<turbo-stream action="append" target="posts_list"><template>    <div class="postbit" id="76867" data-post-id="76867">
  <section>
    <div class="post-wrap">


					<div class="post-header">
		        <div class="user-avatar">
		          <img alt="greysteil" src="https://forum.elixirforum.com/user_avatar/forum.elixirforum.com/greysteil/120/9198_2.png" width="120" height="120" />
		        </div>
					
						<div class="user-details">
		          <div class="user-name">
		            <h3>
                  greysteil
                    <span class="op-star" title="Thread Starter">
                      <img alt="OP" class="op-star-icon" src="/assets/thread-icons/thread-icon-thread-starter-df91e872.png" />
                    </span>
                  </h3>
		          </div>
						
						</div>
					
					</div>

	        <div class="thread-main">
	            <div class="post-body" data-turbo="false">
								<p>Awesome!</p>
<p>Agree a web API to serve the data is the way to go - should be easy to use the GitHub repo as a backend for that, too, and get the benefit of making it easy for folks to contribute.</p>
<p><img src="https://forum.elixirforum.com/images/emoji/apple/raising_hands.png?v=15" title=":raising_hands:" class="emoji only-emoji" alt=":raising_hands:" loading="lazy" width="20" height="20"></p> 
	            </div>

	            <div class="base-line">
	                <div class="thread-counters">
	                    <span class="thread-count count-likes js-likers-trigger" title="Likes" data-post-id="76867" data-batch-url="/posts/batch_likers">
                        2
                      </span>
                      <!-- <span class="thread-count js-solved-indicator" title="Marked as solution"></span> -->
	                </div>
	                <div class="go-to-post">
	                  <a title="Go to post" alt="Go to post" href="https://forum.elixirforum.com/t/creating-a-public-vulnerabilities-database/13467/13">Post #12</a>
	                </div>
	            </div>
              <div id="likers-container-76867" 
                   class="likers-container"
                   data-first-post="false"
                   data-batch-url="/posts/batch_likers">
                   <div class="likers-placeholder" 
                     data-likers-post-id="76867"
                     data-batch-url="/posts/batch_likers">
                  <div class="post-likers"></div>
                </div>
              </div>
	        </div>
			

    </div>

    <div class="triangle-top-right type-standard-post cat-standard-post" title="Post #12"></div>
  </section>
</div>
    <div class="postbit" id="170757" data-post-id="170757">
  <section>
    <div class="post-wrap">


					<div class="post-header">
		        <div class="user-avatar">
		          <img alt="kitplummer" src="https://forum.elixirforum.com/user_avatar/forum.elixirforum.com/kitplummer/120/18846_2.png" width="120" height="120" />
		        </div>
					
						<div class="user-details">
		          <div class="user-name">
		            <h3>
                  kitplummer
                  </h3>
		          </div>
						
						</div>
					
					</div>

	        <div class="thread-main">
	            <div class="post-body" data-turbo="false">
								<p>Couple years later…</p>
<p>Doesn’t seem like there’s a lot of action in the database.  Probably a combination of research isn’t happening on Elixir things - at least out of the Phoenix and its periphery.  Maybe with mix_audit getting going it’ll help.</p>
<p>Doesn’t look like <a href="http://elixirsecurity.com" rel="noopener nofollow ugc">elixirsecurity.com</a> made it - redirects to <a class="mention" href="/u/griffinbyatt" rel="nofollow">@griffinbyatt</a> blog.  And the <a href="http://elixiradvisories.org" rel="noopener nofollow ugc">elixiradvisories.org</a> site, looks like it died on the vine.</p>
<p>I wouldn’t mind help picking on the <a href="http://elixiradivsories.org" rel="noopener nofollow ugc">elixiradivsories.org</a> <a class="mention" href="/u/maennchen" rel="nofollow">@maennchen</a> - at least to get it back to displaying thing correctly.  Have a few other thoughts…</p> 
	            </div>

	            <div class="base-line">
	                <div class="thread-counters">
	                    <span class="thread-count count-likes js-likers-trigger" title="Likes" data-post-id="170757" data-batch-url="/posts/batch_likers">
                        0
                      </span>
                      <!-- <span class="thread-count js-solved-indicator" title="Marked as solution"></span> -->
	                </div>
	                <div class="go-to-post">
	                  <a title="Go to post" alt="Go to post" href="https://forum.elixirforum.com/t/creating-a-public-vulnerabilities-database/13467/14">Post #13</a>
	                </div>
	            </div>
              <div id="likers-container-170757" 
                   class="likers-container"
                   data-first-post="false"
                   data-batch-url="/posts/batch_likers">
                   <div class="likers-placeholder" 
                     data-likers-post-id="170757"
                     data-batch-url="/posts/batch_likers">
                  <div class="post-likers"></div>
                </div>
              </div>
	        </div>
			

