{"id":52757,"date":"2019-11-16T00:00:00","date_gmt":"2019-11-15T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po"},"modified":"2020-02-18T14:00:33","modified_gmt":"2020-02-18T11:00:33","slug":"github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po","title":{"rendered":"GitHub ha lanciato un progetto collaborativo per identificare vulnerabilit\u00e0 nel software open source","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>GitHub <noindex><a rel=\"nofollow\" href=\"https:\/\/github.blog\/2019-11-14-announcing-github-security-lab-securing-the-worlds-code-together\/\">si \u00e8 espresso<\/a><\/noindex> l'iniziativa  <noindex><a rel=\"nofollow\" href=\"https:\/\/securitylab.github.com\/\">GitHub Security Lab<\/a><\/noindex>, mirata all'organizzazione della collaborazione tra esperti di sicurezza di diverse aziende e organizzazioni per identificare vulnerabilit\u00e0 e supportare la loro risoluzione nel codice di progetti open source.  <\/p>\n<p>Tutte le aziende interessate e i singoli esperti di sicurezza informatica sono invitati a partecipare all'iniziativa. Per l'identificazione delle vulnerabilit\u00e0  <noindex><a rel=\"nofollow\" href=\"https:\/\/securitylab.github.com\/bounties\">\u00e8 previsto<\/a><\/noindex> un premio di fino a 3000 dollari, a seconda della gravit\u00e0 del problema e della qualit\u00e0 della relazione. Per inviare informazioni sui problemi, si consiglia di utilizzare un tool <noindex><a rel=\"nofollow\" href=\"https:\/\/securitylab.github.com\/tools\/codeql\">CodeQL<\/a><\/noindex>, che consente di creare un modello di codice vulnerabile per identificare la presenza di simili vulnerabilit\u00e0 nel codice di altri progetti (CodeQL offre la possibilit\u00e0 di effettuare analisi semantiche del codice e generare query per la ricerca di specifiche strutture).<\/p>\n<p>All'iniziativa hanno gi\u00e0 aderito ricercatori di sicurezza di aziende come F5, Google, HackerOne, Intel, IOActive, J.P. Morgan, LinkedIn, Microsoft, Mozilla, NCC Group, Oracle, Trail of Bits, Uber e<br \/>\nVMware, che negli ultimi due anni <noindex><a rel=\"nofollow\" href=\"https:\/\/securitylab.github.com\/disclosures\">hanno identificato<\/a><\/noindex> e <noindex><a rel=\"nofollow\" href=\"https:\/\/securitylab.github.com\/research\">hanno contribuito a correggere<\/a><\/noindex> 105 vulnerabilit\u00e0 in progetti come Chromium, libssh2, il nucleo Linux, Memcached, UBoot, VLC, Apport, HHVM, Exiv2, FFmpeg, Fizz, libav, Ansible, npm, XNU, Ghostscript, Icecast, Apache Struts, strongSwan, Apache Ignite, rsyslog, Apache Geode e Hadoop. <\/p>\n<p>Il ciclo di vita della sicurezza del codice proposto su GitHub prevede che i membri del GitHub Security Lab identificano vulnerabilit\u00e0; successivamente, le informazioni sui problemi verranno comunicate ai manutentori e agli sviluppatori, che elaboreranno le correzioni, concordando il momento della divulgazione delle informazioni sul problema e informeranno i progetti dipendenti sulla necessit\u00e0 di installare la versione con la vulnerabilit\u00e0 corretta. Un database ospiter\u00e0 modelli CodeQL che consentiranno di prevenire il riemergere di problemi risolti nel codice presente su GitHub.<br \/>\n<center><noindex><a rel=\"nofollow\" href=\"https:\/\/github.blog\/wp-content\/uploads\/2019\/11\/Screen-Shot-2019-11-13-at-12.33.17-PM.png\"><img decoding=\"async\" alt=\"GitHub ha lanciato un progetto collaborativo per identificare vulnerabilit\u00e0 nel software open source\" src=\"\/wp-content\/uploads\/2019\/11\/f605545e88da52ebd21d412dc7518a71.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p>Ora, tramite l'interfaccia di GitHub, \u00e8 possibile <noindex><a rel=\"nofollow\" href=\"https:\/\/github.blog\/changelog\/2019-11-11-security-advisories-generally-available-can-request-cves\/\">ricevere<\/a><\/noindex> ottenere un identificatore CVE per il problema identificato e preparare un rapporto, e GitHub si occuper\u00e0 di inviare le necessarie notifiche e organizzer\u00e0 la loro correzione coordinata. Inoltre, dopo la risoluzione del problema, GitHub invier\u00e0 automaticamente richieste di pull per l'aggiornamento delle dipendenze collegate al progetto vulnerabile.<\/p>\n<p>GitHub ha anche introdotto un catalogo delle vulnerabilit\u00e0 <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/advisories\">GitHub Advisory Database<\/a><\/noindex>, in cui vengono pubblicate informazioni sulle vulnerabilit\u00e0 che interessano i progetti su GitHub, e dettagli per il monitoraggio dei pacchetti e dei repository vulnerabili. I riferimenti CVE menzionati nei commenti di GitHub rimandano automaticamente a informazioni dettagliate sulla vulnerabilit\u00e0 nel database fornito. Per automatizzare il lavoro con il database, \u00e8 stata proposta una soluzione separata <noindex><a rel=\"nofollow\" href=\"https:\/\/developer.github.com\/v4\/object\/securityadvisory\/\">API<\/a><\/noindex>.<\/p>\n<p>Si segnala anche un aggiornamento <noindex><a rel=\"nofollow\" href=\"https:\/\/developer.github.com\/partnerships\/token-scanning\/\">servizio<\/a><\/noindex> per proteggere da <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50374\">fuoriuscite di<\/a><\/noindex>  in repository pubblicamente accessibili<br \/>\ndati riservati come token di autenticazione e chiavi di accesso. Durante il commit, lo scanner verifica i formati standard dei token e delle chiavi utilizzati <noindex><a rel=\"nofollow\" href=\"https:\/\/help.github.com\/en\/github\/administering-a-repository\/about-token-scanning\">da 20 fornitori cloud e servizi<\/a><\/noindex>, inclusi API di Alibaba Cloud, Amazon Web Services (AWS), Azure, Google Cloud, Slack e Stripe. In caso di individuazione di un token, viene inviata una richiesta al fornitore di servizi per confermare la fuga e revocare i token compromessi. Da ieri, oltre ai formati supportati in precedenza, \u00e8 stata aggiunta la compatibilit\u00e0 per l'individuazione di token GoCardless, HashiCorp, Postman e Tencent.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fonte: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51867\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>GitHub \u0432\u044b\u0441\u0442\u0443\u043f\u0438\u043b \u0441 \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u043e\u0439 GitHub Security Lab, \u043d\u0430\u0446\u0435\u043b\u0435\u043d\u043d\u043e\u0439 \u043d\u0430 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u044e \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u043d\u043e\u0439 \u0440\u0430\u0431\u043e\u0442\u044b \u044d\u043a\u0441\u043f\u0435\u0440\u0442\u043e\u0432 \u043f\u043e \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0439 \u0438 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0439 \u0434\u043b\u044f \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0438 \u0441\u043e\u0434\u0435\u0439\u0441\u0442\u0432\u0438\u044e \u043f\u043e \u0438\u0445 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u044e \u0432 \u043a\u043e\u0434\u0435 \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u0445 \u043f\u0440\u043e\u0435\u043a\u0442\u043e\u0432. \u0414\u043b\u044f \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u043a \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u0435 \u043f\u0440\u0438\u0433\u043b\u0430\u0448\u0430\u044e\u0442\u0441\u044f \u0432\u0441\u0435 \u0437\u0430\u0438\u043d\u0442\u0435\u0440\u0435\u0441\u043e\u0432\u0430\u043d\u043d\u044b\u0435 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 \u0438 \u0438\u043d\u0434\u0438\u0432\u0438\u0434\u0443\u0430\u043b\u044c\u043d\u044b\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u0438\u0441\u0442\u044b \u043f\u043e \u043a\u043e\u043c\u043f\u044c\u044e\u0442\u0435\u0440\u043d\u043e\u0439 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438. \u0417\u0430 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u0440\u0435\u0434\u0443\u0441\u043c\u043e\u0442\u0440\u0435\u043d\u0430 \u0432\u044b\u043f\u043b\u0430\u0442\u0430 \u0432\u043e\u0437\u043d\u0430\u0433\u0440\u0430\u0436\u0434\u0435\u043d\u0438\u044f \u0440\u0430\u0437\u043c\u0435\u0440\u043e\u043c \u0434\u043e 3000 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":52758,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-52757","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-novosti-interneta"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"GitHub \u0432\u044b\u0441\u0442\u0443\u043f\u0438\u043b \u0441 \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u043e\u0439\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47GitHub \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u043b \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u043d\u044b\u0439 \u043f\u0440\u043e\u0435\u043a\u0442 \u0434\u043b\u044f \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u043c \u041f\u041e | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"GitHub \u0432\u044b\u0441\u0442\u0443\u043f\u0438\u043b \u0441 \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u043e\u0439\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-11-15T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:00:33+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47GitHub ha avviato un progetto collaborativo per identificare vulnerabilit\u00e0 nel software open source | ProHoster","description":"GitHub ha lanciato un'iniziativa","canonical_url":"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47GitHub \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u043b \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u043d\u044b\u0439 \u043f\u0440\u043e\u0435\u043a\u0442 \u0434\u043b\u044f \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u043c \u041f\u041e | ProHoster","og:description":"GitHub \u0432\u044b\u0441\u0442\u0443\u043f\u0438\u043b \u0441 \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u043e\u0439","og:url":"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-11-15T21:00:00+00:00","article:modified_time":"2020-02-18T11:00:33+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"52757","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 04:44:21","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 12:18:18","updated":"2026-01-24 04:44:21","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/52757","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=52757"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/52757\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media\/52758"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=52757"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=52757"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=52757"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}