duo-labs / duo-labs/cloudmapper

Have private account list for weboftrust

Open
#714 0 comments 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
JavaScript
Stars
6.3k
Forks
836
PR merge metrics
No merged PRs in 30d

Description

If you're a pentester, you might audit companies regularly. You might come across vendors that aren't known by the `weboftrust` command, and aren't public. If a vendor doesn't publish their account ID, I've wanted to avoid including it in my public vendor account list. I'm not sure if that decision is necessary (happy to discuss), but assuming that decision stays, then the question is, what do you do for vendors you know about? You don't want to have a private fork of CloudMapper just for that. So we could potentially have a `private_vendor_accounts.yaml` file.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.