043d\u043d\u044b\u0435 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 \u0438 \u0438\u043d\u0434\u0438\u0432\u0438\u0434\u0443\u0430\u043b\u044c\u043d\u044b\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u0438\u0441\u0442\u044b \u043f\u043e \u043a\u043e\u043c\u043f\u044c\u044e\u0442\u0435\u0440\u043d\u043e\u0439 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438. \u0417\u0430 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u0440\u0435\u0434\u0443\u0441\u043c\u043e\u0442\u0440\u0435\u043d\u0430 \u0432\u044b\u043f\u043b\u0430\u0442\u0430 \u0432\u043e\u0437\u043d\u0430\u0433\u0440\u0430\u0436\u0434\u0435\u043d\u0438\u044f \u0440\u0430\u0437\u043c\u0435\u0440\u043e\u043c \u0434\u043e 3000 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":52758,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-52757","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"GitHub \u0432\u044b\u0441\u0442\u0443\u043f\u0438\u043b \u0441 \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u043e\u0439\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47GitHub \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u043b \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u043d\u044b\u0439 \u043f\u0440\u043e\u0435\u043a\u0442 \u0434\u043b\u044f \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u043c \u041f\u041e | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"GitHub \u0432\u044b\u0441\u0442\u0443\u043f\u0438\u043b \u0441 \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u043e\u0439\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-11-15T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:00:33+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47GitHub a lanc\u00e9 un projet commun pour d\u00e9tecter les vuln\u00e9rabilit\u00e9s dans les logiciels open source | ProHoster","description":"GitHub a lanc\u00e9 une initiative","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47GitHub \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u043b \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u043d\u044b\u0439 \u043f\u0440\u043e\u0435\u043a\u0442 \u0434\u043b\u044f \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u043c \u041f\u041e | ProHoster","og:description":"GitHub \u0432\u044b\u0441\u0442\u0443\u043f\u0438\u043b \u0441 \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u043e\u0439","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-11-15T21:00:00+00:00","article:modified_time":"2020-02-18T11:00:33+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"52757","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 04:44:21","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 12:18:18","updated":"2026-01-24 04:44:21","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/52757","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=52757"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/52757\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media\/52758"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=52757"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=52757"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=52757"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}