tukaani-project
github-explorer
tukaani-project | github-explorer | |
---|---|---|
5 | 13 | |
- | 134 | |
- | 3.0% | |
- | 4.3 | |
- | 5 months ago | |
HTML | ||
- | - |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
tukaani-project
-
Backdoor in upstream xz/liblzma leading to SSH server compromise
Thank you. If you wouldn't have explained the background, I totally would've thought that this is just an innocent typo.
(I still think it's like... 60% a typo? don't know)
Anyhow, other people called the CCing of JiaT75 by Lasse suspicious:
https://news.ycombinator.com/item?id=39867593
https://lore.kernel.org/lkml/20240320183846.19475-2-lasse.co...
Someone pointed out the "mental health issues" and "some other things"
https://news.ycombinator.com/item?id=39868881
https://www.mail-archive.com/[email protected]/msg00567.h...
Lasse is of course a Nordic name, and the whole project has a finnish name and hosting
https://news.ycombinator.com/item?id=39866902
If I wanted to go rogue and insert a backdoor in a project of mine, I'd probably create a new sockpuppet account and hand over management of the project to them. The above is worringly compatible with this hypothesis.
OTOH, JiaT75 did not reuse the existing hosting provider, but rather switched the site to github.io and uploaded there old tarballs:
https://github.com/tukaani-project/tukaani-project.github.io...
If JiaT75 is an old-timer in the project, wouldn't they have kept using the same hosting infra?
There are also some other grim possibilities: someone forced Lasse to hand over the project (violence or blackmailing? as farfetched as that sounds)... or maybe stole Lasse devices (and identity?) and now Lasse is incapacitated?
Or maybe it's just some other fellow scandinavian who pretends to be chinese and got Lasse's trust.
Is the same person sockpuppeting Hans Jansen? It's amusing (but unsurprising) that they are using both german-sounding and chinese-sounding identities.
That said, I don't think it's unreasonable to think that Lasse genuinely trusted JiaT75, genuinely believed that the ifunc stuff was reasonable (it probably isn't: https://news.ycombinator.com/item?id=39869538 ) and handed over the project to them.
And at the end of the day, the only thing linking JiaT75 is a swedish/finnish racist joke which could well be a typo. People already checked the timezone of the commits, but I wonder if anyone has already checked the time-of-day of those commits... does it actually match the working hours that a person genuinely living (and sleeping) in China would follow?
github-explorer
-
Backdoor in upstream xz/liblzma leading to SSH server compromise
clickhouse has pretty good github_events dataset on their playground that folks can use to do some research - some info on the dataset https://ghe.clickhouse.tech/
Example of what user JiaT75 did so far:
https://play.clickhouse.com/play?user=play#U0VMRUNUICogRlJPT...
pull requests mentioning xz, 5.6 without downgrade, cve being mentioned in the last 60 days:
https://play.clickhouse.com/play?user=play#U0VMRUNUIGNyZWF0Z...
- Everything You Always Wanted to Know About GitHub (But Were Afraid to Ask)
-
Stargazers intersections for most popular GitHub projects in Venn diagrams
It shouldn’t be hard to implement: https://ghe.clickhouse.tech/#how-to-download-the-data
- GitHub Profile Achievements
-
Getting 10TB of GitHub Logs and Extracting Details of All Users and Repositories
The article leaves a bitter taste of unnecessary complexity. Data engineering should not be hard.
For example, you can load the GitHub Archive to ClickHouse, and it will be accessible with interactive real-time queries: https://ghe.clickhouse.tech/
See also https://til.simonwillison.net/clickhouse/github-explorer
-
Hundreds of millions of stars turned into a map of GitHub projects
I recommend checking https://ghe.clickhouse.tech/
It explains the full pipeline - how to download, collect, and analyze this sort of data.
- Everything you always wanted to know about GitHub (but were afraid to ask)
-
Cached Chrome Top Million Websites
Yes, it's continuously updated.
The source code is here: https://github.com/ClickHouse/github-explorer
This shell scripts updates it: https://github.com/ClickHouse/github-explorer/blob/main/upda...
What are some alternatives?
systemd - The systemd System and Service Manager
map-of-github - Inspirational Mapping
xz - XZ Utils [GET https://api.github.com/repos/tukaani-project/xz: 403 - Repository access blocked]
crux-top-lists - Downloadable snapshots of the Chrome Top Million Websites pulled from public CrUX data in Google BigQuery.
homebrew-core - 🍻 Default formulae for the missing package manager for macOS (or Linux)
map-of-reddit - Interactive map of reddit
wasmtime - A fast and secure runtime for WebAssembly
github-profile-trophy - 🏆 Add dynamically generated GitHub Stat Trophies on your readme
rust1 - rust1
demo - A new issue is created in this repo every minute
openconnect
Comcast - Simulating shitty network connections so you can build better systems.