First-party GitHub Action (action.yml) with Marketplace listing for scheduled attack-surface monitoring
Mantenedores costumam responder em até 1 dia
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 5/5
- Tempo estimado
- Mais de uma semana
- Facilidade para iniciantes
- 35/100
Direção de pesquisa
Start with ROADMAP.md:24 and the existing -diff, exit-code-4, -stats, and signed-release behavior described in the issue. Define the composite Action inputs and steps in action.yml, including release verification and durable baseline storage; the issue does not name a baseline store, so that choice needs investigation. Done means a scheduled diff works with three inputs, the README and docs/monitoring.md use it, and the Action is listed on the Marketplace.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
Value / who it's for
Security teams and bug-bounty hunters who want "tell me when a new subdomain appears" without hand-maintaining a workflow. The Marketplace is a discovery channel none of the main DNS brute-force tools (puredns, shuffledns, dnsx, gobuster) occupy. It also replaces the hand-copied example in docs/monitoring.md, which has the supply-chain and baseline problems tracked separately.
Rationale
-diff, the exit code 4 on change, the -stats verdict and signed releases with attestations already exist. An Action is mostly packaging. ROADMAP.md:24 already lists it.
Suggested approach
action.yml(composite) in this repo orTMHSDigital/subenum-action. Inputs:domain/domains-file,wordlist,rate,max-queries,resolvers,fail-on: degraded|unreliable,open-issue: true.- Steps: download the release asset for the runner OS, verify the checksum or attestation, restore the baseline from a durable store, run with
-diff -stats, upload artifacts, write a job summary table, and optionally open or update an issue. - Publish to the Marketplace and tag
v1.
Done when
uses: TMHSDigital/subenum@v1 with three inputs runs a scheduled diff end to end, the README and docs/monitoring.md use it, and it's listed on the Marketplace.
- Linguagem predominante
- Go
- Estrelas
- 1
- Forks
- 1
- Merge médio
- 5d 2h
- PRs com merge (30d)
- 3
Preparar o ambiente
Inicia o contêiner de desenvolvimento do projeto no navegador, com a sua própria conta do GitHub.
- Inclui um Dockerfile ou arquivo Docker Compose
- Tem um modelo de pull request
- Ler o guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de TMHSDigital/subenum
-
area: cli enhancement good first issue
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 88/100
TMHSDigital/subenum#136 ·
Mantenedores costumam responder em até 1 dia
-
community documentation good first issue
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 85/100
TMHSDigital/subenum#135 ·
Mantenedores costumam responder em até 1 dia
-
area: dns enhancement good first issue
Dificuldade 2/5 Menos de uma hora Facilidade para iniciantes 90/100
TMHSDigital/subenum#134 ·
Mantenedores costumam responder em até 1 dia
-
community marketing priority: low
Dificuldade 5/5 Mais de uma semana Facilidade para iniciantes 35/100
TMHSDigital/subenum#132 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
-
feature priority: low
Dificuldade 5/5 Mais de uma semana Facilidade para iniciantes 35/100
TMHSDigital/subenum#131 ·
Mantenedores costumam responder em até 1 dia
Todas as issues de TMHSDigital/subenum
Issues semelhantes
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 86/100
war-and-code/dircue#200 ·
Mantenedores costumam responder em até 1 dia
-
actor/human kind/bug priority/important-soon triage-accepted
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 66/100
kelos-dev/kelos#1804 · 2 comentários ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 82/100
Mantenedores costumam responder em até 1 dia
-
`date` → `date-time` (and `time` → `date-time`) is classified as a widening, but a date is not a valid date-timeTalvez já em andamento @reuvenharrison assumiu hoje. Aberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 88/100
Mantenedores costumam responder em até 1 dia
-
fix: invalid GPU spec in SparkApplication is silently ignoredTalvez já em andamento @pratik-naik003 assumiu hoje. Aberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 85/100
kubeflow/spark-operator#3223 ·
Mantenedores costumam responder em até 5 dias