Attempts to post the latest Trivy security incident have been marked [dead] (news.ycombinator.com)

by JoshuaDavid 23 comments 90 points
Read article View on HN

23 comments

[−] JoshuaDavid 56d ago
Trivy (a very widely-used security scanner) was recently compromised. Anyone who installed the aquasecurity/trivy-action dependency by tag rather than by sha during a 3 hour period on March 19 was likely compromised. There is a Github security advisory at https://github.com/aquasecurity/trivy/security/advisories/GH...

6 separate people have tried to submit this to HN. All of the submissions are marked as [dead]. I am unsure whether this is a malicious action taken by the actors who compromised trivy or whether it's just the result of prior spam under github.com/aquasecurity, but regardless it is probably not ideal for security advisories to be auto-marked as [dead].

[−] tomhow 55d ago
Please just email us (hn@ycombinator.com) when something like this happens.

Moderators didn't see these submissions or if we did, we didn't know why this project or incident was significant or important.

Now we've seen it, we've boosted the first submission of the incident onto the front page, and updated the URL and title to the most up-to-date/complete page about the incident.

The reason the submissions were being killed is that the GitHub account's address had been banned on HN due to previously being submitted by spam bots.

[−] JoshuaDavid 55d ago
Noted and sent. Thanks for all your hard work.
[−] altairprime 55d ago
I emailed this post to the mods (using the footer contact link) on behalf of OP so they have a chance to assess and reply.
[−] mtmail 55d ago
Looks like the repository URL was marked [dead] for several years, I can't tell why. Best to email the moderator (link in footer).

Big security stories often get republished, one might say reviewed and filtered. For this story I see

opensourcemalware.com - https://news.ycombinator.com/item?id=47449498

stepsecurity.io - https://news.ycombinator.com/item?id=47451081

arstechnica.com - https://news.ycombinator.com/item?id=47464996

and 4 others.

[−] kay_o 55d ago
Looking at https://news.ycombinator.com/from?site=github.com/aquasecuri... around 2024 when the dead started, a spambot ring was repeatedly posting it?

( Make need to turn on "showdead"; to see it in the 2024 they have similar posts .. )

[−] fragmede 55d ago
Oh that's clever. Use the spambot ring to promote the story so that the story gets marked dead because of that! Instead of hiding the news, use the botnet to promote it and use the system against itself.
[−] cluckindan 55d ago
Maybe it was intentionally compromised all along.
[−] akerl_ 55d ago
Yea, this looks like a lingering auto-moderation on the Github repo URL prefix due to past spam attempts.
[−] tptacek 55d ago
You should just mail hn@ycombinator.com about this stuff.

Or: write a short blog post about it, and post that, on your (different) domain.

[−] Heckinator 54d ago
[dead]
[−] robutsume 56d ago
[dead]
[−] bfung 55d ago
[flagged]