First-party GitHub Action (action.yml) with Marketplace listing for scheduled attack-surface monitoring
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 初心者へのやさしさ
- 35/100
調査の方向性
Start with ROADMAP.md:24 and the existing -diff, exit-code-4, -stats, and signed-release behavior described in the issue. Define the composite Action inputs and steps in action.yml, including release verification and durable baseline storage; the issue does not name a baseline store, so that choice needs investigation. Done means a scheduled diff works with three inputs, the README and docs/monitoring.md use it, and the Action is listed on the Marketplace.
索引モデルが issue の本文から書いたものです。
説明
Value / who it's for
Security teams and bug-bounty hunters who want "tell me when a new subdomain appears" without hand-maintaining a workflow. The Marketplace is a discovery channel none of the main DNS brute-force tools (puredns, shuffledns, dnsx, gobuster) occupy. It also replaces the hand-copied example in docs/monitoring.md, which has the supply-chain and baseline problems tracked separately.
Rationale
-diff, the exit code 4 on change, the -stats verdict and signed releases with attestations already exist. An Action is mostly packaging. ROADMAP.md:24 already lists it.
Suggested approach
action.yml(composite) in this repo orTMHSDigital/subenum-action. Inputs:domain/domains-file,wordlist,rate,max-queries,resolvers,fail-on: degraded|unreliable,open-issue: true.- Steps: download the release asset for the runner OS, verify the checksum or attestation, restore the baseline from a durable store, run with
-diff -stats, upload artifacts, write a job summary table, and optionally open or update an issue. - Publish to the Marketplace and tag
v1.
Done when
uses: TMHSDigital/subenum@v1 with three inputs runs a scheduled diff end to end, the README and docs/monitoring.md use it, and it's listed on the Marketplace.
- 主要言語
- Go
- スター
- 1
- フォーク
- 1
- 平均マージ
- 5日 2時間
- マージ済み PR(30日)
- 3
環境構築
このプロジェクトの開発コンテナを、あなたの GitHub アカウントでブラウザ上に起動します。
- Dockerfile または Docker Compose ファイルあり
- プルリクエストのテンプレートあり
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
TMHSDigital/subenum のほかの issue
-
area: cli enhancement good first issue
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
TMHSDigital/subenum#136 ·
メンテナーはふだん 1 日以内に返信
-
community documentation good first issue
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
TMHSDigital/subenum#135 ·
メンテナーはふだん 1 日以内に返信
-
area: dns enhancement good first issue
難易度 2/5 1時間未満 初心者へのやさしさ 90/100
TMHSDigital/subenum#134 ·
メンテナーはふだん 1 日以内に返信
-
community marketing priority: low
難易度 5/5 1週間以上 初心者へのやさしさ 35/100
TMHSDigital/subenum#132 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
feature priority: low
難易度 5/5 1週間以上 初心者へのやさしさ 35/100
TMHSDigital/subenum#131 ·
メンテナーはふだん 1 日以内に返信
TMHSDigital/subenum の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 86/100
war-and-code/dircue#200 ·
メンテナーはふだん 1 日以内に返信
-
actor/human kind/bug priority/important-soon triage-accepted
難易度 2/5 1〜3時間 初心者へのやさしさ 66/100
kelos-dev/kelos#1804 · コメント 2 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
メンテナーはふだん 1 日以内に返信
-
`date` → `date-time` (and `time` → `date-time`) is classified as a widening, but a date is not a valid date-time対応中かも @reuvenharrison が今日担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
メンテナーはふだん 1 日以内に返信
-
fix: invalid GPU spec in SparkApplication is silently ignored対応中かも @pratik-naik003 が今日担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
kubeflow/spark-operator#3223 ·
メンテナーはふだん 5 日以内に返信