Query Environment Information for Workflow Jobs
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 25/100
Hướng nghiên cứu
Bắt đầu bằng cách truy vết cách các job của workflow được biểu diễn và cách GitHub REST API được truy vấn để lấy các môi trường của repository. Được xem là hoàn tất khi mỗi job cung cấp một Environment với tên của nó và cho biết liệu các reviewer bắt buộc có xuất hiện trong các quy tắc bảo vệ của nó hay không, để các truy vấn Cypher có thể giảm false positive.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Is your feature request related to a problem? Please describe.
Many workflows that would be vulnerable to pwn requests or injection use a deployment environment with required approvals to protect a job from running. Usually this will manifest as a single job that runs in an environment in the beginning, and all other jobs will depend on that check succeeding.
It is possible to query a list of environments and their rules using the REST API without authentication. By adding this feature it will be possible to update cypher queries to reduce false positives.
Describe the solution you'd like
I'd like to see an Environment graph object attached to each job. The environment object should track the environment name and if the protection_rules array contains one or more entries of the required_reviewers class.
Here is an example of a repository that uses deployment environments: https://api.github.com/repos/netflix/mantis/environments
Describe alternatives you've considered
None, this is pretty clear cut because environment gating with required approvals will require manual verification to ensure a detection is not a false positive.
Additional context
Mentioned this in an earlier issue - https://github.com/CycodeLabs/raven/issues/111, so this covers adding the environment check.
I'm actually working on implementing this and will have a PR open soon!
- Ngôn ngữ chính
- Python
- Star
- 748
- Fork
- 46
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của CycodeLabs/raven
-
`library` folder not included in the source distributionCó thể đã có người làm Có pull request liên kết đang mở hoặc đã được merge. Đang mởquery-library
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 62/100
CycodeLabs/raven#183 · 2 bình luận ·
-
报错Đang mở
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 15/100
CycodeLabs/raven#199 ·
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 35/100
CycodeLabs/raven#188 · 2 bình luận · 1 reaction ·
-
feature indexer
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 45/100
CycodeLabs/raven#114 ·
-
Add option to scan a specific repoCó thể đã có người làm Có pull request liên kết đang mở hoặc đã được merge. Đang mởdownloader feature good first issue
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 25/100
CycodeLabs/raven#109 · 2 bình luận · 1 reaction ·
Tất cả issue của CycodeLabs/raven
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
Maintainer thường phản hồi trong vòng 3 ngày
-
Negation with "not" and "no" is ignored during sentiment analysisCó thể đã có người làm @vivek-3728 đã nhận hôm nay. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
techcsispit/mess-mood#11 · 1 bình luận ·
-
changelog investigate
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
ramnes/notion-sdk-py#408 ·
-
good first issue
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 83/100
btclib-org/btclib-wallet#267 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
good first issue tech-debt
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
knnmelprop/YAADO#111 ·