    </div>

    <div class="triangle-top-right type-standard-post cat-standard-post" title="Post #13"></div>
  </section>
</div>
    <div class="postbit" id="170760" data-post-id="170760">
  <section>
    <div class="post-wrap">


					<div class="post-header">
		        <div class="user-avatar">
		          <img alt="danschultzer" src="https://forum.elixirforum.com/user_avatar/forum.elixirforum.com/danschultzer/120/4942_2.png" width="120" height="120" />
		        </div>
					
						<div class="user-details">
		          <div class="user-name">
		            <h3>
                  danschultzer
                  </h3>
		          </div>
						
			          <div class="user-title">
									<span>Pow Core Team</span>
			          </div>
						</div>
					
					</div>

	        <div class="thread-main">
	            <div class="post-body" data-turbo="false">
								<p>Yeah, there are very few security advisories being published in the Elixir community. Seems like most security vulnerabilities just gets patched without any advisory.</p>
<p>It’s unfortunate, but I don’t blame devs. I use GitHub Security Advisories but have no idea how I otherwise would handle the process of getting CVE id and such. Github makes it so easy, so hopefully it’ll ease the burden and we’ll start to see a lot more advisories being published.</p>
<p>The good thing is that the repo is active, and services like dependabot uses it.</p>
<p>Edit: It would be really nice to see that repo being a more integrated part of the Elixir community though. Maybe used on hex.pm.</p> 
	            </div>

	            <div class="base-line">
	                <div class="thread-counters">
	                    <span class="thread-count count-likes js-likers-trigger" title="Likes" data-post-id="170760" data-batch-url="/posts/batch_likers">
                        0
                      </span>
                      <!-- <span class="thread-count js-solved-indicator" title="Marked as solution"></span> -->
	                </div>
	                <div class="go-to-post">
	                  <a title="Go to post" alt="Go to post" href="https://forum.elixirforum.com/t/creating-a-public-vulnerabilities-database/13467/15">Post #14</a>
	                </div>
	            </div>
              <div id="likers-container-170760" 
                   class="likers-container"
                   data-first-post="false"
                   data-batch-url="/posts/batch_likers">
                   <div class="likers-placeholder" 
                     data-likers-post-id="170760"
                     data-batch-url="/posts/batch_likers">
                  <div class="post-likers"></div>
                </div>
              </div>
	        </div>
			

    </div>

    <div class="triangle-top-right type-standard-post cat-standard-post" title="Post #14"></div>
  </section>
</div>
    <div class="postbit" id="170817" data-post-id="170817">
  <section>
    <div class="post-wrap">


					<div class="post-header">
		        <div class="user-avatar">
		          <img alt="greysteil" src="https://forum.elixirforum.com/user_avatar/forum.elixirforum.com/greysteil/120/9198_2.png" width="120" height="120" />
		        </div>
					
						<div class="user-details">
		          <div class="user-name">
		            <h3>
                  greysteil
                    <span class="op-star" title="Thread Starter">
                      <img alt="OP" class="op-star-icon" src="/assets/thread-icons/thread-icon-thread-starter-df91e872.png" />
                    </span>
                  </h3>
		          </div>
						
