Ultralytics ã»ãã¥ãªãã£ã»ããªã·ãŒ
ã«ãã㊠Ultralyticsã§ã¯ããŠãŒã¶ãŒã®ããŒã¿ãšã·ã¹ãã ã®ã»ãã¥ãªãã£ãæãéèŠèŠããŠããŸããç§ãã¡ã®ãªãŒãã³ãœãŒã¹ãããžã§ã¯ãã®å®å šæ§ãšã»ãã¥ãªãã£ã確ä¿ããããã«ãç§ãã¡ã¯ã»ãã¥ãªãã£ã®è匱æ§ãæ€åºããé²æ¢ããããã®ããã€ãã®å¯Ÿçãå®æœããŠããŸãã
ã¹ããŒã¯ã»ã¹ãã£ãã³ã°
ç§ãã¡ã¯Snyk ãå©çšããŠãUltralytics ãªããžããªã®å æ¬çãªã»ãã¥ãªã㣠ã¹ãã£ã³ãè¡ã£ãŠããŸããSnykã®å ç¢ãªã¹ãã£ã³æ©èœã¯ãäŸåé¢ä¿ã®ãã§ãã¯ã«ãšã©ãŸãããåœç€Ÿã®ã³ãŒããšDockerfileã«ããŸããŸãªè匱æ§ããªããã©ããã調ã¹ãŸãããã®ãããªåé¡ãæªç¶ã«ç¹å®ã察åŠããããšã§ããŠãŒã¶ã«å¯ŸããŠããé«ãã¬ãã«ã®ã»ãã¥ãªãã£ãšä¿¡é Œæ§ãä¿èšŒããŠããŸãã
GitHub CodeQLã¹ãã£ã³
ç§ãã¡ã®ã»ãã¥ãªãã£æŠç¥ã«ã¯ãGitHubã®CodeQLã¹ãã£ã³ãå«ãŸããŠããŸããCodeQLã¯ç§ãã¡ã®ã³ãŒãããŒã¹ãæ·±ãæãäžããã³ãŒãã®æå³æ§é ãåæããããšã§SQLã€ã³ãžã§ã¯ã·ã§ã³ãXSSã®ãããªè€éãªè匱æ§ãç¹å®ããŸãããã®é«åºŠãªåæã«ãããæœåšçãªã»ãã¥ãªãã£ãªã¹ã¯ãæ©æã«çºèŠãã解決ããããšãã§ããŸãã
GitHub Dependabotã¢ã©ãŒã
Dependabotã¯ç§ãã¡ã®ã¯ãŒã¯ãããŒã«çµ±åãããŠãããæ¢ç¥ã®è匱æ§ã«ã€ããŠäŸåé¢ä¿ãç£èŠããŠããŸããç§ãã¡ã®äŸåé¢ä¿ã®1ã€ã«è匱æ§ãç¹å®ããããšãDependabotã¯ç§ãã¡ã«èŠåãçºããè¿ éãã€æ å ±ã«åºã¥ããä¿®æ£ã¢ã¯ã·ã§ã³ãå¯èœã«ããŸãã
GitHub ã·ãŒã¯ã¬ããã¹ãã£ã³èŠå
ç§ãã¡ã¯GitHubã®ã·ãŒã¯ã¬ããã¹ãã£ã³ã¢ã©ãŒããæ¡çšãã誀ã£ãŠãªããžããªã«ããã·ã¥ãããèªèšŒæ å ±ãç§å¯éµãªã©ã®æ©å¯ããŒã¿ãæ€ç¥ããŠããŸãããã®æ©æçºèŠã¡ã«ããºã ã«ãããæœåšçãªã»ãã¥ãªãã£äŸµå®³ãããŒã¿æµåºãé²ãããšãã§ããŸãã
ãã©ã€ããŒãè匱æ§å ±å
ç§ãã¡ã¯ãã©ã€ããŒããªè匱æ§å ±åãå¯èœã«ãããŠãŒã¶ãŒãæœåšçãªã»ãã¥ãªãã£åé¡ãç®ç«ããªãããã«å ±åã§ããããã«ããŠããŸãããã®ã¢ãããŒãã¯ã責任ããæ å ±å ¬éãä¿é²ããè匱æ§ãå®å šãã€å¹ççã«åŠçãããããšãä¿èšŒããŸãã
ç§ãã¡ã®ãªããžããªã«ã»ãã¥ãªãã£ã®è匱æ§ãçãããå ŽåããŸãã¯çºèŠãããå Žåã¯ãçŽã¡ã«ãç¥ãããã ããããåãåãããã©ãŒã ãŸãã¯security@ultralytics.comããçŽæ¥ãé£çµ¡ãã ãããåœç€Ÿã®ã»ãã¥ãªãã£ããŒã ã調æ»ããã§ããã ãæ©ã察å¿ããããŸãã
å šãŠã®Ultralytics ãªãŒãã³ãœãŒã¹ãããžã§ã¯ããå®å šãã€å®å šã«ä¿ã€ãããçæ§ã®ãååããé¡ãããããŸãðã
ããããã質å
Ultralytics ããŠãŒã¶ãŒããŒã¿ãä¿è·ããããã«ã©ã®ãããªã»ãã¥ãªãã£å¯ŸçããšãããŠããŸããïŒ
Ultralytics ã¯ããŠãŒã¶ãŒã®ããŒã¿ãšã·ã¹ãã ãä¿è·ããããã®å æ¬çãªã»ãã¥ãªãã£æŠç¥ãæ¡çšããŠããŸããäž»ãªå¯Ÿçã¯ä»¥äžã®éãïŒ
- Snykã¹ãã£ã³ïŒã³ãŒããšDockerfileã®è匱æ§ãæ€åºããããã«ã»ãã¥ãªãã£ã¹ãã£ã³ãå®æœããŸãã
- GitHub CodeQLïŒã³ãŒãã®ã»ãã³ãã£ã¯ã¹ã解æããSQLã€ã³ãžã§ã¯ã·ã§ã³ãªã©ã®è€éãªè匱æ§ãæ€åºããŸãã
- Dependabot ã¢ã©ãŒãïŒæ¢ç¥ã®è匱æ§ã®ããã«äŸåé¢ä¿ãç£èŠããè¿ éãªä¿®åŸ©ã®ããã«ã¢ã©ãŒããéä¿¡ããŸãã
- ã·ãŒã¯ã¬ããã¹ãã£ã³ïŒã³ãŒããªããžããªå ã®èªèšŒæ å ±ãç§å¯éµã®ãããªæ©å¯ããŒã¿ãæ€åºããããŒã¿æŒæŽ©ãé²ããŸãã
- ãã©ã€ããŒãè匱æ§å ±åïŒãŠãŒã¶ãŒãæœåšçãªã»ãã¥ãªãã£åé¡ãç®ç«ããªãããã«å ±åããããã®å®å šãªãã£ãã«ãæäŸããŸãã
ãããã®ããŒã«ã¯ãã»ãã¥ãªãã£åé¡ã®ããã¢ã¯ãã£ããªç¹å®ãšè§£æ±ºã確å®ã«ããã·ã¹ãã å šäœã®ã»ãã¥ãªãã£ã匷åããŸãã詳现ã«ã€ããŠã¯ã茞åºé¢é£ææžãã芧ãã ããã
Ultralytics ãã»ãã¥ãªãã£ã»ã¹ãã£ã³ã«Snykãã©ã®ããã«äœ¿çšããŠããŸããïŒ
Ultralytics ã¯Snyk ãå©çšããŠããªããžããªã®åŸ¹åºçãªã»ãã¥ãªãã£ã¹ãã£ã³ãå®æœããŠããŸããSnykã¯åºæ¬çãªäŸåé¢ä¿ã®ãã§ãã¯ã«ãšã©ãŸãããã³ãŒããDockerfileã«ããŸããŸãªè匱æ§ããªããã©ããã調ã¹ãŸããæœåšçãªã»ãã¥ãªãã£åé¡ãç©æ¥µçã«ç¹å®ã解決ããããšã§ãSnykã¯Ultralytics' ãªãŒãã³ãœãŒã¹ãããžã§ã¯ããå®å šã§ä¿¡é Œæ§ã®é«ãç¶æ ãç¶æã§ããããæ¯æŽããŸãã
