GoogleCloudPlatform / GoogleCloudPlatform/reporting-api-processor
Security Policy violation Binary Artifacts
- 主要言語
- Java
- スター
- 9
- フォーク
- 2
- PR マージ指標
- 30日以内にマージされた PR はありません
説明
_This issue was automatically created by [Allstar](https://github.com/ossf/allstar/)._
**Security Policy Violation**
Project is out of compliance with Binary Artifacts policy: binaries present in source code
**Rule Description**
Binary Artifacts are an increased security risk in your repository. Binary artifacts cannot be reviewed, allowing the introduction of possibly obsolete or maliciously subverted executables. For more information see the [Security Scorecards Documentation](https://github.com/ossf/scorecard/blob/main/docs/checks.md#binary-artifacts) for Binary Artifacts.
**Remediation Steps**
To remediate, remove the generated executable artifacts from the repository.
**Artifacts Found**
- redash/docker-compose
**Additional Information**
This policy is drawn from [Security Scorecards](https://github.com/ossf/scorecard/), which is a tool that scores a project's adherence to security best practices. You may wish to run a Scorecards scan directly on this repository for more details.
---
Allstar has been installed on all Google managed GitHub orgs. Policies are gradually being rolled out and enforced by the GOSST and OSPO teams. Learn more at http://go/allstar
This issue will auto resolve when the policy is in compliance.
Issue created by Allstar. See https://github.com/ossf/allstar/ for more information. For questions specific to the repository, please contact the owner or maintainer.
コントリビューションガイド
調査の方向性
まず redash/docker-compose に記載されているアーティファクトを調査し、それがポリシーによって特定された生成済みの実行可能ファイルであることを確認します。そのアーティファクトをリポジトリから削除します。issue には、Binary Artifacts ポリシーに準拠すると自動的に解決されると記載されています。
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- docker-compose
- 領域
- devops, security
- issue の種類
- バグ
- 難易度
- 1/5
- 見積もり時間
- 1時間未満
- 活発さ
- 停滞
- 明瞭さ
- 明確に書かれている
- 初心者へのやさしさ
- 45/100