Giter Site home page Giter Site logo

Comments (6)

rados avatar rados commented on June 21, 2024 1

@tonyping, thank you for the report. @az0, I also see this.

from bleachbit.

az0 avatar az0 commented on June 21, 2024

@tonyping

I've read their docs, modified the text of the page to add the "fine print section," and requested a reviewed. The best I could figure out is that it's related to the builds of the new Python branch, so I uploaded all those files individually, but it didn't flag any individual files. I also uploaded the new installer to external scanners, but it didn't give any insights.

Google likes to automate everything, and I don't a way to report a false positive or get more details, so what's left is a blind process of reverse engineering.

For now I removed the folder 4.4.2.2333-mkhon-python310

See also #1448

from bleachbit.

tonyping avatar tonyping commented on June 21, 2024

@tonyping

Google likes to automate everything, and I don't a way to report a false positive or get more details, so what's left is a blind process of reverse engineering.

Yeah I reached a similar conclusion from the docs. They basically want you to just figure it out for yourself, although their criteria for malware does leaves too much room for interpretation and can lead to grey areas.

Those same areas that a software scanner can't reliably judge, nonetheless are still being tasked with. However, given Google's scale, I don't blame them, as I can't see any other feasible solution.

Have you tried Hybrid Analysis? https://www.hybrid-analysis.com

Maybe the sandbox reports show something. I submitted one but they do take a while to process.

from bleachbit.

tonyping avatar tonyping commented on June 21, 2024

Latest nightly:

https://www.hybrid-analysis.com/sample/f8617873259294fe3392a44207e8df0a9996c5cb169f868d97e0e11c04ca997a/64a510f4b3c160a68707138a

from bleachbit.

az0 avatar az0 commented on June 21, 2024

Here's irony: Google flags the latest comment in this discussion as unsafe too.
Screenshot_20230705_203632_Gmail

Security scanners flag BleachBit because

  1. The application contains the Python runtime and GTK toolkit, which are general and contain many capabilities.
  2. By design, the application has to do "unsafe" things such as reading/changing the registry, marking files for deletion, and checking running processes.

In the past with the false positives , the general process is to submit the application for review ("whitelisting"), even though they deal with many users and flagged software, but Google doesn't allow that.

Adding my digital certificate many help, but that's for beta and final releases---not for the CI site.

from bleachbit.

az0 avatar az0 commented on June 21, 2024

Google Search Console identified that https://ci.bleachbit.org/?prefix=dl/4.4.2.2265-mkhon-python310/ was the problem. As I removed it earlier, I requested a re-review. For now, the whole site is still flagged

from bleachbit.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.