{"id":52757,"date":"2019-11-16T00:00:00","date_gmt":"2019-11-15T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po"},"modified":"2020-02-18T14:00:33","modified_gmt":"2020-02-18T11:00:33","slug":"github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po","title":{"rendered":"GitHub a lansat un proiect colaborativ pentru identificarea vulnerabilit\u0103\u021bilor \u00een software-ul open-source","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>GitHub <noindex><a rel=\"nofollow\" href=\"https:\/\/github.blog\/2019-11-14-announcing-github-security-lab-securing-the-worlds-code-together\/\">a propus<\/a><\/noindex> ini\u021biativa  <noindex><a rel=\"nofollow\" href=\"https:\/\/securitylab.github.com\/\">GitHub Security Lab<\/a><\/noindex>, av\u00e2nd ca scop organizarea colabor\u0103rii exper\u021bilor \u00een securitate din diverse companii \u0219i organiza\u021bii pentru a identifica vulnerabilit\u0103\u021bile \u0219i a oferi asisten\u021b\u0103 \u00een remedierea acestora \u00een codul proiectelor open-source.  <\/p>\n<p>La ini\u021biativ\u0103 sunt invitate toate companiile \u0219i speciali\u0219tii individuali \u00een securitate cibernetic\u0103 interesa\u021bi. Pentru identificarea vulnerabilit\u0103\u021bii  <noindex><a rel=\"nofollow\" href=\"https:\/\/securitylab.github.com\/bounties\">este prev\u0103zut\u0103<\/a><\/noindex> o recompens\u0103 de p\u00e2n\u0103 la 3000 de dolari, \u00een func\u021bie de gravitatea problemei \u0219i de calitatea raportului. Pentru raportarea problemelor se recomand\u0103 utilizarea uneltelor <noindex><a rel=\"nofollow\" href=\"https:\/\/securitylab.github.com\/tools\/codeql\">CodeQL<\/a><\/noindex>, care permite crearea unui \u0219ablon de cod vulnerabil pentru identificarea prezen\u021bei unei astfel de vulnerabilit\u0103\u021bi \u00een codul altor proiecte (CodeQL ofer\u0103 posibilitatea de a efectua analize semantice ale codului \u0219i de a crea interog\u0103ri pentru a c\u0103uta anumite construc\u021bii).<\/p>\n<p>La ini\u021biativ\u0103 s-au al\u0103turat deja cercet\u0103tori \u00een securitate din companii precum F5, Google, HackerOne, Intel, IOActive, J.P. Morgan, LinkedIn, Microsoft, Mozilla, NCC Group, Oracle, Trail of Bits, Uber \u0219i<br \/>\nVMWare, care \u00een ultimii doi ani <noindex><a rel=\"nofollow\" href=\"https:\/\/securitylab.github.com\/disclosures\">au identificat<\/a><\/noindex> \u0219i <noindex><a rel=\"nofollow\" href=\"https:\/\/securitylab.github.com\/research\">au contribuit la corectarea<\/a><\/noindex> 105 vulnerabilit\u0103\u021bilor \u00een proiecte precum Chromium, libssh2, nucleul Linux, Memcached, UBoot, VLC, Apport, HHVM, Exiv2, FFmpeg, Fizz, libav, Ansible, npm, XNU, Ghostscript, Icecast, Apache Struts, strongSwan, Apache Ignite, rsyslog, Apache Geode \u0219i Hadoop. <\/p>\n<p>Ciclul de via\u021b\u0103 propus de GitHub pentru \u00eentre\u021binerea securit\u0103\u021bii codului presupune ca participan\u021bii la GitHub Security Lab s\u0103 identifice vulnerabilit\u0103\u021bile, dup\u0103 care informa\u021biile despre probleme vor fi transmise \u00eentre\u021bin\u0103torilor \u0219i dezvoltatorilor, care vor dezvolta remedieri, vor conveni asupra momentului divulg\u0103rii informa\u021biilor despre problem\u0103 \u0219i vor informa proiectele dependente despre necesitatea instal\u0103rii versiunii corecte. \u00cen baza de date vor fi stocate \u0219abloane CodeQL care s\u0103 previn\u0103 reapari\u021bia problemelor rezolvate \u00een codul disponibil pe GitHub.<br \/>\n<center><noindex><a rel=\"nofollow\" href=\"https:\/\/github.blog\/wp-content\/uploads\/2019\/11\/Screen-Shot-2019-11-13-at-12.33.17-PM.png\"><img decoding=\"async\" alt=\"GitHub a lansat un proiect colaborativ pentru identificarea vulnerabilit\u0103\u021bilor \u00een software-ul open-source\" src=\"\/wp-content\/uploads\/2019\/11\/f605545e88da52ebd21d412dc7518a71.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p>Prin intermediul interfe\u021bei GitHub, acum este posibil <noindex><a rel=\"nofollow\" href=\"https:\/\/github.blog\/changelog\/2019-11-11-security-advisories-generally-available-can-request-cves\/\">s\u0103 ob\u021bin\u0103<\/a><\/noindex> s\u0103 ob\u021bine\u021bi un identificator CVE pentru problema identificat\u0103 \u0219i s\u0103 preg\u0103ti\u021bi un raport, iar GitHub va trimite automat notific\u0103rile necesare \u0219i va organiza corectarea acestora. Mai mult, dup\u0103 rezolvarea problemei, GitHub va trimite automat cereri de pull pentru actualizarea dependen\u021belor legate de proiectul vulnerabil.<\/p>\n<p>GitHub a introdus de asemenea un catalog al vulnerabilit\u0103\u021bilor <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/advisories\">Baza de Date a Advisory GitHub<\/a><\/noindex>, \u00een care sunt publicate informa\u021bii despre vulnerabilit\u0103\u021bile care afecteaz\u0103 proiectele de pe GitHub \u0219i informa\u021bii pentru urm\u0103rirea pachetelor \u0219i repositoarelor afectate de probleme. CVE-urile men\u021bionate \u00een comentariile de pe GitHub se refer\u0103 acum automat la informa\u021bii detaliate despre vulnerabilitate \u00een baza de date prezentat\u0103. Pentru a automatiza lucrul cu baza de date a fost propus un <noindex><a rel=\"nofollow\" href=\"https:\/\/developer.github.com\/v4\/object\/securityadvisory\/\">API<\/a><\/noindex>.