Snyk ãããžã確èªãããã®å±éã«ã€ããŠè©³ããç¥ãã«ã¯ãSnyk Scanning ã»ã¯ã·ã§ã³ãã芧ãã ããã
CodeQLãšã¯äœãããããŠUltralytics ãã©ã®ããã«ã»ãã¥ãªãã£ã匷åããã®ãïŒ
CodeQLã¯ãGitHub ãä»ããŠUltralytics' ã¯ãŒã¯ãããŒã«çµ±åãããã»ãã¥ãªãã£åæããŒã«ã§ããã³ãŒãããŒã¹ãæ·±ãæãäžããSQLã€ã³ãžã§ã¯ã·ã§ã³ãã¯ãã¹ãµã€ãã¹ã¯ãªããã£ã³ã°ïŒXSSïŒãªã©ã®è€éãªè匱æ§ãç¹å®ããŸããCodeQL ã¯ã³ãŒãã®ã»ãã³ãã£ãã¯æ§é ãåæããŠé«åºŠãªã»ãã¥ãªãã£ã¬ãã«ãæäŸããæœåšçãªãªã¹ã¯ã®æ©æçºèŠãšè»œæžã確å®ã«ããŸãã
CodeQLã®äœ¿çšæ¹æ³ã®è©³çŽ°ã«ã€ããŠã¯ãGitHub CodeQL Scanningã»ã¯ã·ã§ã³ãã芧ãã ããã
Dependabotã¯ãUltralytics' ã³ãŒãã®ã»ãã¥ãªãã£ãç¶æããããã«ã©ã®ããã«åœ¹ç«ã¡ãŸããïŒ
Dependabotã¯ãæ¢ç¥ã®è匱æ§ã«ã€ããŠäŸåé¢ä¿ãç£èŠã»ç®¡çããèªååããŒã«ã§ããDependabot ãUltralytics ãããžã§ã¯ãã®äŸåé¢ä¿ã«è匱æ§ãæ€åºãããšãã¢ã©ãŒããéä¿¡ãããããŒã ã¯è¿ éã«åé¡ã«å¯ŸåŠããŠç·©åããããšãã§ããŸããããã«ãããäŸåé¢ä¿ãå®å šãã€ææ°ã®ç¶æ ã«ä¿ãããæœåšçãªã»ãã¥ãªãã£ãªã¹ã¯ãæå°éã«æããããšãã§ããŸãã
詳现ã«ã€ããŠã¯ãGitHub Dependabot Alertsã»ã¯ã·ã§ã³ãåç §ããŠãã ããã
Ultralytics ãéå ¬éã®è匱æ§å ±åã¯ã©ã®ããã«æ±ãããã®ãïŒ
Ultralytics ã¯ãæœåšçãªã»ãã¥ãªãã£åé¡ããã©ã€ããŒãã»ãã£ãã«ãéããŠå ±åããããšããŠãŒã¶ãŒã«æšå¥šããŠããŸãããŠãŒã¶ãŒã¯ãã³ã³ã¿ã¯ããã©ãŒã ãŸãã¯security@ultralytics.comã«é»åã¡ãŒã«ãéãããšã§ãç®ç«ããªãããã«è匱æ§ãå ±åããããšãã§ããŸããããã«ããã責任ããæ å ±é瀺ãä¿èšŒãããã»ãã¥ãªãã£ããŒã ãå®å šãã€å¹ççã«è匱æ§ã調æ»ãã察åŠããããšãã§ããŸãã
ãã©ã€ããŒãè匱æ§å ±åã®è©³çŽ°ã«ã€ããŠã¯ããã©ã€ããŒãè匱æ§å ±åã®ã»ã¯ã·ã§ã³ãåç §ããŠãã ããã