Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Malicious packages not being reported in Copilot Chat #602

Open
danbarr opened this issue Jan 15, 2025 · 3 comments
Open

Malicious packages not being reported in Copilot Chat #602

danbarr opened this issue Jan 15, 2025 · 3 comments

Comments

@danbarr
Copy link
Collaborator

danbarr commented Jan 15, 2025

Describe the issue

Starting with v0.1.6, malicious/deprecated packages are not being reported by CodeGate via Copilot Chat. Copilot Explain is reporting them as expected, and Continue chat is also fine.

With v0.1.5:

Image

Starting in v0.1.6:

Image

Steps to Reproduce

Ask Copilot Chat to explain or review a file with a malicious package reference, for example https://github.com/stacklok/codegate-demonstration/blob/main/python/fabric.py

Operating System

MacOS (Arm)

IDE and Version

VS Code 1.96.3

Extension and Version

Copilot 1.257.0

Provider

GitHub Copilot

Model

GPT-4

Logs

No response

Additional Context

No response

@lukehinds
Copy link
Contributor

Do you know if this is still on 0.1.7 @danbarr ?

@danbarr
Copy link
Collaborator Author

danbarr commented Jan 16, 2025

@lukehinds Yes I am still able to reproduce on 1.0.7 when starting from a fresh chat session.

@jhrozek
Copy link
Contributor

jhrozek commented Jan 16, 2025

@danbarr I think this got fixed today by one of @yrobla 's patches. We should get a release out

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants