crashappsec / crashappsec/github-analyzer

Audit public gists for internal APIs and sensitive information

Aperta
#22 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
Lingua principale
Go
Stelle
77
Fork
8
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

Audit public gists for a given repo for non-public APIs or sensitive information exposed. We can use some off-the-shelf secrets scanner for this but it might be trickier to automatically detect snippets. We can definitely provide awareness for users' activity though by outlining their public gists

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

No files, tests, or entry points are named. Start by reviewing the repository's existing GitHub audit flow, then define how public gists for a repository are found and what counts as an exposed internal API or sensitive value; done should include a documented scope and reliable reporting behavior.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
github, go
Ambito
security
Tipo di issue
Funzionalità
Difficoltà
5/5
Tempo stimato
Più di una settimana
Stato di attività
Ferma
Chiarezza
Da chiarire
Idoneità per principianti
25/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.