Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Daily VirusTotal scan #109

Open
co-stig opened this issue Jan 25, 2025 · 1 comment
Open

Daily VirusTotal scan #109

co-stig opened this issue Jan 25, 2025 · 1 comment
Labels
enhancement New feature or request installer
Milestone

Comments

@co-stig
Copy link
Contributor

co-stig commented Jan 25, 2025

We've already received a few reports that Windows Defender detects flowkeeper.exe as malware, e.g. #107. Those are not caught by the Defender scans that the pipeline runs as part of the release. Indeed, Defender might update its detection database after the release.

We need to implement a scheduled pipeline (ideally public, in GitHub), which runs every day and submits / rescans the latest binaries using VirusTotal APIs. Once it detects a false positive -- it should send me an email.

The results can be published as a badge on the GitHub page, and added to Downloads section on flowkeeper.org, so that the users feel safe when they install it.

This can be done together with #103.

Reporting false positives: https://docs.virustotal.com/docs/false-positive-contacts

Potential alternatives to VirusTotal:

@co-stig co-stig added enhancement New feature or request installer labels Jan 25, 2025
@co-stig
Copy link
Contributor Author

co-stig commented Jan 31, 2025

Reminder -- need to scan the "installed" Flowkeeper.exe, too -- apparently that's the one which gets flagged most:

Image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request installer
Projects
None yet
Development

No branches or pull requests

1 participant