						</div>
					
					</div>

	        <div class="thread-main">
	            <div class="post-body" data-turbo="false">
								<p>Happy to help with anything on the database, be that:</p>
<ol>
<li>keeping merging PRs as/when folks submit them to the database</li>
<li>add additional maintainers to the database (after auditing their GitHub account, of course)</li>
<li>transferring the database to another namespace, if folks want</li>
</ol>
<p>When I started the database I was building Dependabot, which was directly consuming from it. Since then, Dependabot got acquire by GitHub, and I ended up working on all things related to code scanning there. Dependabot still consumes the database though <img src="https://forum.elixirforum.com/images/emoji/apple/slight_smile.png?v=15" title=":slight_smile:" class="emoji" alt=":slight_smile:" loading="lazy" width="20" height="20"></p>
<p>Longer term, I’d love to see the database become part of <a href="http://github.com/advisories" class="inline-onebox" rel="noopener nofollow ugc">GitHub Advisory Database · GitHub</a>. That DB</p>
<ul>
<li>is licensed under <a href="https://help.github.com/en/github/site-policy/github-additional-product-terms#11-advisory-database" rel="noopener nofollow ugc">Creative Commons Attribution 4.0</a>, which I think is acceptable</li>
<li>is easy for maintainers to contribute to (for supported languages, which don’t yet include Elixir) and linked up to a flow where GitHub will issue CVEs when required/desired (which <strong>is</strong> already supported for Elixir)</li>
<li>receives dedicated curation (we have folks at GitHub who are paid to maintain it and to review all entries in the NVD for missing entries)</li>
</ul>
<p>We’re not there quite yet on adding support for Elixir to <a href="http://github.com/advisories" class="inline-onebox" rel="noopener nofollow ugc">GitHub Advisory Database · GitHub</a> - the blocker on GitHub’s side is having our curation tooling and team in a place where they can take on new languages. In the meantime I’m more than happy to keep doing the right thing on <a href="https://github.com/dependabot/elixir-security-advisories" class="inline-onebox" rel="noopener nofollow ugc">GitHub - dependabot/elixir-security-advisories: Old database of Elixir security advisories before the GitHub Security Advisory DB supported Hex / Elixir. · GitHub</a>.</p> 
	            </div>

	            <div class="base-line">
	                <div class="thread-counters">
	                    <span class="thread-count count-likes js-likers-trigger" title="Likes" data-post-id="170817" data-batch-url="/posts/batch_likers">
                        7
                      </span>
                      <!-- <span class="thread-count js-solved-indicator" title="Marked as solution"></span> -->
	                </div>
	                <div class="go-to-post">
	                  <a title="Go to post" alt="Go to post" href="https://forum.elixirforum.com/t/creating-a-public-vulnerabilities-database/13467/16">Post #15</a>
	                </div>
	            </div>
              <div id="likers-container-170817" 
                   class="likers-container"
                   data-first-post="false"
                   data-batch-url="/posts/batch_likers">
                   <div class="likers-placeholder" 
                     data-likers-post-id="170817"
                     data-batch-url="/posts/batch_likers">
                  <div class="post-likers"></div>
                </div>
              </div>
	        </div>
			

    </div>

    <div class="triangle-top-right type-standard-post cat-standard-post" title="Post #15"></div>
  </section>
</div>
    <div class="postbit" id="170863" data-post-id="170863">
  <section>
    <div class="post-wrap">


					<div class="post-header">
		        <div class="user-avatar">
		          <img alt="kitplummer" src="https://forum.elixirforum.com/user_avatar/forum.elixirforum.com/kitplummer/120/18846_2.png" width="120" height="120" />
		        </div>
					
						<div class="user-details">
		          <div class="user-name">
		            <h3>
                  kitplummer
                  </h3>
		          </div>
						
						</div>
					
					</div>

	        <div class="thread-main">
	            <div class="post-body" data-turbo="false">
								<p>Expanding the scope a little bit.  I’d like to see more responsibilities for these things within the hex.pm ecosystem - as the centralized package source.  Curious what you guys think about <a href="https://reproducible-builds.org" rel="noopener nofollow ugc">https://reproducible-builds.org</a> too.</p>
<p>I think transitioning the database to <a href="http://github.com/advisories" class="inline-onebox" rel="noopener nofollow ugc">GitHub Advisory Database · GitHub</a> makes sense as things evolve at Github.</p>
<p>I’m also thinking it would make sense to get mix_audit into Hex, as a first-class citizen.  I believe the “audit” task and reproducible builds would go a long way to “assuring” the quality of the package/dependency environment.</p>
<p>Caveat, I’m doing a little bit of research into the Hex ecosystem, in terms of risk associated with dependencies and source repositories.  I know similar things have been done on the NPM and Python ecosystems - both to raise aware of security in dependencies and adjudicate packages (especially critical ones).  I’m tying a few loose ends then will make my work available (probably here first) then to the wider Elixir community.  Will of course appreciate any feedback.</p>
<p>One of the obvious things is that Hex doesn’t require or verify source repositories - in fact the spec provides only an arbitrary place for a source link (with an arbitrary key) making it difficult to traverse from package to source in any automated way.  Not impossible, but any complexity or lack of standard creates potential holes.</p> 
	            </div>

