-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Chocolatey package held in review due to too many false virus detection positives #61
Comments
|
All of these files are from Ocra. Maybe some malicious executables are built with Ocra, and the Ocra files get tagged? |
@ronaldtse probably, let me check |
Found the original issue at Ocra: larsch/ocra#175 |
Found the offending This file is provided in libmspack which is included via the ruby-libmspack gem (https://github.com/davispuh/ruby-libmspack) |
We've forked Ocra at https://github.com/metanorma/ocra to attempt fixing these issues, and will contribute back if they work... |
@ronaldtse It doesn't look like we can do anything about it. We cannot get rid of Regarding |
@CAMOBAP we will be able to resolve the issues with Orca when we switch to Tebako. However for libmspack - why does this test file get into ruby-libmspack gem? Only the compiled artifact (only the |
As requested here by the Chocolatey admins of our package, #64 (comment) False positivesAll "positives" at VirusTotal for the Metanorma package are false positives, from these engines:
Quite a few of them I've never even heard of: Antiy-AVL, Ikarus, NANO-Antivirus, Gridinsoft, Jiangmin. @CAMOBAP has used DrWeb, SecureAge APEX, VBA32 before. We maintain that the value of an anti-virus scan is about quality - not quantity. Analysis of false positivesHere's an analysis of every false positive file.
I hope this is sufficient for the admins. |
I will update description |
Resubmited |
VirusScan doesn't a problem anymore |
https://community.chocolatey.org/packages/metanorma/1.4.17.20211007#virus
Because our score is either 7 or 8 (tried a couple runs on virustotal.com), it is automatically held up preventing release:
https://www.virustotal.com/gui/file/d006fd078d8c73d0b13a77196944180f6c5cee2b7aeb74240bb5223251210a87?nocache=1
While these are all unknown virus scanners we might still want to remove/update the files that have been falsely flagged as malicious.
The problematic files are:
Is it possible for us to remove or modify these files?
The actual scores are:
The text was updated successfully, but these errors were encountered: