duo-labs / duo-labs/cloudmapper
Have private account list for weboftrust
- Dominant language
- JavaScript
- Stars
- 6.3k
- Forks
- 836
- PR merge metrics
- No merged PRs in 30d
Description
If you're a pentester, you might audit companies regularly. You might come across vendors that aren't known by the `weboftrust` command, and aren't public. If a vendor doesn't publish their account ID, I've wanted to avoid including it in my public vendor account list. I'm not sure if that decision is necessary (happy to discuss), but assuming that decision stays, then the question is, what do you do for vendors you know about? You don't want to have a private fork of CloudMapper just for that. So we could potentially have a `private_vendor_accounts.yaml` file.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.