Should add a custom actions for updating and scanning the dependency #13567

Closed
opened 2025-11-02 10:46:17 -06:00 by GiteaMirror · 5 comments
Owner

Originally created by @sundaram2021 on GitHub (Oct 5, 2024).

Description

i am setting up the gitea repo locally on my windows os and ran the cmd "make backend"
pkg started installing and along the way it also installed some virus(trojan) with the dependency
and i have to remove that virus and stop the installation

Gitea Version

latest

Can you reproduce the bug on the Gitea demo site?

No

Log Gist

No response

Screenshots

No response

Git Version

No response

Operating System

No response

How are you running Gitea?

no

Database

None

Originally created by @sundaram2021 on GitHub (Oct 5, 2024). ### Description i am setting up the gitea repo locally on my windows os and ran the cmd "make backend" pkg started installing and along the way it also installed some virus(trojan) with the dependency and i have to remove that virus and stop the installation ### Gitea Version latest ### Can you reproduce the bug on the Gitea demo site? No ### Log Gist _No response_ ### Screenshots _No response_ ### Git Version _No response_ ### Operating System _No response_ ### How are you running Gitea? no ### Database None
GiteaMirror added the issue/needs-feedback label 2025-11-02 10:46:17 -06:00
Author
Owner

@lunny commented on GitHub (Oct 5, 2024):

I think those are false alerts. We have dependencies scanning enabled in this repository. Can you post which packages are considered virus?

@lunny commented on GitHub (Oct 5, 2024): I think those are false alerts. We have dependencies scanning enabled in this repository. Can you post which packages are considered virus?
Author
Owner

@wxiaoguang commented on GitHub (Oct 6, 2024):

Official document: Why does my virus-scanning software think my Go distribution or compiled binary is infected? https://go.dev/doc/faq#virus

@wxiaoguang commented on GitHub (Oct 6, 2024): Official document: Why does my virus-scanning software think my Go distribution or compiled binary is infected? https://go.dev/doc/faq#virus
Author
Owner

@sundaram2021 commented on GitHub (Oct 6, 2024):

image

see this is the problem ..
and windows security does not allow to proceed with the installation
and it considered as server threat by it

@sundaram2021 commented on GitHub (Oct 6, 2024): ![image](https://github.com/user-attachments/assets/dc021a33-dbfe-49e0-83f6-7834b0c96ea2) see this is the problem .. and windows security does not allow to proceed with the installation and it considered as server threat by it
Author
Owner
@wxiaoguang commented on GitHub (Oct 6, 2024): It is a false report https://go.dev/doc/faq#virus And google more: https://www.reddit.com/r/golang/comments/1729tuc/my_programs_keep_getting_flagged_as_viruses/ https://github.com/golang/go/issues/55042 https://forum.golangbridge.org/t/my-compiled-exe-file-is-declared-as-a-virus/34038/2
Author
Owner

@sundaram2021 commented on GitHub (Oct 6, 2024):

okay cool.
I will try once more and inform

thanks :)

@sundaram2021 commented on GitHub (Oct 6, 2024): okay cool. I will try once more and inform thanks :)
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/gitea#13567