Skip to content

Commit d1fdcf3

Browse files
authored
Merge pull request #194 from OWASP/develop
chore: github issues archive
2 parents bfebed1 + 2b1f996 commit d1fdcf3

8 files changed

+110
-85
lines changed

github-open-issues-exported.md

Lines changed: 31 additions & 84 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,18 @@
11
Export of Github issues for [OWASP/www-project-machine-learning-security-top-10](https://github.com/OWASP/www-project-machine-learning-security-top-10).
22

3+
# [\#194 PR](https://github.com/OWASP/www-project-machine-learning-security-top-10/pull/194) `open`: chore: github issues archive
4+
5+
#### <img src="https://avatars.githubusercontent.com/u/412800?v=4" width="50">[shsingh](https://github.com/shsingh) opened issue at [2023-12-18 04:11](https://github.com/OWASP/www-project-machine-learning-security-top-10/pull/194):
6+
7+
- chore: github issues archive
8+
- chore: github issues archive
9+
10+
11+
12+
13+
14+
-------------------------------------------------------------------------------
15+
316
# [\#189 Issue](https://github.com/OWASP/www-project-machine-learning-security-top-10/issues/189) `open`: [FEEDBACK]: Include a page with a brief descriptions of each of the vulnerabilities
417
**Labels**: `issues/general`, `issues/triage`
518

@@ -22,7 +35,11 @@ Sometimes when you e.g. work on some slides for a presentation, you just want t
2235

2336
- [X] I agree to follow this project's Code of Conduct
2437

38+
#### <img src="https://avatars.githubusercontent.com/u/412800?v=4" width="50">[shsingh](https://github.com/shsingh) commented at [2023-12-18 04:07](https://github.com/OWASP/www-project-machine-learning-security-top-10/issues/189#issuecomment-1859518422):
2539

40+
Hi @mik0w is the suggestion to create a summary page? Or to look at enhacing the introductory sections within each of the ML risks so that they can be used as a summary? Or both?
41+
42+
In either case I think this is a good idea, let me get started on it.
2643

2744

2845
-------------------------------------------------------------------------------
@@ -53,6 +70,10 @@ I'd suggest including MLOps-related vulnerabilities in the ML06 (or maybe in som
5370

5471
In my view it should be in ML06, However is should be better renamed with ML from AI supply chain i believe to keep ourself distinct, How would you recommend adding these in the existing ML06, keeping the attacks generic to other packages
5572

73+
#### <img src="https://avatars.githubusercontent.com/u/412800?v=4" width="50">[shsingh](https://github.com/shsingh) commented at [2023-12-18 04:06](https://github.com/OWASP/www-project-machine-learning-security-top-10/issues/188#issuecomment-1859517344):
74+
75+
Hi @mik0w I definitely think we should look at including the ecosystem of MLOps software. I am not sure that it all falls within supply chain though. Keen to hear your thoughts on this.
76+
5677

5778
-------------------------------------------------------------------------------
5879

@@ -79,7 +100,17 @@ Thanks!
79100

80101
- [X] I agree to follow this project's Code of Conduct
81102

103+
#### <img src="https://avatars.githubusercontent.com/u/412800?v=4" width="50">[shsingh](https://github.com/shsingh) commented at [2023-12-18 04:03](https://github.com/OWASP/www-project-machine-learning-security-top-10/issues/187#issuecomment-1859515638):
104+
105+
Hi @kapsolas apologies for the delay in responsing.
106+
107+
Will definitely look to changing "Model Stealing" to "Model Theft".
82108

109+
In terms of "Data Poisoning v Training data poisoning" I would like to defer to @yodap-dg
110+
111+
Typically in research papers it is referred to as "Data Poisoning" and I agree that the use case is largely around the training data itself.
112+
113+
What are your thoughts @yodap-dg?
83114

84115

85116
-------------------------------------------------------------------------------
@@ -852,90 +883,6 @@ Reference https://github.com/OWASP/www-project-machine-learning-security-top-10/
852883
initial issue mentioned #43
853884

854885

855-
-------------------------------------------------------------------------------
856-
857-
# [\#129 PR](https://github.com/OWASP/www-project-machine-learning-security-top-10/pull/129) `open`: fix ePUB Renders.
858-
859-
#### <img src="https://avatars.githubusercontent.com/u/49409979?u=069bd6928cc6b4b478a304e0eb660ad4cb9cb505&v=4" width="50">[msnishanth9001](https://github.com/msnishanth9001) opened issue at [2023-10-20 06:50](https://github.com/OWASP/www-project-machine-learning-security-top-10/pull/129):
860-
861-
this PR contains fix to #99 and #128
862-
863-
1. Workflow to automate mirror to the https://mltop10.info/ host GitHub repo.
864-
2. Fixes MD files, so the ePUB renders without errors.
865-
3. Fixes alignment of tables.
866-
867-
note, the data in table arrangement is not good so the ePUB variant has jumbled data. This can be revisited once the tabular data is fixed.
868-
869-
#### <img src="https://avatars.githubusercontent.com/u/49409979?u=069bd6928cc6b4b478a304e0eb660ad4cb9cb505&v=4" width="50">[msnishanth9001](https://github.com/msnishanth9001) commented at [2023-10-20 06:54](https://github.com/OWASP/www-project-machine-learning-security-top-10/pull/129#issuecomment-1772185642):
870-
871-
Note, this requires a GitHub token of the MLTOP10 Repo, saved with name COPY_TOKEN to do the WF push.
872-
873-
#### <img src="https://avatars.githubusercontent.com/u/412800?v=4" width="50">[shsingh](https://github.com/shsingh) commented at [2023-10-30 00:36](https://github.com/OWASP/www-project-machine-learning-security-top-10/pull/129#issuecomment-1784304978):
874-
875-
> this PR contains fix to #99 and #128
876-
>
877-
> 1. Workflow to automate mirror to the https://mltop10.info/ host GitHub repo.
878-
> 2. Fixes MD files, so the ePUB renders without errors.
879-
> 3. Fixes alignment of tables.
880-
>
881-
> note, the data in table arrangement is not good so the ePUB variant has jumbled data. This can be revisited once the tabular data is fixed.
882-
883-
Hi @msnishanth9001 thanks for the PR.
884-
885-
Is the intent of this PR to mirror or to fix formatting issues? Or both?
886-
887-
At this stage the repo for https://mltop10.info is done manually because it needs a manual run of 'quarto' to generate the files.
888-
889-
The rendering of EPUB and PDF at this stage is more critical then worrying about the mirroring portion IMHO.
890-
891-
#### <img src="https://avatars.githubusercontent.com/u/49409979?u=069bd6928cc6b4b478a304e0eb660ad4cb9cb505&v=4" width="50">[msnishanth9001](https://github.com/msnishanth9001) commented at [2023-10-30 06:46](https://github.com/OWASP/www-project-machine-learning-security-top-10/pull/129#issuecomment-1784575634):
892-
893-
Hi @shsingh can you please assign me this issue.
894-
895-
The intent is to do both fix mirror and formatting issues. Once the formatting issue is fixed the ePUB generation will be fixed.
896-
897-
the following WF PR will publish ePUB and PDF.
898-
- https://github.com/mltop10-info/mltop10.info/pull/4
899-
900-
#### <img src="https://avatars.githubusercontent.com/u/49409979?u=069bd6928cc6b4b478a304e0eb660ad4cb9cb505&v=4" width="50">[msnishanth9001](https://github.com/msnishanth9001) commented at [2023-10-30 07:30](https://github.com/OWASP/www-project-machine-learning-security-top-10/pull/129#issuecomment-1784623302):
901-
902-
updated PR to remove WF for mirror.
903-
904-
This fixes ePUB and PDF render only.
905-
906-
#### <img src="https://avatars.githubusercontent.com/u/412800?v=4" width="50">[shsingh](https://github.com/shsingh) commented at [2023-10-31 17:11](https://github.com/OWASP/www-project-machine-learning-security-top-10/pull/129#issuecomment-1787638590):
907-
908-
Hi @msnishanth9001 as your change is only for the _quarto.yml file did you want to add that as a PR to the mltop10-info repo instead?
909-
910-
The _quarto.yml file is not contained under docs/ in this project repository
911-
912-
#### <img src="https://avatars.githubusercontent.com/u/49409979?u=069bd6928cc6b4b478a304e0eb660ad4cb9cb505&v=4" width="50">[msnishanth9001](https://github.com/msnishanth9001) commented at [2023-10-31 17:19](https://github.com/OWASP/www-project-machine-learning-security-top-10/pull/129#issuecomment-1787651198):
913-
914-
was using it to test the renders, forgot to remove. Done now.
915-
916-
#### <img src="https://avatars.githubusercontent.com/u/412800?v=4" width="50">[shsingh](https://github.com/shsingh) commented at [2023-11-05 21:04](https://github.com/OWASP/www-project-machine-learning-security-top-10/pull/129#issuecomment-1793845257):
917-
918-
Hi @msnishanth9001,
919-
920-
The files look like they have gone back to cfc455f7b7cb8cdac19e46d2321090e9085f619c
921-
922-
Will they work properly on both the OWASP site as well as render PDF on https://mltop10.info site?
923-
924-
#### <img src="https://avatars.githubusercontent.com/u/49409979?u=069bd6928cc6b4b478a304e0eb660ad4cb9cb505&v=4" width="50">[msnishanth9001](https://github.com/msnishanth9001) commented at [2023-11-06 14:54](https://github.com/OWASP/www-project-machine-learning-security-top-10/pull/129#issuecomment-1795014821):
925-
926-
> The files look like they have gone back to https://github.com/OWASP/www-project-machine-learning-security-top-10/commit/cfc455f7b7cb8cdac19e46d2321090e9085f619c
927-
928-
- I have rebased the commit.
929-
930-
> Will they work properly on both the OWASP site as well as render PDF on https://mltop10.info/ site?
931-
932-
- yes. https://mltop10.info/ site needs this PR integrated. https://github.com/mltop10-info/mltop10.info/pull/6.
933-
- ePUB file to verify ePUB render available on my fork. > https://github.com/msnishanth9001/mltop10.info/blob/epub-fixes/docs/OWASP-Machine-Learning-Security-Top-10.epub
934-
935-
- for the fix to actually take effect you would have to run > quarto render and upload the new ePUB and PDF files.
936-
- this WF is to make renders and upload new ePUB and PDF renders every time there is a change in MD files. https://github.com/mltop10-info/mltop10.info/pull/4
937-
938-
939886
-------------------------------------------------------------------------------
940887

941888
# [\#114 Issue](https://github.com/OWASP/www-project-machine-learning-security-top-10/issues/114) `open`: [Fortnightly] Working Group Meeting - 2023-Sep-14
Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
# [\#129 PR](https://github.com/OWASP/www-project-machine-learning-security-top-10/pull/129) `open`: fix ePUB Renders.
1+
# [\#129 PR](https://github.com/OWASP/www-project-machine-learning-security-top-10/pull/129) `closed`: fix ePUB Renders.
22

33
#### <img src="https://avatars.githubusercontent.com/u/49409979?u=069bd6928cc6b4b478a304e0eb660ad4cb9cb505&v=4" width="50">[msnishanth9001](https://github.com/msnishanth9001) opened issue at [2023-10-20 06:50](https://github.com/OWASP/www-project-machine-learning-security-top-10/pull/129):
44

@@ -79,6 +79,10 @@ Will they work properly on both the OWASP site as well as render PDF on https://
7979
- for the fix to actually take effect you would have to run > quarto render and upload the new ePUB and PDF files.
8080
- this WF is to make renders and upload new ePUB and PDF renders every time there is a change in MD files. https://github.com/mltop10-info/mltop10.info/pull/4
8181

82+
#### <img src="https://avatars.githubusercontent.com/u/412800?v=4" width="50">[shsingh](https://github.com/shsingh) commented at [2023-12-18 03:59](https://github.com/OWASP/www-project-machine-learning-security-top-10/pull/129#issuecomment-1859513213):
83+
84+
Hi @msnishanth9001 I am not sure what is being commited in this PR anymore as the files only show the GH issues. Are please you able to see if you can send another PR with the proposed changes you had?
85+
8286

8387
-------------------------------------------------------------------------------
8488

issues/2023-11-16.187.issue.open.md

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,17 @@ Thanks!
2121

2222
- [X] I agree to follow this project's Code of Conduct
2323

24+
#### <img src="https://avatars.githubusercontent.com/u/412800?v=4" width="50">[shsingh](https://github.com/shsingh) commented at [2023-12-18 04:03](https://github.com/OWASP/www-project-machine-learning-security-top-10/issues/187#issuecomment-1859515638):
2425

26+
Hi @kapsolas apologies for the delay in responsing.
27+
28+
Will definitely look to changing "Model Stealing" to "Model Theft".
29+
30+
In terms of "Data Poisoning v Training data poisoning" I would like to defer to @yodap-dg
31+
32+
Typically in research papers it is referred to as "Data Poisoning" and I agree that the use case is largely around the training data itself.
33+
34+
What are your thoughts @yodap-dg?
2535

2636

2737
-------------------------------------------------------------------------------

issues/2023-11-17.188.issue.open.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -24,6 +24,10 @@ I'd suggest including MLOps-related vulnerabilities in the ML06 (or maybe in som
2424

2525
In my view it should be in ML06, However is should be better renamed with ML from AI supply chain i believe to keep ourself distinct, How would you recommend adding these in the existing ML06, keeping the attacks generic to other packages
2626

27+
#### <img src="https://avatars.githubusercontent.com/u/412800?v=4" width="50">[shsingh](https://github.com/shsingh) commented at [2023-12-18 04:06](https://github.com/OWASP/www-project-machine-learning-security-top-10/issues/188#issuecomment-1859517344):
28+
29+
Hi @mik0w I definitely think we should look at including the ecosystem of MLOps software. I am not sure that it all falls within supply chain though. Keen to hear your thoughts on this.
30+
2731

