Attempts to post the latest Trivy security incident have been marked [dead]
news.ycombinator.com
Attempts to post the latest Trivy security incident have been marked [dead]
1–10 of 28 posts
Re: Attempts to post the latest Trivy security incident have been marked [dead]
#26 separate people have tried to submit this to HN. All of the submissions are marked as [dead]. I am unsure whether this is a malicious action taken by the actors who compromised trivy or whether it's just the result of prior spam under github.com/aquasecurity, but regardless it is probably not ideal for security advisories to be auto-marked as [dead].
Re: Attempts to post the latest Trivy security incident have been marked [dead]
#3Re: Attempts to post the latest Trivy security incident have been marked [dead]
#4Big security stories often get republished, one might say reviewed and filtered. For this story I see
opensourcemalware.com - https://news.ycombinator.com/item?id=47449498
stepsecurity.io - https://news.ycombinator.com/item?id=47451081
arstechnica.com - https://news.ycombinator.com/item?id=47464996
and 4 others.
Re: Attempts to post the latest Trivy security incident have been marked [dead]
#5Looks like the repository URL was marked [dead] for several years, I can't tell why. Best to email the moderator (link in footer). Big security stories often get republished, one might say reviewed and filtered. For this story I see opensourcemalware.com - https://news.ycombinator.com/item?id=47449498 stepsecurity.io - https://news.ycombinator.com/item?id=47451081 arstechnica.com - https://news.ycombinator.com/item?i…
( Make need to turn on "showdead"; to see it in the 2024 they have similar posts .. )
Re: Attempts to post the latest Trivy security incident have been marked [dead]
#6Re: Attempts to post the latest Trivy security incident have been marked [dead]
#7Looks like the repository URL was marked [dead] for several years, I can't tell why. Best to email the moderator (link in footer). Big security stories often get republished, one might say reviewed and filtered. For this story I see opensourcemalware.com - https://news.ycombinator.com/item?id=47449498 stepsecurity.io - https://news.ycombinator.com/item?id=47451081 arstechnica.com - https://news.ycombinator.com/item?i…
Looking at https://news.ycombinator.com/from?site=github.com/aquasecuri... around 2024 when the dead started, a spambot ring was repeatedly posting it? ( Make need to turn on "showdead"; to see it in the 2024 they have similar posts .. )
Re: Attempts to post the latest Trivy security incident have been marked [dead]
#8Re: Attempts to post the latest Trivy security incident have been marked [dead]
#9[flagged]
Re: Attempts to post the latest Trivy security incident have been marked [dead]
#10Looks like the repository URL was marked [dead] for several years, I can't tell why. Best to email the moderator (link in footer). Big security stories often get republished, one might say reviewed and filtered. For this story I see opensourcemalware.com - https://news.ycombinator.com/item?id=47449498 stepsecurity.io - https://news.ycombinator.com/item?id=47451081 arstechnica.com - https://news.ycombinator.com/item?i…
Looking at https://news.ycombinator.com/from?site=github.com/aquasecuri... around 2024 when the dead started, a spambot ring was repeatedly posting it? ( Make need to turn on "showdead"; to see it in the 2024 they have similar posts .. )