Giter Site home page Giter Site logo

Comments (6)

jeffmendoza avatar jeffmendoza commented on September 24, 2024

@olivekl Can you take a look and share your thoughts? Thanks!

from allstar.

olivekl avatar olivekl commented on September 24, 2024

All minor stuff:

Security Policy Violation (capitalization for consistency with other headings)
For more information see the [Security Scorecards documentation] for Binary Artifacts. (full Scorecards name and the policy name)
'Artifacts Found(caps again)Binary Artifacts security policy has failed: binaries present in source code(change order for clarity)This issue was automatically created by Allstar.(period at end)which is a tool that scores a project's adherence to security best practices.` (reorder)

from allstar.

jeffmendoza avatar jeffmendoza commented on September 24, 2024

Updated:

This issue was automatically created by Allstar.

Security Policy Violation
Binary Artifacts security policy has failed: binaries present in source code

Rule Description
Binary Artifacts are an increased security risk in your repository. Binary artifacts cannot be reviewed, allowing the introduction of possibly obsolete or maliciously subverted executables. For more information see the Security Scorecards Documentation for Binary Artifacts.

Remediation Steps
To remediate, remove the generated executable artifacts from the repository.

Artifacts Found

  • dummy.dll
  • dummy.exe
  • dummy.jar
  • dummy.so

Additional Information
This policy is drawn from Security Scorecards, which is a tool that scores a project's adherence to security best practices. You may wish to run a Scorecards scan directly on this repository for more details.


Staging deploy of Allstar for testing, see https://github.com/ossf-tests/.allstar for config. (This is the custom footer)

This issue will auto resolve when the policy is in compliance. (This is current Allstar footer)

Issue created by Allstar. See https://github.com/ossf/allstar/ for more information. For questions specific to the repository, please contact the owner or maintainer.

from allstar.

olivekl avatar olivekl commented on September 24, 2024

Thanks, Jeff. I have one more thought now that I'm looking again with fresh eyes. What do you think of:

Project is out of compliance with Binary Artifacts policy: binaries present in source code (since a policy doesn't fail, and we changed "check" to "policy")

Too long?

from allstar.

jeffmendoza avatar jeffmendoza commented on September 24, 2024

Sounds good, so now:

This issue was automatically created by Allstar.

Security Policy Violation
Project is out of compliance with Binary Artifacts policy: binaries present in source code

Rule Description
Binary Artifacts are an increased security risk in your repository. Binary artifacts cannot be reviewed, allowing the introduction of possibly obsolete or maliciously subverted executables. For more information see the Security Scorecards Documentation for Binary Artifacts.

Remediation Steps
To remediate, remove the generated executable artifacts from the repository.

Artifacts Found

  • dummy.dll
  • dummy.exe
  • dummy.jar
  • dummy.so

Additional Information
This policy is drawn from Security Scorecards, which is a tool that scores a project's adherence to security best practices. You may wish to run a Scorecards scan directly on this repository for more details.


Staging deploy of Allstar for testing, see https://github.com/ossf-tests/.allstar for config. (This is the custom footer)

This issue will auto resolve when the policy is in compliance. (This is current Allstar footer)

Issue created by Allstar. See https://github.com/ossf/allstar/ for more information. For questions specific to the repository, please contact the owner or maintainer.

from allstar.

olivekl avatar olivekl commented on September 24, 2024

LGTM!

from allstar.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.