Query Environment Information for Workflow Jobs
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 25/100
Direzione di ricerca
Inizia tracciando come sono rappresentati i job del workflow e come viene interrogata la GitHub REST API per gli ambienti del repository. Il lavoro è completato quando ogni job espone un Environment con il relativo nome e indica se nelle sue regole di protezione compaiono reviewer obbligatori, così che le query Cypher possano ridurre i falsi positivi.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Is your feature request related to a problem? Please describe.
Many workflows that would be vulnerable to pwn requests or injection use a deployment environment with required approvals to protect a job from running. Usually this will manifest as a single job that runs in an environment in the beginning, and all other jobs will depend on that check succeeding.
It is possible to query a list of environments and their rules using the REST API without authentication. By adding this feature it will be possible to update cypher queries to reduce false positives.
Describe the solution you'd like
I'd like to see an Environment graph object attached to each job. The environment object should track the environment name and if the protection_rules array contains one or more entries of the required_reviewers class.
Here is an example of a repository that uses deployment environments: https://api.github.com/repos/netflix/mantis/environments
Describe alternatives you've considered
None, this is pretty clear cut because environment gating with required approvals will require manual verification to ensure a detection is not a false positive.
Additional context
Mentioned this in an earlier issue - https://github.com/CycodeLabs/raven/issues/111, so this covers adding the environment check.
I'm actually working on implementing this and will have a PR open soon!
- Lingua principale
- Python
- Stelle
- 748
- Fork
- 45
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di CycodeLabs/raven
-
`library` folder not included in the source distributionForse già presa Una pull request collegata a questa issue è aperta o già unita. Apertaquery-library
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
CycodeLabs/raven#183 · 2 commenti ·
-
报错Aperta
Difficoltà 4/5 3-5 giorni Idoneità per principianti 15/100
CycodeLabs/raven#199 ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 35/100
CycodeLabs/raven#188 · 2 commenti · 1 reazione ·
-
feature indexer
Difficoltà 3/5 1-2 giorni Idoneità per principianti 45/100
CycodeLabs/raven#114 ·
-
Add option to scan a specific repoForse già presa Una pull request collegata a questa issue è aperta o già unita. Apertadownloader feature good first issue
Difficoltà 3/5 1-2 giorni Idoneità per principianti 25/100
CycodeLabs/raven#109 · 2 commenti · 1 reazione ·
Tutte le issue di CycodeLabs/raven
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
I maintainer di solito rispondono entro 3 giorni
-
Negation with "not" and "no" is ignored during sentiment analysisForse già presa @vivek-3728 l’ha presa oggi. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
techcsispit/mess-mood#11 · 1 commento ·
-
changelog investigate
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
ramnes/notion-sdk-py#408 ·
-
good first issue
Difficoltà 2/5 1-3 ore Idoneità per principianti 83/100
btclib-org/btclib-wallet#267 ·
I maintainer di solito rispondono entro 1 giorno
-
good first issue tech-debt
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
knnmelprop/YAADO#111 ·