android / android/app-bundle-samples

Security Policy violation Binary Artifacts

Open
#123 28 comments 0 reactions 0 assignees View on GitHub
allstar
Dominant language
C++
Stars
735
Forks
348
PR merge metrics
No merged PRs in 30d

Description

_This issue was automatically created by [Allstar](https://github.com/ossf/allstar/)._

**Security Policy Violation**
Project is out of compliance with Binary Artifacts policy: binaries present in source code

**Rule Description**
Binary Artifacts are an increased security risk in your repository. Binary artifacts cannot be reviewed, allowing the introduction of possibly obsolete or maliciously subverted executables. For more information see the [Security Scorecards Documentation](https://github.com/ossf/scorecard/blob/main/docs/checks.md#binary-artifacts) for Binary Artifacts.

**Remediation Steps**
To remediate, remove the generated executable artifacts from the repository.

**Artifacts Found**

- DynamicFeatureNavigation/XML/third_party/bundletool/bundletool-all-0.13.0.jar

**Additional Information**
This policy is drawn from [Security Scorecards](https://github.com/ossf/scorecard/), which is a tool that scores a project's adherence to security best practices. You may wish to run a Scorecards scan directly on this repository for more details.

---

Allstar has been installed on all Google managed GitHub orgs. Policies are gradually being rolled out and enforced by the GOSST and OSPO teams. Learn more at http://go/allstar

This issue will auto resolve when the policy is in compliance.

Issue created by Allstar. See https://github.com/ossf/allstar/ for more information. For questions specific to the repository, please contact the owner or maintainer.

Contributor guide

Open the contributing guide

Research direction

Start with DynamicFeatureNavigation/XML/third_party/bundletool/bundletool-all-0.13.0.jar, the binary artifact identified by Allstar. Remove the generated executable artifact from the repository, then verify that the Binary Artifacts policy is compliant and that the issue auto-resolves.

Written by the indexing model from the issue text.

Assessment

Tech stack
android
Domain
build-system, security
Issue type
Bug
Difficulty
1/5
Estimated time
Under an hour
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.