<\/p>\n<p>De asemenea, s-a raportat despre o actualizare <noindex><a rel=\"nofollow\" href=\"https:\/\/developer.github.com\/partnerships\/token-scanning\/\">serviciului<\/a><\/noindex> pentru a proteja \u00eempotriva <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50374\">inclusului<\/a><\/noindex>  \u00een repositoarele publice accesibile<br \/>\na datelor confiden\u021biale, cum ar fi token-uri de autentificare \u0219i chei de acces. \u00cen timpul comiterii, scannerul verific\u0103 formatele tipice ale cheilor \u0219i token-urilor utilizate <noindex><a rel=\"nofollow\" href=\"https:\/\/help.github.com\/en\/github\/administering-a-repository\/about-token-scanning\">de 20 de furnizori de servicii cloud<\/a><\/noindex>, inclusiv API-ul Alibaba Cloud, Amazon Web Services (AWS), Azure, Google Cloud, Slack \u0219i Stripe. \u00cen cazul \u00een care este detectat un token, furnizorul de servicii prime\u0219te o solicitare pentru a confirma scurgerea \u0219i revocarea token-urilor compromise. \u00cencep\u00e2nd de ieri, pe l\u00e2ng\u0103 formatele sus\u021binute anterior, a fost ad\u0103ugat\u0103 suportul pentru identificarea token-urilor GoCardless, HashiCorp, Postman \u0219i Tencent.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Sursa: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51867\">opennet.ro<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>GitHub \u0432\u044b\u0441\u0442\u0443\u043f\u0438\u043b \u0441 \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u043e\u0439 GitHub Security Lab, \u043d\u0430\u0446\u0435\u043b\u0435\u043d\u043d\u043e\u0439 \u043d\u0430 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u044e \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u043d\u043e\u0439 \u0440\u0430\u0431\u043e\u0442\u044b \u044d\u043a\u0441\u043f\u0435\u0440\u0442\u043e\u0432 \u043f\u043e \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0439 \u0438 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0439 \u0434\u043b\u044f \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0438 \u0441\u043e\u0434\u0435\u0439\u0441\u0442\u0432\u0438\u044e \u043f\u043e \u0438\u0445 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u044e \u0432 \u043a\u043e\u0434\u0435 \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u0445 \u043f\u0440\u043e\u0435\u043a\u0442\u043e\u0432. \u0414\u043b\u044f \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u043a \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u0435 \u043f\u0440\u0438\u0433\u043b\u0430\u0448\u0430\u044e\u0442\u0441\u044f \u0432\u0441\u0435 \u0437\u0430\u0438\u043d\u0442\u0435\u0440\u0435\u0441\u043e\u0432\u0430\u043d\u043d\u044b\u0435 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 \u0438 \u0438\u043d\u0434\u0438\u0432\u0438\u0434\u0443\u0430\u043b\u044c\u043d\u044b\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u0438\u0441\u0442\u044b \u043f\u043e \u043a\u043e\u043c\u043f\u044c\u044e\u0442\u0435\u0440\u043d\u043e\u0439 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438. \u0417\u0430 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u0440\u0435\u0434\u0443\u0441\u043c\u043e\u0442\u0440\u0435\u043d\u0430 \u0432\u044b\u043f\u043b\u0430\u0442\u0430 \u0432\u043e\u0437\u043d\u0430\u0433\u0440\u0430\u0436\u0434\u0435\u043d\u0438\u044f \u0440\u0430\u0437\u043c\u0435\u0440\u043e\u043c \u0434\u043e 3000 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":52758,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-52757","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"GitHub \u0432\u044b\u0441\u0442\u0443\u043f\u0438\u043b \u0441 \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u043e\u0439\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47GitHub \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u043b \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u043d\u044b\u0439 \u043f\u0440\u043e\u0435\u043a\u0442 \u0434\u043b\u044f \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u043c \u041f\u041e | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"GitHub \u0432\u044b\u0441\u0442\u0443\u043f\u0438\u043b \u0441 \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u043e\u0439\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-11-15T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:00:33+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47GitHub a lansat un proiect colaborativ pentru identificarea vulnerabilit\u0103\u021bilor \u00een software-ul open-source | ProHoster","description":"GitHub a lansat o ini\u021biativ\u0103","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47GitHub \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u043b \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u043d\u044b\u0439 \u043f\u0440\u043e\u0435\u043a\u0442 \u0434\u043b\u044f \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u043c \u041f\u041e | ProHoster","og:description":"GitHub \u0432\u044b\u0441\u0442\u0443\u043f\u0438\u043b \u0441 \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u043e\u0439","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/github-zapustil-sovmestnyj-proekt-dlya-vyyavleniya-uyazvimostej-v-otkrytom-po","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-11-15T21:00:00+00:00","article:modified_time":"2020-02-18T11:00:33+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"52757","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 04:44:21","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 12:18:18","updated":"2026-01-24 04:44:21","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/52757","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=52757"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/52757\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media\/52758"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=52757"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=52757"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=52757"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}