Skip to content

Commit d11deaf

Browse files
committed
chore: github issues archive
1 parent 27a4293 commit d11deaf

File tree

5 files changed

+195
-0
lines changed

5 files changed

+195
-0
lines changed

github-open-issues-exported.md

Lines changed: 82 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,87 @@
11
Export of Github issues for [OWASP/www-project-machine-learning-security-top-10](https://github.com/OWASP/www-project-machine-learning-security-top-10).
22

3+
# [\#189 Issue](https://github.com/OWASP/www-project-machine-learning-security-top-10/issues/189) `open`: [FEEDBACK]: Include a page with a brief descriptions of each of the vulnerabilities
4+
**Labels**: `issues/general`, `issues/triage`
5+
6+
7+
#### <img src="https://avatars.githubusercontent.com/u/64902909?u=756899683e78c4e336cc1e8a6b7584bc6b508200&v=4" width="50">[mik0w](https://github.com/mik0w) opened issue at [2023-11-23 12:08](https://github.com/OWASP/www-project-machine-learning-security-top-10/issues/189):
8+
9+
### Type
10+
11+
Suggestions for Improvement
12+
13+
### What would you like to report?
14+
15+
For example in Top10 for LLM there's this page with a summary of each of the vulnerabilities, which I think would be pretty useful to have in Top10 for ML as well.
16+
17+
Sometimes when you e.g. work on some slides for a presentation, you just want to get a short summary of each of the vulnerabilities. In my opinion including such a page in Top10 for ML would be an improvement:
18+
19+
![summary](https://github.com/OWASP/www-project-machine-learning-security-top-10/assets/64902909/0bc2b1c8-43a0-4a5d-b549-71cf83e897c1)
20+
21+
### Code of Conduct
22+
23+
- [X] I agree to follow this project's Code of Conduct
24+
25+
26+
27+
28+
-------------------------------------------------------------------------------
29+
30+
# [\#188 Issue](https://github.com/OWASP/www-project-machine-learning-security-top-10/issues/188) `open`: [FEEDBACK]: Include MLOps vulnerabilties somewhere in the Supply Chain Security category
31+
**Labels**: `issues/general`, `issues/triage`
32+
33+
34+
#### <img src="https://avatars.githubusercontent.com/u/64902909?u=756899683e78c4e336cc1e8a6b7584bc6b508200&v=4" width="50">[mik0w](https://github.com/mik0w) opened issue at [2023-11-17 10:26](https://github.com/OWASP/www-project-machine-learning-security-top-10/issues/188):
35+
36+
### Type
37+
38+
Suggestions for Improvement
39+
40+
### What would you like to report?
41+
42+
**Context**
43+
One of the parts of the supply chain in modern ML systems is MLOps software - like i.e. MLFlow, Prefect etc. Those systems are vulnerable to classic web based attacks and they seem to be "misconfured by default". I've described it here: https://hackstery.com/2023/10/13/no-one-is-prefect-is-your-mlops-infrastructure-leaking-secrets/ or here: https://github.com/logspace-ai/langflow/issues/1145
44+
45+
**Suggestion for improvement**
46+
I'd suggest including MLOps-related vulnerabilities in the ML06 (or maybe in some other categories as well? I am open for suggestions).
47+
48+
### Code of Conduct
49+
50+
- [X] I agree to follow this project's Code of Conduct
51+
52+
53+
54+
55+
-------------------------------------------------------------------------------
56+
57+
# [\#187 Issue](https://github.com/OWASP/www-project-machine-learning-security-top-10/issues/187) `open`: [FEEDBACK]: Sync attack names between LLMT10 and MLT10 where appropriate
58+
**Labels**: `issues/general`, `issues/triage`
59+
60+
61+
#### <img src="https://avatars.githubusercontent.com/u/795878?u=d704fd433504e531d707c517cdb6ff75bdf20372&v=4" width="50">[kapsolas](https://github.com/kapsolas) opened issue at [2023-11-16 22:16](https://github.com/OWASP/www-project-machine-learning-security-top-10/issues/187):
62+
63+
### Type
64+
65+
Suggestions for Improvement
66+
67+
### What would you like to report?
68+
69+
I would like to make the suggestion that we consolidate the terms used in the LLM and ML top 10 documents.
70+
71+
Many of the top 10 items in each are closely related or even the same.
72+
Where possible, the same term should be used (i.e. Model Theft vs Model Stealing, Data Poisoning Attack vs Training data Poisoning).
73+
74+
Thanks!
75+
76+
### Code of Conduct
77+
78+
- [X] I agree to follow this project's Code of Conduct
79+
80+
81+
82+
83+
-------------------------------------------------------------------------------
84+
385
# [\#182 Issue](https://github.com/OWASP/www-project-machine-learning-security-top-10/issues/182) `open`: fix: merge review from @harrietf
486
**Labels**: `issues/triage`, `review needed`
587