	            <div class="base-line">
	                <div class="thread-counters">
	                    <span class="thread-count count-likes js-likers-trigger" title="Likes" data-post-id="170863" data-batch-url="/posts/batch_likers">
                        3
                      </span>
                      <!-- <span class="thread-count js-solved-indicator" title="Marked as solution"></span> -->
	                </div>
	                <div class="go-to-post">
	                  <a title="Go to post" alt="Go to post" href="https://forum.elixirforum.com/t/creating-a-public-vulnerabilities-database/13467/17">Post #16</a>
	                </div>
	            </div>
              <div id="likers-container-170863" 
                   class="likers-container"
                   data-first-post="false"
                   data-batch-url="/posts/batch_likers">
                   <div class="likers-placeholder" 
                     data-likers-post-id="170863"
                     data-batch-url="/posts/batch_likers">
                  <div class="post-likers"></div>
                </div>
              </div>
	        </div>
			

    </div>

    <div class="triangle-top-right type-standard-post cat-standard-post" title="Post #16"></div>
  </section>
</div>
    <div class="postbit" id="170992" data-post-id="170992">
  <section>
    <div class="post-wrap">


					<div class="post-header">
		        <div class="user-avatar">
		          <img alt="maennchen" src="https://forum.elixirforum.com/user_avatar/forum.elixirforum.com/maennchen/120/32742_2.png" width="120" height="120" />
		        </div>
					
						<div class="user-details">
		          <div class="user-name">
		            <h3>
                  maennchen
                  </h3>
		          </div>
						
						</div>
					
					</div>

	        <div class="thread-main">
	            <div class="post-body" data-turbo="false">
								<p><a class="mention" href="/u/kitplummer" rel="nofollow">@kitplummer</a> I kind of put that project on ice since it basically got no traction at all from the community.</p>
<p>If you’d like  to pick it back up, you’re very welcome to do so. If there’s any interest in the community, I’d love to make this work as well.</p>
<blockquote>
<p>I’m also thinking it would make sense to get mix_audit into Hex, as a first-class citizen.</p>
</blockquote>
<p>That’s what I wanted to test-drive with this repo: <a href="https://github.com/ex-security-advisory/cli-client" class="inline-onebox" rel="noopener nofollow ugc">GitHub - ex-security-advisory/cli-client: ⚠ Client for the Elixir Security Vulnerability Project API. · GitHub</a></p> 
	            </div>

	            <div class="base-line">
	                <div class="thread-counters">
	                    <span class="thread-count count-likes js-likers-trigger" title="Likes" data-post-id="170992" data-batch-url="/posts/batch_likers">
                        0
                      </span>
                      <!-- <span class="thread-count js-solved-indicator" title="Marked as solution"></span> -->
	                </div>
	                <div class="go-to-post">
	                  <a title="Go to post" alt="Go to post" href="https://forum.elixirforum.com/t/creating-a-public-vulnerabilities-database/13467/18">Post #17</a>
	                </div>
	            </div>
              <div id="likers-container-170992" 
                   class="likers-container"
                   data-first-post="false"
                   data-batch-url="/posts/batch_likers">
                   <div class="likers-placeholder" 
                     data-likers-post-id="170992"
                     data-batch-url="/posts/batch_likers">
                  <div class="post-likers"></div>
                </div>
              </div>
	        </div>
			

    </div>

    <div class="triangle-top-right type-standard-post cat-standard-post" title="Post #17"></div>
  </section>
</div>
    <div class="postbit" id="171013" data-post-id="171013">
  <section>
    <div class="post-wrap">


					<div class="post-header">
		        <div class="user-avatar">
		          <img alt="kitplummer" src="https://forum.elixirforum.com/user_avatar/forum.elixirforum.com/kitplummer/120/18846_2.png" width="120" height="120" />
		        </div>
					
						<div class="user-details">
		          <div class="user-name">
		            <h3>
                  kitplummer
                  </h3>
		          </div>
						
						</div>
					
					</div>

	        <div class="thread-main">
	            <div class="post-body" data-turbo="false">
								<p>I’m definitely interested in picking up the “let’s make the Elixir package ecosystem better” torch.  By better I mean pretty much replicate NPM’s response:</p>
<ul>
<li>Create a “security” effort: <a href="https://www.npmjs.com/policies/security" rel="noopener nofollow ugc">https://www.npmjs.com/policies/security</a></li>
<li>Make the advisories core to Hex.pm: <a href="https://www.npmjs.com/advisories" rel="noopener nofollow ugc">https://www.npmjs.com/advisories</a></li>
<li>Inform about currency: <a href="https://docs.npmjs.com/cli-commands/outdated.html" rel="noopener nofollow ugc">https://docs.npmjs.com/cli-commands/outdated.html</a></li>
</ul>
<p>Snyk highlights some other things as well: <a href="https://snyk.io/blog/ten-npm-security-best-practices/" class="inline-onebox" rel="noopener nofollow ugc">10 npm Security Best Practices | Snyk</a></p>
<p>And I also believe there’s a need to address other obvious risks: such as the reproducible build problem and general bus-factor of the flattened package ecosystem/transitive dependency matrix explosion.</p> 
	            </div>

