Query Environment Information for Workflow Jobs
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 25/100
Línea de trabajo
Empieza rastreando cómo se representan los trabajos de workflow y cómo se consulta la GitHub REST API para obtener los entornos del repositorio. Se considera terminado cuando cada trabajo expone un Environment con su nombre y si aparecen revisores requeridos en sus reglas de protección, de modo que las consultas de Cypher puedan reducir los falsos positivos.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Is your feature request related to a problem? Please describe.
Many workflows that would be vulnerable to pwn requests or injection use a deployment environment with required approvals to protect a job from running. Usually this will manifest as a single job that runs in an environment in the beginning, and all other jobs will depend on that check succeeding.
It is possible to query a list of environments and their rules using the REST API without authentication. By adding this feature it will be possible to update cypher queries to reduce false positives.
Describe the solution you'd like
I'd like to see an Environment graph object attached to each job. The environment object should track the environment name and if the protection_rules array contains one or more entries of the required_reviewers class.
Here is an example of a repository that uses deployment environments: https://api.github.com/repos/netflix/mantis/environments
Describe alternatives you've considered
None, this is pretty clear cut because environment gating with required approvals will require manual verification to ensure a detection is not a false positive.
Additional context
Mentioned this in an earlier issue - https://github.com/CycodeLabs/raven/issues/111, so this covers adding the environment check.
I'm actually working on implementing this and will have a PR open soon!
- Lenguaje dominante
- Python
- Estrellas
- 748
- Forks
- 46
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de CycodeLabs/raven
-
`library` folder not included in the source distributionPosiblemente ocupada Un pull request vinculado a esta issue está abierto o ya se fusionó. Abiertoquery-library
Dificultad 2/5 1-3 horas Aptitud para principiantes 62/100
CycodeLabs/raven#183 · 2 comentarios ·
-
报错Abierto
Dificultad 4/5 3-5 días Aptitud para principiantes 15/100
CycodeLabs/raven#199 ·
-
Dificultad 4/5 3-5 días Aptitud para principiantes 35/100
CycodeLabs/raven#188 · 2 comentarios · 1 reacción ·
-
feature indexer
Dificultad 3/5 1-2 días Aptitud para principiantes 45/100
CycodeLabs/raven#114 ·
-
Add option to scan a specific repoPosiblemente ocupada Un pull request vinculado a esta issue está abierto o ya se fusionó. Abiertodownloader feature good first issue
Dificultad 3/5 1-2 días Aptitud para principiantes 25/100
CycodeLabs/raven#109 · 2 comentarios · 1 reacción ·
Todos los issues de CycodeLabs/raven
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
Los mantenedores suelen responder en 3 días
-
Negation with "not" and "no" is ignored during sentiment analysisPosiblemente ocupada @vivek-3728 la tomó hoy. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
techcsispit/mess-mood#11 · 1 comentario ·
-
changelog investigate
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
ramnes/notion-sdk-py#408 ·
-
good first issue
Dificultad 2/5 1-3 horas Aptitud para principiantes 83/100
btclib-org/btclib-wallet#267 ·
Los mantenedores suelen responder en 1 día
-
good first issue tech-debt
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
knnmelprop/YAADO#111 ·