crashappsec / crashappsec/github-analyzer
Audit public gists for internal APIs and sensitive information
- Lingua principale
- Go
- Stelle
- 77
- Fork
- 8
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Descrizione
Audit public gists for a given repo for non-public APIs or sensitive information exposed. We can use some off-the-shelf secrets scanner for this but it might be trickier to automatically detect snippets. We can definitely provide awareness for users' activity though by outlining their public gists
Guida per i contributori
Apri la guida per i contributori
Direzione di ricerca
No files, tests, or entry points are named. Start by reviewing the repository's existing GitHub audit flow, then define how public gists for a repository are found and what counts as an exposed internal API or sensitive value; done should include a documented scope and reliable reporting behavior.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- github, go
- Ambito
- security
- Tipo di issue
- Funzionalità
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Stato di attività
- Ferma
- Chiarezza
- Da chiarire
- Idoneità per principianti
- 25/100