issues/2023-11-15.186.pr.merged.md

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
# [\#186 PR](https://github.com/OWASP/www-project-machine-learning-security-top-10/pull/186) `merged`: chore: archive github issues
2+
3+
#### <img src="https://avatars.githubusercontent.com/u/412800?v=4" width="50">[shsingh](https://github.com/shsingh) opened issue at [2023-11-15 03:53](https://github.com/OWASP/www-project-machine-learning-security-top-10/pull/186):
4+
5+
- chore: add mik0w to CODEOWNERS
6+
- fix: test updating ML06 to verify CODEOWNERS working
7+
- docs: add @adityoari as a contributor
8+
- docs: update @aryanxk02 as a contributor
9+
- chore: add adityoari to CONTRIBUTORS
10+
- fix: README formatting
11+
- chore: add yodap-dg to CODEOWNERS
12+
- chore: archive gh issues
13+
14+
15+
16+
17+
18+
-------------------------------------------------------------------------------
19+
20+
21+
22+
[Export of Github issue for [OWASP/www-project-machine-learning-security-top-10](https://github.com/OWASP/www-project-machine-learning-security-top-10).]
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
# [\#187 Issue](https://github.com/OWASP/www-project-machine-learning-security-top-10/issues/187) `open`: [FEEDBACK]: Sync attack names between LLMT10 and MLT10 where appropriate
2+
**Labels**: `issues/general`, `issues/triage`
3+
4+
5+
#### <img src="https://avatars.githubusercontent.com/u/795878?u=d704fd433504e531d707c517cdb6ff75bdf20372&v=4" width="50">[kapsolas](https://github.com/kapsolas) opened issue at [2023-11-16 22:16](https://github.com/OWASP/www-project-machine-learning-security-top-10/issues/187):
6+
7+
### Type
8+
9+
Suggestions for Improvement
10+
11+
### What would you like to report?
12+
13+
I would like to make the suggestion that we consolidate the terms used in the LLM and ML top 10 documents.
14+
15+
Many of the top 10 items in each are closely related or even the same.
16+
Where possible, the same term should be used (i.e. Model Theft vs Model Stealing, Data Poisoning Attack vs Training data Poisoning).
17+
18+
Thanks!
19+
20+
### Code of Conduct
21+
22+
- [X] I agree to follow this project's Code of Conduct
23+
24+
25+
26+
27+
-------------------------------------------------------------------------------
28+
29+
30+
31+
[Export of Github issue for [OWASP/www-project-machine-learning-security-top-10](https://github.com/OWASP/www-project-machine-learning-security-top-10).]
Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,30 @@
1+
# [\#188 Issue](https://github.com/OWASP/www-project-machine-learning-security-top-10/issues/188) `open`: [FEEDBACK]: Include MLOps vulnerabilties somewhere in the Supply Chain Security category
2+
**Labels**: `issues/general`, `issues/triage`
3+
4+
5+
#### <img src="https://avatars.githubusercontent.com/u/64902909?u=756899683e78c4e336cc1e8a6b7584bc6b508200&v=4" width="50">[mik0w](https://github.com/mik0w) opened issue at [2023-11-17 10:26](https://github.com/OWASP/www-project-machine-learning-security-top-10/issues/188):
6+
7+
### Type
8+
9+
Suggestions for Improvement
10+
11+
### What would you like to report?
12+
13+
**Context**
14+
One of the parts of the supply chain in modern ML systems is MLOps software - like i.e. MLFlow, Prefect etc. Those systems are vulnerable to classic web based attacks and they seem to be "misconfured by default". I've described it here: https://hackstery.com/2023/10/13/no-one-is-prefect-is-your-mlops-infrastructure-leaking-secrets/ or here: https://github.com/logspace-ai/langflow/issues/1145
15+
16+
**Suggestion for improvement**
17+
I'd suggest including MLOps-related vulnerabilities in the ML06 (or maybe in some other categories as well? I am open for suggestions).
18+
19+
### Code of Conduct
20+
21+
- [X] I agree to follow this project's Code of Conduct
22+
23+
24+
25+
26+
-------------------------------------------------------------------------------
27+
28+
29+
30+
[Export of Github issue for [OWASP/www-project-machine-learning-security-top-10](https://github.com/OWASP/www-project-machine-learning-security-top-10).]
Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,30 @@
1+
# [\#189 Issue](https://github.com/OWASP/www-project-machine-learning-security-top-10/issues/189) `open`: [FEEDBACK]: Include a page with a brief descriptions of each of the vulnerabilities
2+
**Labels**: `issues/general`, `issues/triage`
3+
4+
5+
#### <img src="https://avatars.githubusercontent.com/u/64902909?u=756899683e78c4e336cc1e8a6b7584bc6b508200&v=4" width="50">[mik0w](https://github.com/mik0w) opened issue at [2023-11-23 12:08](https://github.com/OWASP/www-project-machine-learning-security-top-10/issues/189):
6+
7+
### Type
8+
9+
Suggestions for Improvement
10+
11+
### What would you like to report?
12+
13+
For example in Top10 for LLM there's this page with a summary of each of the vulnerabilities, which I think would be pretty useful to have in Top10 for ML as well.
14+
15+
Sometimes when you e.g. work on some slides for a presentation, you just want to get a short summary of each of the vulnerabilities. In my opinion including such a page in Top10 for ML would be an improvement:
16+
17+
![summary](https://github.com/OWASP/www-project-machine-learning-security-top-10/assets/64902909/0bc2b1c8-43a0-4a5d-b549-71cf83e897c1)
18+
19+
### Code of Conduct
20+
21+
- [X] I agree to follow this project's Code of Conduct
22+
23+
24+
25+
26+
-------------------------------------------------------------------------------
27+
28+
29+
30+
[Export of Github issue for [OWASP/www-project-machine-learning-security-top-10](https://github.com/OWASP/www-project-machine-learning-security-top-10).]

0 commit comments

Comments
 (0)