salesforce / salesforce/cloudsplaining

Proposal: Implement Automated Logic Ingestion for IAM Privilege Escalation via Pathfinding.cloud

Open
#537 1 comment 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
JavaScript
Stars
2.2k
Forks
221
Avg merge
3h 21m
Merged PRs (30d)
8

Description

To automate the update frequency of Cloudsplaining's privilege escalation database and enhance its coverage, I propose creating a synchronization script that polls the Pathfinding repository for new YAML-defined paths and updates the constants.py file from Cloudsplaining.

I am willing to lead this task, but I still have some questions about this automation, and I am unsure how the script should be executed. Should it be executed manually or every time a new update is made to the Pathfinding repository? I also not sure how the new paths should be organized on cloudsplaining (I am thinking of just extending the PRIVILEGE_ESCALATION_METHODS dictionary).

I am open to suggestions and discussions on how to solve this task!

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with constants.py and the PRIVILEGE_ESCALATION_METHODS dictionary, then inspect the Pathfinding repository's YAML-defined paths. Define whether synchronization is manual or triggered by Pathfinding updates and how new paths are organized; done means Cloudsplaining's privilege-escalation data stays synchronized with the source.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
cloud, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.