First-party GitHub Action (action.yml) with Marketplace listing for scheduled attack-surface monitoring
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Aptitud para principiantes
- 35/100
Línea de trabajo
Start with ROADMAP.md:24 and the existing -diff, exit-code-4, -stats, and signed-release behavior described in the issue. Define the composite Action inputs and steps in action.yml, including release verification and durable baseline storage; the issue does not name a baseline store, so that choice needs investigation. Done means a scheduled diff works with three inputs, the README and docs/monitoring.md use it, and the Action is listed on the Marketplace.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Value / who it's for
Security teams and bug-bounty hunters who want "tell me when a new subdomain appears" without hand-maintaining a workflow. The Marketplace is a discovery channel none of the main DNS brute-force tools (puredns, shuffledns, dnsx, gobuster) occupy. It also replaces the hand-copied example in docs/monitoring.md, which has the supply-chain and baseline problems tracked separately.
Rationale
-diff, the exit code 4 on change, the -stats verdict and signed releases with attestations already exist. An Action is mostly packaging. ROADMAP.md:24 already lists it.
Suggested approach
action.yml(composite) in this repo orTMHSDigital/subenum-action. Inputs:domain/domains-file,wordlist,rate,max-queries,resolvers,fail-on: degraded|unreliable,open-issue: true.- Steps: download the release asset for the runner OS, verify the checksum or attestation, restore the baseline from a durable store, run with
-diff -stats, upload artifacts, write a job summary table, and optionally open or update an issue. - Publish to the Marketplace and tag
v1.
Done when
uses: TMHSDigital/subenum@v1 with three inputs runs a scheduled diff end to end, the README and docs/monitoring.md use it, and it's listed on the Marketplace.
- Lenguaje dominante
- Go
- Estrellas
- 1
- Forks
- 1
- Merge medio
- 5 d 2 h
- PR fusionados (30 d)
- 3
Preparar el entorno
Inicia el contenedor de desarrollo del proyecto en tu navegador, con tu propia cuenta de GitHub.
- Incluye un Dockerfile o un archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de TMHSDigital/subenum
-
area: cli enhancement good first issue
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
TMHSDigital/subenum#136 ·
Los mantenedores suelen responder en 1 día
-
community documentation good first issue
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
TMHSDigital/subenum#135 ·
Los mantenedores suelen responder en 1 día
-
area: dns enhancement good first issue
Dificultad 2/5 Menos de una hora Aptitud para principiantes 90/100
TMHSDigital/subenum#134 ·
Los mantenedores suelen responder en 1 día
-
community marketing priority: low
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
TMHSDigital/subenum#132 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
feature priority: low
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
TMHSDigital/subenum#131 ·
Los mantenedores suelen responder en 1 día
Todos los issues de TMHSDigital/subenum
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 86/100
war-and-code/dircue#200 ·
Los mantenedores suelen responder en 1 día
-
actor/human kind/bug priority/important-soon triage-accepted
Dificultad 2/5 1-3 horas Aptitud para principiantes 66/100
kelos-dev/kelos#1804 · 2 comentarios ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
Los mantenedores suelen responder en 1 día
-
`date` → `date-time` (and `time` → `date-time`) is classified as a widening, but a date is not a valid date-timePosiblemente ocupada @reuvenharrison la tomó hoy. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
Los mantenedores suelen responder en 1 día
-
fix: invalid GPU spec in SparkApplication is silently ignoredPosiblemente ocupada @pratik-naik003 la tomó hoy. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
kubeflow/spark-operator#3223 ·
Los mantenedores suelen responder en 5 días