android / android/android-test
Security Policy violation Binary Artifacts
- Dominant language
- Java
- Stars
- 1.2k
- Forks
- 342
- Avg merge
- 11h 29m
- Merged PRs (30d)
- 2
Description
_This issue was automatically created by [Allstar](https://github.com/ossf/allstar/)._
**Security Policy Violation**
Project is out of compliance with Binary Artifacts policy: binaries present in source code
**Rule Description**
Binary Artifacts are an increased security risk in your repository. Binary artifacts cannot be reviewed, allowing the introduction of possibly obsolete or maliciously subverted executables. For more information see the [Security Scorecards Documentation](https://github.com/ossf/scorecard/blob/main/docs/checks.md#binary-artifacts) for Binary Artifacts.
**Remediation Steps**
To remediate, remove the generated executable artifacts from the repository.
**First 10 Artifacts Found**
- opensource/entry_point_deploy.jar
- opensource/java_lib/libEvaluationAtom.jar
- opensource/java_lib/libWebDriverScripts.jar
- opensource/java_lib/libbridge.jar
- tools/android/emulator/daemon/g3_activity_controller.jar
- tools/android/emulator/daemon/x86/adbd
- tools/android/emulator/daemon/x86/pipe_traversal
- tools/android/emulator/daemon/x86/waterfall
- tools/android/emulator/support/adb.turbo
- tools/android/emulator/support/waterfall/forward_bin
- Run a Scorecards scan to see full list.
**Additional Information**
This policy is drawn from [Security Scorecards](https://github.com/ossf/scorecard/), which is a tool that scores a project's adherence to security best practices. You may wish to run a Scorecards scan directly on this repository for more details.
---
:warning: There is an updated version of this policy result! [Click here to see the latest update](https://github.com/android/android-test/issues/1621#issuecomment-1376285707)
---
Allstar has been installed on all Google managed GitHub orgs. Policies are gradually being rolled out and enforced by the GOSST and OSPO teams. Learn more at http://go/allstar
This issue will auto resolve when the policy is in compliance.
Issue created by Allstar. See https://github.com/ossf/allstar/ for more information. For questions specific to the repository, please contact the owner or maintainer.
Contributor guide
Research direction
Run a Security Scorecards scan to obtain the complete artifact list, then inspect the listed paths such as opensource/entry_point_deploy.jar and tools/android/emulator/daemon/x86/adbd. Determine which are generated artifacts, remove them from the repository, and rerun the scan until the Binary Artifacts policy is compliant.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- android, java
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100