Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Query Environment Information for Workflow Jobs

Aperta
#119 6 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
25/100
Tipo di issue
Funzionalità
Chiarezza
Abbastanza chiara
Stato di attività
Ferma
Stack tecnologico
github, github-actions, python
Ambito
ci-cd, security

Direzione di ricerca

Inizia tracciando come sono rappresentati i job del workflow e come viene interrogata la GitHub REST API per gli ambienti del repository. Il lavoro è completato quando ogni job espone un Environment con il relativo nome e indica se nelle sue regole di protezione compaiono reviewer obbligatori, così che le query Cypher possano ridurre i falsi positivi.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

feature

Is your feature request related to a problem? Please describe.

Many workflows that would be vulnerable to pwn requests or injection use a deployment environment with required approvals to protect a job from running. Usually this will manifest as a single job that runs in an environment in the beginning, and all other jobs will depend on that check succeeding.

It is possible to query a list of environments and their rules using the REST API without authentication. By adding this feature it will be possible to update cypher queries to reduce false positives.

Describe the solution you'd like

I'd like to see an Environment graph object attached to each job. The environment object should track the environment name and if the protection_rules array contains one or more entries of the required_reviewers class.

Here is an example of a repository that uses deployment environments: https://api.github.com/repos/netflix/mantis/environments

Describe alternatives you've considered

None, this is pretty clear cut because environment gating with required approvals will require manual verification to ensure a detection is not a false positive.

Additional context

Mentioned this in an earlier issue - https://github.com/CycodeLabs/raven/issues/111, so this covers adding the environment check.

I'm actually working on implementing this and will have a PR open soon!

Lingua principale
Python
Stelle
748
Fork
45
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di CycodeLabs/raven

Tutte le issue di CycodeLabs/raven

Issue simili

Altre issue su Python

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.