Live data from Hacker News

Attempts to post the latest Trivy security incident have been marked [dead]

news.ycombinator.com

1–10 of 28 posts

Re: Attempts to post the latest Trivy security incident have been marked [dead]

#2
Trivy (a very widely-used security scanner) was recently compromised. Anyone who installed the aquasecurity/trivy-action dependency by tag rather than by sha during a 3 hour period on March 19 was likely compromised. There is a Github security advisory at https://github.com/aquasecurity/trivy/security/advisories/GH...

6 separate people have tried to submit this to HN. All of the submissions are marked as [dead]. I am unsure whether this is a malicious action taken by the actors who compromised trivy or whether it's just the result of prior spam under github.com/aquasecurity, but regardless it is probably not ideal for security advisories to be auto-marked as [dead].

Re: Attempts to post the latest Trivy security incident have been marked [dead]

#4
Looks like the repository URL was marked [dead] for several years, I can't tell why. Best to email the moderator (link in footer).

Big security stories often get republished, one might say reviewed and filtered. For this story I see

opensourcemalware.com - https://news.ycombinator.com/item?id=47449498

stepsecurity.io - https://news.ycombinator.com/item?id=47451081

arstechnica.com - https://news.ycombinator.com/item?id=47464996

and 4 others.

Re: Attempts to post the latest Trivy security incident have been marked [dead]

#5
post #4

Looks like the repository URL was marked [dead] for several years, I can't tell why. Best to email the moderator (link in footer). Big security stories often get republished, one might say reviewed and filtered. For this story I see opensourcemalware.com - https://news.ycombinator.com/item?id=47449498 stepsecurity.io - https://news.ycombinator.com/item?id=47451081 arstechnica.com - https://news.ycombinator.com/item?i…

Looking at https://news.ycombinator.com/from?site=github.com/aquasecuri... around 2024 when the dead started, a spambot ring was repeatedly posting it?

( Make need to turn on "showdead"; to see it in the 2024 they have similar posts .. )

Re: Attempts to post the latest Trivy security incident have been marked [dead]

#7
post #5
post #4

Looks like the repository URL was marked [dead] for several years, I can't tell why. Best to email the moderator (link in footer). Big security stories often get republished, one might say reviewed and filtered. For this story I see opensourcemalware.com - https://news.ycombinator.com/item?id=47449498 stepsecurity.io - https://news.ycombinator.com/item?id=47451081 arstechnica.com - https://news.ycombinator.com/item?i…

Looking at https://news.ycombinator.com/from?site=github.com/aquasecuri... around 2024 when the dead started, a spambot ring was repeatedly posting it? ( Make need to turn on "showdead"; to see it in the 2024 they have similar posts .. )

Maybe it was intentionally compromised all along.

Re: Attempts to post the latest Trivy security incident have been marked [dead]

#10
post #5
post #4

Looks like the repository URL was marked [dead] for several years, I can't tell why. Best to email the moderator (link in footer). Big security stories often get republished, one might say reviewed and filtered. For this story I see opensourcemalware.com - https://news.ycombinator.com/item?id=47449498 stepsecurity.io - https://news.ycombinator.com/item?id=47451081 arstechnica.com - https://news.ycombinator.com/item?i…

Looking at https://news.ycombinator.com/from?site=github.com/aquasecuri... around 2024 when the dead started, a spambot ring was repeatedly posting it? ( Make need to turn on "showdead"; to see it in the 2024 they have similar posts .. )

Oh that's clever. Use the spambot ring to promote the story so that the story gets marked dead because of that! Instead of hiding the news, use the botnet to promote it and use the system against itself.
Post reply on HN