Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

write and publish detection rules for open source tools in a separate repo #329

Closed
5 tasks
commjoen opened this issue Jun 29, 2022 · 7 comments
Closed
5 tasks
Labels
hacktoberfest help wanted Extra attention is needed

Comments

@commjoen
Copy link
Collaborator

commjoen commented Jun 29, 2022

  • get a repo organized with github actions, etc..
  • pick up the first secret from the testbed (create a secrets detection testbed branch with revoked credentials #201) to write rules/config for for both tools. best would be to take one you are very familiar with from the list in that issue (e.g. you can smell/recognize the credential for miles away 😄 )
  • setup a test suite to see if the tool(git-secrets/trufflehog/detect-secrets) using the rule detects exactly that and not too much (e.g. very low false positive ratio)
  • make sure we have a github action to fire the rule suite, linters, etc.
  • rinse and repeat for other secrets in testbed (e.g. create rules and detection tests, with possible separate issues in another git repo)
@commjoen
Copy link
Collaborator Author

commjoen commented Jul 1, 2022

this could be for https://github.com/Yelp/detect-secrets as well aaaand we might need base64 encoded/ hex encoding stuff as well?

@mackowski
Copy link

I will help with that

@mack-droid
Copy link

I am in for contribution.

@su-muskan
Copy link

I am up for the task

@commjoen
Copy link
Collaborator Author

commjoen commented Jul 8, 2022

Awesome! Assigned it to all 3 of you :) welcome to the team!

@commjoen
Copy link
Collaborator Author

commjoen commented Jul 8, 2022

Decisions to be tackled:

  • one tool (if so which?) versus all 3 tools in scope of this issue
  • any other tool to extend?
  • repos: commjoen, wrongsecrets-orga, owasp (prefered wrongsecrets-orga for now)

@commjoen commjoen added the help wanted Extra attention is needed label Feb 13, 2023
@commjoen
Copy link
Collaborator Author

Given nothign really came out of this, I am closing this issue and generating a new one with fresh assisgnment slot and hacktoberfest possibility.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
hacktoberfest help wanted Extra attention is needed
Projects
Status: Done
Development

No branches or pull requests

4 participants