GitHub security workshop: Add Copilot-assisted remediation and verification
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 68/100
- Loại issue
- Tài liệu
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- github, github-actions, python
- Lĩnh vực
- ci-cd, documentation, security, testing-qa
Hướng nghiên cứu
Bắt đầu từ alert do CodeQL lab hiện có giới thiệu, rồi lần theo đường dẫn dễ bị tổn thương và các bài kiểm thử hành vi tập trung của nó. Thêm hướng dẫn khắc phục có Copilot hỗ trợ và hướng dẫn khắc phục thủ công, sau đó commit bản sửa lỗi vào lab branch, chạy lại code scanning và xác nhận rằng pull request check đã đạt cũng như alert ban đầu đã được khắc phục hoặc không còn tồn tại.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Goal
Teach a complete remediation loop: understand a CodeQL finding, use Copilot as an optional assistant, review the proposed fix, test it, and verify the security alert is resolved.
Scope
Use the alert introduced by the CodeQL lab. Prompts should ask Copilot to explain the weakness and propose a minimal secure change, but learners must validate the output rather than accept it automatically. Include an equivalent manual remediation path for learners without Copilot.
Acceptance criteria
- The exercise provides model-agnostic example prompts for explanation, remediation, and test generation.
- A manual secure implementation is available as a fallback.
- Learners review the change against the CodeQL data flow and secure coding guidance.
- Focused behavior tests cover the vulnerable path and pass after remediation.
- Learners commit the fix to the lab branch and trigger code scanning again.
- The pull request check passes and the original alert is shown as fixed or absent from the updated analysis.
- The exercise states that Copilot output is untrusted until reviewed and tested.
- No specific optional model or transient UI layout is required.
- Ngôn ngữ chính
- Python
- Star
- 80
- Fork
- 169
- Merge trung bình
- 31 phút
- Pull request đã merge (30 ngày)
- 1
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của github-samples/pets-workshop
-
priority: P0
Độ khó 2/5 1-2 ngày Mức phù hợp với người mới 78/100
github-samples/pets-workshop#268 · 1 bình luận ·
-
priority: P0
Độ khó 1/5 1-3 giờ Mức phù hợp với người mới 88/100
github-samples/pets-workshop#267 · 1 bình luận ·
-
priority: P1
Độ khó 1/5 1-3 giờ Mức phù hợp với người mới 92/100
github-samples/pets-workshop#261 · 1 bình luận ·
-
priority: P1
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
github-samples/pets-workshop#257 · 1 bình luận ·
-
priority: deferred
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 45/100
github-samples/pets-workshop#278 · 1 bình luận ·
Tất cả issue của github-samples/pets-workshop
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
Maintainer thường phản hồi trong vòng 1 ngày
-
SR_SECURITY_DESCRIPTOR.fromString drops the SACL when no DACL is presentCó thể đã có người làm @paul7436 đã nhận hôm nay. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
equinor/fmu-sumo-uploader#302 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
modelscope/evalscope#1821 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Sanity on ansible-core devel fails: ignore-2.23.txt references the removed import-3.9 testCó thể đã có người làm @yurnov đã nhận hôm nay. Đang mởneeds_triage
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 91/100
ansible-collections/kubernetes.core#1275 ·
Maintainer thường phản hồi trong vòng 1 ngày