Malware & known vulnerabilities
Two different questions, two different answers:
"Is this package KNOWN-BAD?" "Does this package behave badly?" ──────────────────────────── ──────────────────────────────── advisory database (a list) capability rules (behaviour) MALWARE.DEPENDENCY.KNOWN MALWARE.DROPPER / SUSPECT.EXFIL / ... VULNERABLE.DEPENDENCY.KNOWN (tutorial 02)
Both run offline against data shipped with the tool. See 06 to refresh it.
lockfile ──┬──▶ name+version in the MALICIOUS list? ──▶ MALWARE.DEPENDENCY.KNOWN.001
│ (critical — do not install)
└──▶ name+version in the VULNERABLE list? ──▶ VULNERABLE.DEPENDENCY.KNOWN.001
(severity from the advisory) TYPOSQUAT DEPENDENCY CONFUSION
───────── ────────────────────
you meant: requests your private pkg: acme-internal (internal registry)
you got: reqeusts attacker publishes: acme-internal (public registry,
got: python-requests3 higher version) ──▶ pulled instead
│ │
▼ ▼
SUSPECT.TYPOSQUAT.* SUSPECT.DEPENDENCYCONFUSION.*OFFLINE (default) ONLINE (--online) — asks the registry ───────────────── ────────────────────────────────────── known-bad lists + was this version YANKED by its publisher? name-shape heuristics + is the pin far behind (downgrade attack)? behaviour rules + does the lockfile hash match the registry? + provenance / attestation (tutorial 05)
cordon-scanner scan . # offline: safe, reproducible, air-gap-ready cordon-scanner scan . --online # + live registry questions (not reproducible)
A vulnerability three levels deep that your code never calls is not the same as one you invoke on every request. That is reachability, tutorial 04.
Next: 04 · Reachability.