Packj(发音为 package)是一款帮助缓解软件供应链攻击的工具。它可以检测来自流行开源包注册中心(如 NPM、RubyGems 和 PyPI)的恶意、存在漏洞、已废弃、拼写错误以及其他“高风险”包。该工具易于定制以降低噪音。Packj 始于一个博士研究项目,目前正在多个政府资助下进行开发。
注意 本月晚些时候将推出自托管 Packj Web 服务器和多项集成 👊 关注此仓库以获取最新信息。

我们支持多种部署模型:
使用 Packj 审计拉取请求中的依赖项。```yaml
在 GitHub [marketplace](https://github.com/marketplace/actions/packj-security-audit) 上查看。示例 [PR 运行](https://github.com/ossillate-inc/packj-github-action-demo/pull/3#issuecomment-1274797138)。
### 2. Docker 镜像(推荐)
尝试/测试 Packj 的最快方式是使用 Docker。此外还支持 Podman 进行容器化(隔离)运行。```
docker run -v /tmp:/tmp/packj -it ossillate/packj:latest --help
克隆此仓库,``` git clone https://github.com/ossillate-inc/packj.git && cd packj
安装依赖```
bundle install && pip3 install -r requirements.txt
从帮助开始:``` python3 main.py --help
# 支持的生态系统 #
Packj 可以对来自 NPM、PyPI、Rust、PHP 和 Rubygems 包注册表的已发布包进行审查。Rust 和 PHP 支持正在开发中。我们正在积极增加对注册表的支持。
它还支持审查本地(未发布)的 NPM 和 PyPI 包。
| Registry | Ecosystem | Supported |
| --------- | ---------- | ------------------ |
| NPM | JavaScript | :white_check_mark: |
| PyPI | Python | :white_check_mark: |
| Cargo | Rust | :white_check_mark: |
| Rubygems | Ruby | :white_check_mark: |
| Packagist | PHP | :white_check_mark: |
| Docker | Docker | :x: |
| Nuget | .NET | :white_check_mark: |
| Maven | Java | :white_check_mark: |
| Cocoapods | Swift | :x: |
# 功能 #
Packj 提供以下工具:
* [审计](#auditing-a-package) - 审查包的“风险”属性。
* [沙箱](#sandboxed-package-installation) - 用于安全安装包。
## 审查包 ##
Packj 审查开源软件包的“风险”属性,这些属性使其容易受到供应链攻击。例如,具有过期邮件域名(缺乏2FA)、发布间隔时间长、敏感API或访问权限等的包会被标记为风险。
支持审查以下内容:
- 多个包:`python3 main.py audit -p pypi:requests rubygems:overcommit`
- 依赖文件:`python3 main.py audit -f npm:package.json pypi:requirements.txt`
默认情况下,`audit` 只执行静态代码分析来检测风险代码。你可以传递 `-t` 或 `--trace` 标志来同时执行动态代码分析,这将在 strace 下安装所有请求的包并监控包的安装时行为。请参见下面的示例输出。
<details>
<summary><h4>显示示例运行/输出</h4></summary>
$ docker run -v /tmp:/tmp/packj -it ossillate/packj:latest audit --trace -p npm:browserify
[+] Fetching 'browserify' from npm..........PASS [ver 17.0.0]
[+] Checking package description.........PASS [browser-side require() the node way]
[+] Checking release history.............PASS [484 version(s)]
[+] Checking version........................RISK [702 days old]
[+] Checking release time gap............PASS [68 days since last release]
[+] Checking author.........................PASS [[email protected]]
[+] Checking email/domain validity.......RISK [expired author email domain]
[+] Checking readme.........................PASS [26838 bytes]
[+] Checking homepage.......................PASS [https://github.com/browserify/browserify#readme]
[+] Checking downloads......................PASS [2M weekly]
[+] Checking repo URL.......................PASS [https://github.com/browserify/browserify]
[+] Checking repo data...................PASS [stars: 14189, forks: 1244]
[+] Checking if repo is a forked copy....PASS [original, not forked]
[+] Checking repo description............PASS [browser-side require() the node.js way]
[+] Checking repo activity...............PASS [commits: 2290, contributors: 207, tags: 413]
[+] Checking for CVEs.......................PASS [none found]
[+] Checking dependencies...................RISK [48 found]
[+] Downloading package from npm............PASS [163.83 KB]
[+] Analyzing code..........................RISK [needs 3 perm(s): decode,codegen,file]
[+] Checking files/funcs....................PASS [429 files (383 .js), 744 funcs, LoC: 9.7K]
[+] Installing package and tracing code.....PASS [found 5 process,1130 files,22 network syscalls]
=============================================
[+] 5 risk(s) found, package is undesirable!
=> Complete report: /tmp/packj_54rbjhgm/report_npm-browserify-17.0.0_hlr1rhcz.json
{
"undesirable": [
"old package: 702 days old",
"invalid or no author email: expired author email domain",
"generates new code at runtime",
"reads files and dirs",
"forks or exits OS processes",
]
}
</details>
> 警告:由于包在安装过程中可能执行恶意代码,建议仅在 Docker 容器或虚拟机内使用 `-t` 或 `--trace`。
审计也可以在 Docker/Podman 容器中执行。有关风险属性的详细信息及使用方法,请参见 [审计 README](https://github.com/ossillate-inc/packj/blob/main/packj/audit/README.md)。
## 沙箱化包安装 ##
Packj 为包的“安全安装”提供轻量级沙箱。具体来说,它防止恶意包窃取敏感数据、访问敏感文件(如 SSH 密钥)和持久化恶意软件。
它对安装时脚本(包括任何原生编译)进行沙箱化。它使用 **strace**(即**不需要** VM/容器)。
有关沙箱机制及使用方法的详细信息,请参见 [沙箱 README](https://github.com/ossillate-inc/packj/blob/main/packj/sandbox/README.md)。
<details>
<summary><h4>显示示例运行/输出</h4></summary>