Trivy (a very widely-used security scanner) was recently compromised. Anyone who installed the aquasecurity/trivy-action dependency by tag rather than by sha during a 3 hour period on March 19 was likely compromised. There is a Github security advisory at https://github.com/aquasecurity/trivy/security/advisories/GH... 6 separate people have tried to submit this to HN. All of the submissions are marked as [dead]. I am…
Attempts to post the latest Trivy security incident have been marked [dead]
11–20 of 28 posts
Re: Attempts to post the latest Trivy security incident have been marked [dead]
#12Looks like the repository URL was marked [dead] for several years, I can't tell why. Best to email the moderator (link in footer). Big security stories often get republished, one might say reviewed and filtered. For this story I see opensourcemalware.com - https://news.ycombinator.com/item?id=47449498 stepsecurity.io - https://news.ycombinator.com/item?id=47451081 arstechnica.com - https://news.ycombinator.com/item?i…
Re: Attempts to post the latest Trivy security incident have been marked [dead]
#13Earlier quoted context omitted.
Looking at https://news.ycombinator.com/from?site=github.com/aquasecuri... around 2024 when the dead started, a spambot ring was repeatedly posting it? ( Make need to turn on "showdead"; to see it in the 2024 they have similar posts .. )
Oh that's clever. Use the spambot ring to promote the story so that the story gets marked dead because of that! Instead of hiding the news, use the botnet to promote it and use the system against itself.
Re: Attempts to post the latest Trivy security incident have been marked [dead]
#14Or: write a short blog post about it, and post that, on your (different) domain.
Re: Attempts to post the latest Trivy security incident have been marked [dead]
#15You should just mail hn@ycombinator.com about this stuff. Or: write a short blog post about it, and post that, on your (different) domain.
It's certainly worked. Lots of people have seen this and now have a slightly worse opinion of HN moderation.
Re: Attempts to post the latest Trivy security incident have been marked [dead]
#16You should just mail hn@ycombinator.com about this stuff. Or: write a short blog post about it, and post that, on your (different) domain.
What if their goal is more to raise awareness about HN moderation practices than to fix the problem quickly? It's certainly worked. Lots of people have seen this and now have a slightly worse opinion of HN moderation.
Re: Attempts to post the latest Trivy security incident have been marked [dead]
#17You should just mail hn@ycombinator.com about this stuff. Or: write a short blog post about it, and post that, on your (different) domain.
What if their goal is more to raise awareness about HN moderation practices than to fix the problem quickly? It's certainly worked. Lots of people have seen this and now have a slightly worse opinion of HN moderation.
What practices?
Re: Attempts to post the latest Trivy security incident have been marked [dead]
#18Trivy (a very widely-used security scanner) was recently compromised. Anyone who installed the aquasecurity/trivy-action dependency by tag rather than by sha during a 3 hour period on March 19 was likely compromised. There is a Github security advisory at https://github.com/aquasecurity/trivy/security/advisories/GH... 6 separate people have tried to submit this to HN. All of the submissions are marked as [dead]. I am…
Moderators didn't see these submissions or if we did, we didn't know why this project or incident was significant or important.
Now we've seen it, we've boosted the first submission of the incident onto the front page, and updated the URL and title to the most up-to-date/complete page about the incident.
The reason the submissions were being killed is that the GitHub account's address had been banned on HN due to previously being submitted by spam bots.
Re: Attempts to post the latest Trivy security incident have been marked [dead]
#19Trivy (a very widely-used security scanner) was recently compromised. Anyone who installed the aquasecurity/trivy-action dependency by tag rather than by sha during a 3 hour period on March 19 was likely compromised. There is a Github security advisory at https://github.com/aquasecurity/trivy/security/advisories/GH... 6 separate people have tried to submit this to HN. All of the submissions are marked as [dead]. I am…
Please just email us (hn@ycombinator.com) when something like this happens. Moderators didn't see these submissions or if we did, we didn't know why this project or incident was significant or important. Now we've seen it, we've boosted the first submission of the incident onto the front page, and updated the URL and title to the most up-to-date/complete page about the incident. The reason the submissions were being…
Re: Attempts to post the latest Trivy security incident have been marked [dead]
#20[flagged]
I did not see it but I was not affected since I had pinned the tag and used a cool down; practices whose value I reminded my coworkers of with this post.