2832
-------------------------------------------------------------------------------
2933

issues/2023-11-23.189.issue.open.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,11 @@ Sometimes when you e.g. work on some slides for a presentation, you just want t
2020

2121
- [X] I agree to follow this project's Code of Conduct
2222

23+
#### <img src="https://avatars.githubusercontent.com/u/412800?v=4" width="50">[shsingh](https://github.com/shsingh) commented at [2023-12-18 04:07](https://github.com/OWASP/www-project-machine-learning-security-top-10/issues/189#issuecomment-1859518422):
2324

25+
Hi @mik0w is the suggestion to create a summary page? Or to look at enhacing the introductory sections within each of the ML risks so that they can be used as a summary? Or both?
26+
27+
In either case I think this is a good idea, let me get started on it.
2428

2529

2630
-------------------------------------------------------------------------------

issues/2023-11-30.192.pr.merged.md

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
# [\#192 PR](https://github.com/OWASP/www-project-machine-learning-security-top-10/pull/192) `merged`: chore: github issues archive
2+
3+
#### <img src="https://avatars.githubusercontent.com/u/412800?v=4" width="50">[shsingh](https://github.com/shsingh) opened issue at [2023-11-30 06:22](https://github.com/OWASP/www-project-machine-learning-security-top-10/pull/192):
4+
5+
6+
7+
8+
9+
10+
-------------------------------------------------------------------------------
11+
12+
13+
14+
[Export of Github issue for [OWASP/www-project-machine-learning-security-top-10](https://github.com/OWASP/www-project-machine-learning-security-top-10).]

issues/2023-12-07.193.pr.closed.md

Lines changed: 26 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,26 @@
1+
# [\#193 PR](https://github.com/OWASP/www-project-machine-learning-security-top-10/pull/193) `closed`: Adding slides from Null Hyderabad Chapter Nov Talk
2+
3+
#### <img src="https://avatars.githubusercontent.com/u/49409979?u=069bd6928cc6b4b478a304e0eb660ad4cb9cb505&v=4" width="50">[msnishanth9001](https://github.com/msnishanth9001) opened issue at [2023-12-07 06:50](https://github.com/OWASP/www-project-machine-learning-security-top-10/pull/193):
4+
5+
null Nov 2023, event details - https://null.community/events/948-hyderabad-monthly-meet
6+
7+
#### <img src="https://avatars.githubusercontent.com/u/25385987?u=7cdade85961090394618858dfe721238d54373cd&v=4" width="50">[sagarbhure](https://github.com/sagarbhure) commented at [2023-12-07 10:40](https://github.com/OWASP/www-project-machine-learning-security-top-10/pull/193#issuecomment-1845103941):
8+
9+
10+
can you addd the null link here in the description?
11+
Also can you add the pdf format, i hope its not much of your time to add this.
12+
13+
#### <img src="https://avatars.githubusercontent.com/u/49409979?u=069bd6928cc6b4b478a304e0eb660ad4cb9cb505&v=4" width="50">[msnishanth9001](https://github.com/msnishanth9001) commented at [2023-12-07 10:56](https://github.com/OWASP/www-project-machine-learning-security-top-10/pull/193#issuecomment-1845127922):
14+
15+
added items now. Thanks.
16+
17+
#### <img src="https://avatars.githubusercontent.com/u/412800?v=4" width="50">[shsingh](https://github.com/shsingh) commented at [2023-12-18 03:57](https://github.com/OWASP/www-project-machine-learning-security-top-10/pull/193#issuecomment-1859511977):
18+
19+
Hey @msnishanth9001 are you able to re-send this PR with signed commits please? As per https://github.com/OWASP/www-project-machine-learning-security-top-10/wiki/Contributing#pull-requests we prefer if contributors sign their commits.
20+
21+
22+
-------------------------------------------------------------------------------
23+
24+
25+
26+
[Export of Github issue for [OWASP/www-project-machine-learning-security-top-10](https://github.com/OWASP/www-project-machine-learning-security-top-10).]

issues/2023-12-18.194.pr.open.md

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
1+
# [\#194 PR](https://github.com/OWASP/www-project-machine-learning-security-top-10/pull/194) `open`: chore: github issues archive
2+
3+
#### <img src="https://avatars.githubusercontent.com/u/412800?v=4" width="50">[shsingh](https://github.com/shsingh) opened issue at [2023-12-18 04:11](https://github.com/OWASP/www-project-machine-learning-security-top-10/pull/194):
4+
5+
- chore: github issues archive
6+
- chore: github issues archive
7+
8+
9+
10+
11+
12+
-------------------------------------------------------------------------------
13+
14+
15+
16+
[Export of Github issue for [OWASP/www-project-machine-learning-security-top-10](https://github.com/OWASP/www-project-machine-learning-security-top-10).]

0 commit comments

Comments
 (0)