Splode / pomotroid

:tomato: Simple and visually-pleasing Pomodoro timer
https://splode.github.io/pomotroid/
MIT License
4.36k stars 369 forks source link

Ransomware found inside the downloaded for windows artifact (20200409) #77

Closed mazaltod closed 4 years ago

mazaltod commented 4 years ago

downloaded Windows artifact from your web site. The enterprise antivirus found a randsomware. Please check. Thanks

Splode commented 4 years ago

Can you provide more information?

I'd be extremely surprised if that were the case. The artifacts are generated on Travis CI's servers and the project's entire source is open.

Edit: just scanned v0.7.1 Windows artifact with Windows Defender and no issues.

mazaltod commented 4 years ago

I'm not sure to be able to provide the needed information as it could be realted to the network/firefall configuration done outside my control and knowledge. Howerver here is what happends on my laptop

image

and when I continue (Execution of execution): image

image

May be your are right and it is the antivirus policy that I should request to be changed to my staff. However it is very rare that this happen so may be there is somtething to improve. I undestand it is very light and i am sorry not to give more. Have a good day. Thanks, David

Splode commented 4 years ago

Thanks for the details. My guess is that because Pomotroid does not ship with code signing, some anti-virus software will raise an alarm. Unfortunately, as this is a free, hobby project there are no plans to ship with code signing any time soon.

Thanks for contributing!