Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

False positive? #35

Open
mridoni opened this issue Jul 17, 2023 · 3 comments
Open

False positive? #35

mridoni opened this issue Jul 17, 2023 · 3 comments

Comments

@mridoni
Copy link

mridoni commented Jul 17, 2023

The antivirus in Windows Server 2019 flags a Trojan in the Windows binary for v0.9, probably a false positive:

image

@GitMensch
Copy link
Contributor

@lefessan Maybe it is time for a new release and maybe you have some code-signing certificate at OCamlPro that can be used?

@lefessan
Copy link
Member

It's weird, the executables are generated by cross-compiling on Linux to lower such risks.

We currently have no code-signing certificates, but I should probably investigate how to get one...

@GitMensch
Copy link
Contributor

GitMensch commented Sep 20, 2023

Note: cross-checking with VirusTotal shows that currently only one vendor flags this file https://www.virustotal.com/gui/file/2ef22dd5544bca090e07472eb9231b6e42996a8d13dac9a360af71b863da1788, according to that Microsoft doesn't do this any more.

You therefore possibly want to close this issue as "not reproducible" and can keep the code-signing separate (note: I'm not aware of any "gratis" code-signing option, other than https://about.signpath.io/product/open-source [signing directly in CI/CD]).

https://shop.certum.eu/open-source-code-signing-code.html is currently at 25 EUR/year

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants