OWASP / OWASP/wrongsecrets

Create a separate repo where you allow actions to run, so you can get the secret out

Open
#425 3 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

New Challenge
Dominant language
HTML
Stars
1.5k
Forks
625
Avg merge
14h 21m
Merged PRs (30d)
44

Description

Create a separate repo where you allow actions to run, so you can get the secret out. The idea would be that you have a challenge with a forkable action+Secret, so anyone forking this repository should get access to the given secret.
TODO:

  • Have the Github secret forkable
  • Create a github action using it
  • Create the actual challenge with the secret encrypted as part of the java code (See contributing.md on how to create the challenge)

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with contributing.md to understand how to create the challenge, then review the requirements for the separate repository, forkable GitHub secret, and GitHub Action. Done means the secret is available to forks, the Action uses it, and the challenge includes the encrypted secret in the Java code.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions, java
Domain
ci-cd, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.