Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

alice: threats: cicd: github: workflow: runs on: Check if self-hosted and building branches #1422

Open
8 tasks
pdxjohnny opened this issue Nov 21, 2022 · 0 comments
Labels
enhancement New feature or request

Comments

@pdxjohnny
Copy link
Member

pdxjohnny commented Nov 21, 2022

  • References
  • Last Friday pushed alice: threats: vulns: serve: nvdstyle: Fix serving of v2 style CVEs - 9f0a41a
    • We can now start serving threats!
  • TODO
    • alice threats cicd (-keys https://github.com/intel/dffml)
      • GitHub Actions workflow analysis overlays
        • Look for runs-on: and anything not GitHub hosted, then
          check on: triggers to ensure pull requests aren't being run.
      • Output to JSON source (so long as we derive from RunRecordSet we'll be done with this)\
      • Have NVDStyle server take source as input/config so that we can point it at the discovered vulns
  • Future
    • alice please log todos -source static=json dynamic=nvdstyle
      • Implement source for reading from NVDSytle API (op source for single function prototype?)
      • Enable creation of TODOs by overlaying operations which take the feature data as inputs (use dfpreprocess?)
@pdxjohnny pdxjohnny added the enhancement New feature or request label Nov 21, 2022
pdxjohnny added a commit to pdxjohnny/istio that referenced this issue Nov 21, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant