Roave / SecurityAdvisories

:closed_lock_with_key: Security advisories as a simple composer exclusion list, updated daily
MIT License
2.73k stars 106 forks source link

Typosquatting - symfont/process #83

Closed Danack closed 3 years ago

Danack commented 3 years ago

Does this project list stuff like tpyo-squatting e.g. symfont/process vs symfony/process

https://www.kernelmode.blog/typosquatting-malware-found-in-composer-repository/

Ocramius commented 3 years ago

Nay, also unlikely to support permutations, as it would explide the repository size

Ocramius commented 3 years ago

You can report symfont/process:* as a security issue to GitHub: it will be picked up.

Danack commented 3 years ago

cool.

Ocramius commented 3 years ago

Meanwhile: https://github.com/Roave/SecurityAdvisories/commit/506ae662828c26fbf1436954388191c452897bde