	            <div class="base-line">
	                <div class="thread-counters">
	                    <span class="thread-count count-likes js-likers-trigger" title="Likes" data-post-id="171013" data-batch-url="/posts/batch_likers">
                        1
                      </span>
                      <!-- <span class="thread-count js-solved-indicator" title="Marked as solution"></span> -->
	                </div>
	                <div class="go-to-post">
	                  <a title="Go to post" alt="Go to post" href="https://forum.elixirforum.com/t/creating-a-public-vulnerabilities-database/13467/19">Post #18</a>
	                </div>
	            </div>
              <div id="likers-container-171013" 
                   class="likers-container"
                   data-first-post="false"
                   data-batch-url="/posts/batch_likers">
                   <div class="likers-placeholder" 
                     data-likers-post-id="171013"
                     data-batch-url="/posts/batch_likers">
                  <div class="post-likers"></div>
                </div>
              </div>
	        </div>
			

    </div>

    <div class="triangle-top-right type-standard-post cat-standard-post" title="Post #18"></div>
  </section>
</div>
    <div class="postbit" id="171016" data-post-id="171016">
  <section>
    <div class="post-wrap">


					<div class="post-header">
		        <div class="user-avatar">
		          <img alt="ericmj" src="https://forum.elixirforum.com/user_avatar/forum.elixirforum.com/ericmj/120/25920_2.png" width="120" height="120" />
		        </div>
					
						<div class="user-details">
		          <div class="user-name">
		            <h3>
                  ericmj
                  </h3>
		          </div>
						
			          <div class="user-title">
									<span>Elixir Core Team</span>
			          </div>
						</div>
					
					</div>

	        <div class="thread-main">
	            <div class="post-body" data-turbo="false">
								<p>There is a Google Summer of Code proposal project [1] for adding features to Hex that will allow users to report security vulnerabilities, maintaining a database of confirmed vulnerabilities, and displaying the reports on the hex.pm website and CLI tooling. I have talked about this in the past [2] and I hope it can work similar to NPM’s feature set for reporting and curating vulnerabilities that <a class="mention" href="/u/kitplummer" rel="nofollow">@kitplummer</a> linked to.</p>
<p>[1] <a href="https://github.com/erlef/gsoc/wiki/Project:-Elixir#idea-2-package-vulnerability-disclosure-for-hex" class="inline-onebox" rel="noopener nofollow ugc">Home · erlef/gsoc Wiki · GitHub</a><br>
[2] <a href="https://forum.elixirforum.com/t/create-hex-pm-vulnerability-disclosure-feature/15905/7" rel="nofollow">https://forum.elixirforum.com/t/create-hex-pm-vulnerability-disclosure-feature/15905/7</a></p> 
	            </div>

	            <div class="base-line">
	                <div class="thread-counters">
	                    <span class="thread-count count-likes js-likers-trigger" title="Likes" data-post-id="171016" data-batch-url="/posts/batch_likers">
                        8
                      </span>
                      <!-- <span class="thread-count js-solved-indicator" title="Marked as solution"></span> -->
	                </div>
	                <div class="go-to-post">
	                  <a title="Go to post" alt="Go to post" href="https://forum.elixirforum.com/t/creating-a-public-vulnerabilities-database/13467/20">Post #19</a>
	                </div>
	            </div>
              <div id="likers-container-171016" 
                   class="likers-container"
                   data-first-post="false"
                   data-batch-url="/posts/batch_likers">
                   <div class="likers-placeholder" 
                     data-likers-post-id="171016"
                     data-batch-url="/posts/batch_likers">
                  <div class="post-likers"></div>
                </div>
              </div>
	        </div>
			

    </div>

    <div class="triangle-top-right type-last-post cat-last-post" title="Last post!"></div>
  </section>
</div>
</template></turbo-stream><turbo-stream action="replace" target="load-more-container"><template><div id="load-more-container" class="load-more-container">
    <span class="all-loaded">— All posts loaded —</span>
</div></template></turbo-stream>