google / google/android-uiconductor

Security Policy violation Binary Artifacts

Offen
#116 215 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

allstar
Vorherrschende Sprache
Java
Sterne
127
Forks
24
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

This issue was automatically created by Allstar.

Security Policy Violation
Project is out of compliance with Binary Artifacts policy: binaries present in source code

Rule Description
Binary Artifacts are an increased security risk in your repository. Binary artifacts cannot be reviewed, allowing the introduction of possibly obsolete or maliciously subverted executables. For more information see the Security Scorecards Documentation for Binary Artifacts.

Remediation Steps
To remediate, remove the generated executable artifacts from the repository.

Artifacts Found

  • backend/commandline/target/classes/com/google/wireless/qa/uicd/backend/commandline/UicdCLI$1.class
  • backend/commandline/target/classes/com/google/wireless/qa/uicd/backend/commandline/UicdCLI.class
  • backend/commandline/target/classes/com/google/wireless/qa/uicd/backend/commandline/UicdCLIArgs.class
  • backend/commandline/target/commandline-0.1.0-jar-with-dependencies.jar
  • backend/commandline/target/commandline-0.1.0.jar
  • backend/input/uicd-plugins/tesseract/lib/liblept.so.5
  • backend/input/uicd-plugins/tesseract/lib/libtesseract.so.4
  • backend/input/uicd-plugins/tesseract/tesseract
  • prebuild/uicd-service-0.1.0.jar
  • prebuild/uicdcli/uicd-commandline.jar

Additional Information
This policy is drawn from Security Scorecards, which is a tool that scores a project's adherence to security best practices. You may wish to run a Scorecards scan directly on this repository for more details.


Allstar has been installed on all Google managed GitHub orgs. Policies are gradually being rolled out and enforced by the GOSST and OSPO teams. Learn more at http://go/allstar

This issue will auto resolve when the policy is in compliance.

Issue created by Allstar. See https://github.com/ossf/allstar/ for more information. For questions specific to the repository, please contact the owner or maintainer.

Beitragsleitfaden

Beitragsleitfaden öffnen

Erste Schritte

  1. Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
  3. Forke das Repository und arbeite in einem Branch.
  4. Öffne einen Pull Request, der die Issue-Nummer nennt.

Rechercherichtung

Überprüfe die aufgeführten Artefakte unter backend/commandline/target, backend/input/uicd-plugins/tesseract/lib, backend/input/uicd-plugins/tesseract und prebuild. Entferne die generierten Binärdateien aus der Versionsverwaltung und überprüfe den Repository-Status auf verbleibende Artefakte. Die Aufgabe ist abgeschlossen, wenn die Allstar Binary Artifacts-Richtlinie konform ist und sich der Issue automatisch schließt.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
java
Bereich
build-system, security
Issue-Typ
Bug
Schwierigkeit
2/5
Geschätzter Aufwand
1-3 Stunden
Aktivitätsstatus
Veraltet
Klarheit
Klar beschrieben
Anfängerfreundlichkeit
35/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.