Skip to main content

defected

Build PyPI PyPI - Python Version PyPI - Status Downloads Downloads

Defected is a CLI tool designed to analyze Git logs and detect suspicious behaviors, such as frequent timezone changes, to enhance the security and reliability of open-source projects.

Open source projects thrive on collaboration, but their openness comes with risks. Contributors may unknowingly or intentionally exhibit suspicious behaviors, such as:

  • Frequent timezone changes in their commit metadata.
  • Working at unusual hours or during public holidays.
  • Unusual patterns in commit activity.

These anomalies could indicate automation scripts, compromised accounts, or malicious actions.

Defected is a CLI tool designed to help maintainers detect and flag suspicious commit patterns. By analyzing Git logs, Defected provides insights into contributors’ behaviors, helping ensure the security and integrity of your project.

We can think of Defected as an OSINT tool that can used by project maintainers to fight against social engineering.

Visit the official documentation.

Install

$ pip install defected

Usage

$ defected -h

Examples of usage and documentation of available commands are available in the official documentation.

The Problem

Most open source projects rely on volunteers, but not all volunteers are all well intentioned. Strategic, financial, or again geopolical aspect made that some actors seek to profit from open source project to carry out their hidden agenda.

Bad actors have interest in open source to introduce exploits, backdoors, or payloads, or even to scuttle projects.

It expose users of open source projects to threats. Such kind of social engineering can lead users to data leak, invasion of privacy, and lot nightmare scenarios.

As maintainers of these projects we are responsible of the safety of people that who trusted in our work.

Goal

The goal of defected is to highlight potential social engineering threats.

Defected addresses these challenges by:

  • Detecting frequent timezone changes in commit metadata.
  • Highlighting contributors with irregular commit patterns.
  • Flagging potential risks for maintainers to investigate.
  • Providing clear and exportable reports for further analysis.

Features

  1. Easy-to-Use CLI:
    • Installable via PyPI, Defected is simple to run directly from your terminal.
  2. Commit Metadata Analysis:
    • Extracts author, email, date, and timezone data from Git logs.
  3. Timezone Change Detection:
    • Flags contributors exceeding a configurable threshold of timezone changes.
  4. Reveal Deception:
    • Find fraudulous activity and unveil bad intentions (example).
  5. Customizable Options:
    • Adjust thresholds, filter suspicious results.
  6. Exportable Reports:
    • Saves results in CSV format for further analysis.

Contributing

We welcome contributions to Defected!

To contribute:

  1. Fork the repository;
  2. Create a feature branch;
  3. Introduce your changes;
  4. Submit a pull request with a detailed description of your changes.

License

Defected is licensed under the MIT License. See the LICENSE file for details.

Acknowledgments

This project is inspired by the open source community and aims to empower maintainers with tools to ensure project security and integrity.

Release files for defected 0.5.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for defected 0.5.1
File Size Uploaded
defected-0.5.1.tar.gz 34.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for defected 0.5.1
File Interpreter ABI Platform
defected-0.5.1-py3-none-any.whl Python 3 none any Details

Total release size: 59.1 kB

Release files / defected-0.5.1.tar.gz

Download URL defected-0.5.1.tar.gz
Size 34.1 kB
Tags Source
SHA-256 checksum
How to use checksums
66fb8ec9e6cff6cf45becad5bdb1aad4b09460f239bea3a7896108e7d62b1f7c
BLAKE2b-256 checksum
How to use checksums
a13b26ab0cc113a10008bb265ce3b73b48f48937febb0922501c614dd85e3e11
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/5.1.1 CPython/3.12.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Nov 29, 2024.

Transparency log

Release files / defected-0.5.1-py3-none-any.whl

Download URL defected-0.5.1-py3-none-any.whl
Size 24.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
4b8dc8cba05dc529460485e78074ebf52f16f6c5621e394cca85a3ae66fc8ee4
BLAKE2b-256 checksum
How to use checksums
012dcc195013b6b10f8ef7d9fc52834e42ac794436d5891a9e55be06b1eea682
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/5.1.1 CPython/3.12.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Nov 29, 2024.

Transparency log

Release history Release notifications | RSS feed

This release

0.5.1 This release

2 release files

0.5.0

2 release files

0.4.2

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page