The popular open source project, "ip" has recently archived its GitHub repository, meaning developer has made it "read-only."
See also: JetBrains IntelliJ IDE bug exposes GitHub access tokens

Fedor Indutny, started being harassed by people online, due to a CVE report filed against his project.
Unfortunately, Indutny's case is not an isolated one. Recently, open source developers have faced a surge in receiving questionable or, in some cases, outright false CVE reports filed for their projects without confirmation.
This can lead to unwarranted panic among users of these projects and alerts generated by security scanners, which turn into a source of headache for developers.
Earlier this month, Fedor Indutny, who is the author of the 'node-ip' project, archived the project's GitHub repository, effectively making it read-only and limiting the ability of people to open new topics (discussions), make requests , or submit comments to the project.
See also: New York Times source code stolen from GitHub repository
The “node-ip” project exists in the npmjs.com as the “ip” package, which sees 17 million downloads per week, making it one of the most popular IP address analysis utilities used by JavaScript.

On Tuesday, June 25, Indutny took to social media to express his reasoning behind making 'node-ip' read-only on GitHub.
Node.js developers who use other open source projects, such as npm packages and dependencies in application , can run the “npm audit” command to check if any of the projects used by their application have reported vulnerabilities .
The CVE is related to the utility not properly recognizing private IP addresses provided to it in a non-standard format, such as hexadecimal. This would result in the “node-ip” utility treating a private IP address (in hexadecimal format) such as “0x7F.1…” (representing 127.1…) as public.
If an application relies solely on node-ip to check whether a provided IP address is public, non-standard inputs may cause affected versions of the utility to return inconsistent results.
See also: New Gitloker attacks delete GitHub repos
GitHub is a web-based platform primarily used for version control and collaborative software development. Built on Git, a distributed version control system, it allows multiple developers to work on multiple projects simultaneously. GitHub provides tools for managing repositories, tracking issues and bugs, and integrating continuous development services. By enabling teams to share code, track changes, and manage their projects more efficiently, GitHub has become an indispensable tool for developers and organizations worldwide, driving innovation and improved workflows.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: bleepingcomputer
