Skip to content

Many security_advisory.published failing webhook events originating from similar npm packages #4578

Open
@robase

Description

My github org is currently receiving many webhooks of the security_advisory.published type. My understanding is that these advisories are general in nature and are not necessarily received due to a specific package being used within an org (please correct me if wrong).

The reason I'm raising this is that there appear to be many junk malware type advisories being pushed out through the database:

see: https://github.com/advisories?query=type%3Amalware

example advisory: GHSA-hh4g-p2q6-7fvj

image

These advisories would need to be reviewed before being sent out, is that correct? An interesting note is that these events are also all failing the X-Hub-Signature-256 check for the github app installed in my org receiving the webhook events

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions