Replies: 2 comments
|
Data in the |
0 replies
|
Hi @kmbyr23, the The details of this structure are described in https://github.com/ossf/malicious-packages/blob/main/docs/schema_additions.md. These are not hashes of the artifacts themselves (whl, zip, tgz, etc). |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
For example, the SHA-256 hashes listed here: https://osv.dev/vulnerability/MAL-2025-3016 and here: https://osv.dev/vulnerability/MAL-2025-47749
What is the file that is being hashed here? Is it the .whl for the package?
All reactions