GoogleCloudPlatform / GoogleCloudPlatform/reporting-api-processor

Security Policy violation Binary Artifacts

Ouverte
#6 2 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
allstar
Langage dominant
Java
Étoiles
9
Forks
2
Métriques de merge des PR
Aucune PR mergée en 30 j

Description

_This issue was automatically created by [Allstar](https://github.com/ossf/allstar/)._

**Security Policy Violation**
Project is out of compliance with Binary Artifacts policy: binaries present in source code

**Rule Description**
Binary Artifacts are an increased security risk in your repository. Binary artifacts cannot be reviewed, allowing the introduction of possibly obsolete or maliciously subverted executables. For more information see the [Security Scorecards Documentation](https://github.com/ossf/scorecard/blob/main/docs/checks.md#binary-artifacts) for Binary Artifacts.

**Remediation Steps**
To remediate, remove the generated executable artifacts from the repository.

**Artifacts Found**

- redash/docker-compose

**Additional Information**
This policy is drawn from [Security Scorecards](https://github.com/ossf/scorecard/), which is a tool that scores a project's adherence to security best practices. You may wish to run a Scorecards scan directly on this repository for more details.

---

Allstar has been installed on all Google managed GitHub orgs. Policies are gradually being rolled out and enforced by the GOSST and OSPO teams. Learn more at http://go/allstar

This issue will auto resolve when the policy is in compliance.

Issue created by Allstar. See https://github.com/ossf/allstar/ for more information. For questions specific to the repository, please contact the owner or maintainer.

Guide de contribution

Ouvrir le guide de contribution

Piste de recherche

Commencez par inspecter l’artefact indiqué dans redash/docker-compose et confirmez qu’il s’agit de l’exécutable généré identifié par la politique. Supprimez cet artefact du dépôt ; l’issue indique qu’elle se résoudra automatiquement lorsque la politique Binary Artifacts sera conforme.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
docker-compose
Domaine
devops, security
Type d'issue
Bug
Difficulté
1/5
Temps estimé
Moins d'une heure
Activité
À l'abandon
Clarté
Clairement spécifiée
Accessibilité débutants
45/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.