github-samples / github-samples/pets-workshop

GitHub security workshop: Add a deterministic CodeQL scanning lab

Đang mở
#271 1 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

priority: P2
Ngôn ngữ chính
Python
Star
80
Fork
161
Merge trung bình
31 phút
Pull request đã merge (30 ngày)
1

Mô tả

Goal

Teach learners how to enable code scanning and observe a real, intentionally introduced CodeQL finding in the pets application.

Scope

Add one safe training change that is detected reliably by a documented Python CodeQL query. The vulnerable path should be realistic enough to teach source-to-sink reasoning, but isolated from normal workshop startup and clearly marked as training-only. Provide a maintainer verification procedure so dependency or query-suite updates cannot silently break the exercise.

Acceptance criteria

  • The exercise explains default setup versus advanced setup and selects one tested path.
  • Learners enable CodeQL using current, capability-based instructions.
  • A training fixture or guided code change triggers a named CodeQL query deterministically.
  • The fixture contains no real secret, external side effect, or production deployment path.
  • Learners trigger analysis on a branch or pull request and can identify the resulting check.
  • The expected query ID, severity, file, and vulnerable data flow are documented for maintainers.
  • A repeatable validation step proves the expected alert appears.
  • Cleanup/reset instructions return the repository to a safe state.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Hướng nghiên cứu

Bắt đầu bằng cách xem xét ứng dụng pets và hướng dẫn thiết lập hiện có của workshop, sau đó so sánh các tùy chọn thiết lập mặc định và nâng cao của CodeQL. Xác định một fixture chỉ dùng cho đào tạo hoặc một thay đổi có hướng dẫn, đồng thời ghi lại truy vấn có tên, mức độ nghiêm trọng, tệp, luồng dữ liệu, trình kích hoạt branch hoặc pull request, bước xác thực và quy trình dọn dẹp. Hoàn tất khi cảnh báo xuất hiện một cách đáng tin cậy mà không có secrets, tác dụng phụ hoặc đường dẫn production.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
github, github-actions, python
Lĩnh vực
documentation, security
Loại issue
Tính năng
Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức độ hoạt động
Sôi nổi
Độ rõ ràng
Khá rõ ràng
Mức phù hợp với người mới
50/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.