GoogleCloudPlatform / GoogleCloudPlatform/reporting-api-processor

Security Policy violation Binary Artifacts

Abierto
#6 2 comentarios 0 reacciones 0 asignados Ver en GitHub
allstar
Lenguaje dominante
Java
Estrellas
9
Forks
2
Métricas de merge de PR
Sin PR fusionados en 30 d

Descripción

_This issue was automatically created by [Allstar](https://github.com/ossf/allstar/)._

**Security Policy Violation**
Project is out of compliance with Binary Artifacts policy: binaries present in source code

**Rule Description**
Binary Artifacts are an increased security risk in your repository. Binary artifacts cannot be reviewed, allowing the introduction of possibly obsolete or maliciously subverted executables. For more information see the [Security Scorecards Documentation](https://github.com/ossf/scorecard/blob/main/docs/checks.md#binary-artifacts) for Binary Artifacts.

**Remediation Steps**
To remediate, remove the generated executable artifacts from the repository.

**Artifacts Found**

- redash/docker-compose

**Additional Information**
This policy is drawn from [Security Scorecards](https://github.com/ossf/scorecard/), which is a tool that scores a project's adherence to security best practices. You may wish to run a Scorecards scan directly on this repository for more details.

---

Allstar has been installed on all Google managed GitHub orgs. Policies are gradually being rolled out and enforced by the GOSST and OSPO teams. Learn more at http://go/allstar

This issue will auto resolve when the policy is in compliance.

Issue created by Allstar. See https://github.com/ossf/allstar/ for more information. For questions specific to the repository, please contact the owner or maintainer.

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

Comienza inspeccionando el artefacto indicado en redash/docker-compose y confirma que es el ejecutable generado identificado por la política. Elimina ese artefacto del repositorio; el issue indica que se resolverá automáticamente cuando la política de Binary Artifacts cumpla los requisitos.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
docker-compose
Área
devops, security
Tipo de issue
Error
Dificultad
1/5
Tiempo estimado
Menos de una hora
Estado de actividad
Estancado
Claridad
Bien especificado
Aptitud para principiantes
45/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.