GoogleCloudPlatform / GoogleCloudPlatform/reporting-api-processor

Security Policy violation Binary Artifacts

Đang mở
#6 2 bình luận 0 reaction 0 người được giao Xem trên GitHub
allstar
Ngôn ngữ chính
Java
Star
9
Fork
2
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Mô tả

_This issue was automatically created by [Allstar](https://github.com/ossf/allstar/)._

**Security Policy Violation**
Project is out of compliance with Binary Artifacts policy: binaries present in source code

**Rule Description**
Binary Artifacts are an increased security risk in your repository. Binary artifacts cannot be reviewed, allowing the introduction of possibly obsolete or maliciously subverted executables. For more information see the [Security Scorecards Documentation](https://github.com/ossf/scorecard/blob/main/docs/checks.md#binary-artifacts) for Binary Artifacts.

**Remediation Steps**
To remediate, remove the generated executable artifacts from the repository.

**Artifacts Found**

- redash/docker-compose

**Additional Information**
This policy is drawn from [Security Scorecards](https://github.com/ossf/scorecard/), which is a tool that scores a project's adherence to security best practices. You may wish to run a Scorecards scan directly on this repository for more details.

---

Allstar has been installed on all Google managed GitHub orgs. Policies are gradually being rolled out and enforced by the GOSST and OSPO teams. Learn more at http://go/allstar

This issue will auto resolve when the policy is in compliance.

Issue created by Allstar. See https://github.com/ossf/allstar/ for more information. For questions specific to the repository, please contact the owner or maintainer.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

Bắt đầu bằng cách kiểm tra artifact được liệt kê tại redash/docker-compose và xác nhận rằng đó là tệp thực thi được tạo tự động do policy xác định. Xóa artifact đó khỏi repository; issue nêu rằng nó sẽ tự động được giải quyết khi policy Binary Artifacts tuân thủ.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
docker-compose
Lĩnh vực
devops, security
Loại issue
Lỗi
Độ khó
1/5
Thời gian dự kiến
Dưới một giờ
Mức độ hoạt động
Đình trệ
Độ rõ ràng
Đặc tả rõ ràng
Mức phù hợp với người mới
45/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.