github-samples / github-samples/pets-workshop
GitHub security workshop: Add a deterministic CodeQL scanning lab
Chưa có ai nhận issue này.
- Ngôn ngữ chính
- Python
- Star
- 80
- Fork
- 161
- Merge trung bình
- 31 phút
- Pull request đã merge (30 ngày)
- 1
Mô tả
Goal
Teach learners how to enable code scanning and observe a real, intentionally introduced CodeQL finding in the pets application.
Scope
Add one safe training change that is detected reliably by a documented Python CodeQL query. The vulnerable path should be realistic enough to teach source-to-sink reasoning, but isolated from normal workshop startup and clearly marked as training-only. Provide a maintainer verification procedure so dependency or query-suite updates cannot silently break the exercise.
Acceptance criteria
- The exercise explains default setup versus advanced setup and selects one tested path.
- Learners enable CodeQL using current, capability-based instructions.
- A training fixture or guided code change triggers a named CodeQL query deterministically.
- The fixture contains no real secret, external side effect, or production deployment path.
- Learners trigger analysis on a branch or pull request and can identify the resulting check.
- The expected query ID, severity, file, and vulnerable data flow are documented for maintainers.
- A repeatable validation step proves the expected alert appears.
- Cleanup/reset instructions return the repository to a safe state.
Hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Hướng nghiên cứu
Bắt đầu bằng cách xem xét ứng dụng pets và hướng dẫn thiết lập hiện có của workshop, sau đó so sánh các tùy chọn thiết lập mặc định và nâng cao của CodeQL. Xác định một fixture chỉ dùng cho đào tạo hoặc một thay đổi có hướng dẫn, đồng thời ghi lại truy vấn có tên, mức độ nghiêm trọng, tệp, luồng dữ liệu, trình kích hoạt branch hoặc pull request, bước xác thực và quy trình dọn dẹp. Hoàn tất khi cảnh báo xuất hiện một cách đáng tin cậy mà không có secrets, tác dụng phụ hoặc đường dẫn production.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- github, github-actions, python
- Lĩnh vực
- documentation, security
- Loại issue
- Tính năng
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức độ hoạt động
- Sôi nổi
- Độ rõ ràng
- Khá rõ ràng
- Mức phù hợp với người mới
- 50/100