Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Malicious submissions should not be available for download in Submission Review or OR #270

Open
rakibansary opened this issue Feb 10, 2022 · 1 comment

Comments

@rakibansary
Copy link
Contributor

Submissions that are flagged by av-scanner-service as infected are still available for download in submission review. Additionally it looks like for infected files no email notification saying the submission is infected is sent out.

@rakibansary
Copy link
Contributor Author

rakibansary commented Feb 10, 2022

@lakshmiathreya

  1. I'll check/confirm if there's a proper email template available for malicious submissions. Generally for good files, an email with a review score of 100/100 is sent out. For a bad file, I only received an email saying a review type of "Virus Scan" was performed on the file, but no final update was given.
  2. Should there be any mechanism to mark/keep track of users who upload malicious files?
  3. What's the expected behaviour after detection of a malicious file? Not show it at all in Submission Review or show the file name, but not make it available for download?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant