Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

db backup restore threat #565

Merged
merged 8 commits into from
Nov 27, 2024
Merged

db backup restore threat #565

merged 8 commits into from
Nov 27, 2024

Conversation

ianwalkersmithciticom
Copy link
Contributor

It is possible for a threat actor to write backup over a database, thereby overwriting the db with restored copy.

@ianwalkersmithciticom ianwalkersmithciticom requested a review from a team as a code owner November 26, 2024 14:15
@eddie-knight
Copy link
Contributor

@sshiells-scottlogic @dogle-scottlogic @damienjburks — Who can bring the link checker into a good state? Looks like it needs to be disabled or a standalone PR created to resolve the findings

@damienjburks
Copy link
Contributor

@eddie-knight i got you. Working on it now. Will be resolved in the next 30

@damienjburks
Copy link
Contributor

@sshiells-scottlogic was able to update it before me. We should be good to move forward @eddie-knight

@sshiells-scottlogic
Copy link
Contributor

@eddie-knight we pushed a quick fix for now that should unblock this.

Will look for a proper fix asap

@sshiells-scottlogic
Copy link
Contributor

@damienjburks @eddie-knight a better fix is available #568

@damienjburks
Copy link
Contributor

@ianwalkersmithciticom please fix your yaml-lint checks.

@eddie-knight
Copy link
Contributor

Checks are good, now just needs approval from @finos/ccc-wg-security

@mlysaght2017 mlysaght2017 merged commit cfaf224 into main Nov 27, 2024
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants