googlefonts / googlefonts-project-template

(DEMO) Repository architecture example for a typeface design project
SIL Open Font License 1.1
130 stars 27 forks source link

Fonts artifacts zip shows virus alert in Windows 10 #168

Closed xconsau closed 5 months ago

xconsau commented 5 months ago

I am using the googlefonts-project-template for one of my fonts "Cause" . When I try to download the artifacts zip file, the Windows security center alerts me if a virus and automatically deletes the downloaded zip file. Please see attached screenshot.

artifacts

Artifacts link: https://github.com/xconsau/Cause/actions/runs/8642807521

Upon checking the details of the virus, I found that it is a Trojan located inside the proof HTML files. See attached screenshot:

trojan

simoncozens commented 5 months ago

Thanks for letting us know, I'm taking a look.

simoncozens commented 5 months ago

This is a false positive. There is nothing unusual or suspicious about the HTML and Javascript in the proof file; the nice thing about HTML files is that you can inspect them yourself and confirm this!

The "H" stands for "heuristic" and the "ML" stands for "machine learning", which means that Windows Defender is hallucinating here. I found for "wacatac h ml" on the Internet was (a) people complaining about false positives, and (b) this impressively useless "threat description" from Microsoft. Not our bug!

xconsau commented 5 months ago

Thank you for the swift response, Simon. I added an exclusion rule for the Windows defender for the artifacts zip file. Nothing unusual was found in the download. Thanks once again.