Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Feat/sonar demo #112

Open
wants to merge 58 commits into
base: master
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
58 commits
Select commit Hold shift + click to select a range
26547f0
first commit
erichusband Nov 28, 2019
c67b1ba
Remove node runtime agent to fix Dockerfile (#707)
MichaelAquilina Jan 30, 2020
30facfd
docs: add apache 2 license
lirantal Feb 2, 2020
b897ba4
chore(project): add license key in manifest file
lirantal Feb 2, 2020
aab037b
chore(project): correct license key name
lirantal Feb 2, 2020
9dabba3
chore(heroku): support heroku mongodb url (#720)
lirantal Feb 2, 2020
c20267a
chore(heroku): add instructions for deployment
lirantal Feb 2, 2020
a349cd0
policy
Feb 6, 2020
0bd4d3c
Revert "policy"
Feb 6, 2020
be9a290
feat: add prototype pollution exploit in typeorm (#784)
lirantal Aug 12, 2020
4ff67c0
chore: engines specification in package.json is outdated (#797)
FauxFaux Aug 27, 2020
9300e9a
chore: codeowners -> devrel
lirantal Sep 6, 2020
a2ec84d
docs: mongoose disclaimer about the specific Node.js version required
lirantal Feb 14, 2021
5a4f50e
fix: use an up-to-date version of the Node.js base image
lirantal Feb 14, 2021
c9d461e
chore: ignore ide files
lirantal Jun 2, 2021
6fa7510
feat: add open redirect and xss vulns in code (#960)
lirantal Jun 3, 2021
01c7957
feat: add code injection via template (#961)
lirantal Jun 9, 2021
79d4be7
feat: add cookie session for logged in state (#962)
lirantal Jun 9, 2021
9205051
fix: package lockfile update
lirantal Jun 9, 2021
744ecb2
fix: only logged in users can save account details
lirantal Jun 9, 2021
30b3c78
fix: use correct controller function name for route
lirantal Jun 15, 2021
a6a04d7
feat: add nodemon to reload changes easily
lirantal Jun 15, 2021
4c2d076
feat: add a false positive case
lirantal Jun 15, 2021
f0012a5
feat: ignore just a single line from snyk code
lirantal Jun 15, 2021
f5d685f
fix: update README for NoSQL injection vector
lirantal Jun 18, 2021
07fd4b3
fix: updated exploit payload for code injections
lirantal Jun 21, 2021
0e11662
Update README.md
bmvermeer Jun 23, 2021
6386cc1
sarif: testing scanning flow with sarif file
ArturSnyk Jul 18, 2021
94c93d7
Merge pull request #9 from ArturSnyk/sarif/checking_scanning_flow
ArturSnyk Jul 18, 2021
3837e22
sarif: testing scanning flow with sarif file
ArturSnyk Jul 18, 2021
6048009
Update sarif.json
ArturSnyk Jul 18, 2021
73d09dc
Create snyk-test-sarif.yml
ArturSnyk Jul 18, 2021
c0ad7b4
Create snyk-test-sarif.yml
ArturSnyk Jul 18, 2021
12407f6
Create codeql-analysis.yml
ArturSnyk Jul 19, 2021
3f38d63
Merge pull request #10 from ArturSnyk/sarif/testing1
ArturSnyk Jul 19, 2021
64fa1b0
Merge pull request #12 from ArturSnyk/testing1
ArturSnyk Jul 19, 2021
a5545dc
sarif: testing of workflows
ArturSnyk Jul 19, 2021
8f5a5cc
mend
ArturSnyk Jul 19, 2021
e2f1828
mend
ArturSnyk Jul 19, 2021
015a7e9
mend
ArturSnyk Jul 19, 2021
b3ddff5
Merge pull request #13 from ArturSnyk/sarif/testing-diff-flows
ArturSnyk Jul 19, 2021
d729023
sarif: test on merge
ArturSnyk Jul 19, 2021
02af3cf
Merge pull request #14 from ArturSnyk/sarif/test-on-merge
ArturSnyk Jul 19, 2021
11a22e2
Update sarif.json
ArturSnyk Aug 5, 2021
0645e45
Merge pull request #17 from ArturSnyk/ArturSnyk-sarif-fix
ArturSnyk Aug 5, 2021
0336589
Merge branch 'master' into master
ArturSnyk Aug 22, 2021
a2d0d99
Update README.md (#1236)
developersteve Apr 20, 2022
b322174
fix: M1 compatibility for mysql (#1169)
sebsnyk Jun 22, 2022
f985f27
Update README.md
clarkio Jul 12, 2022
0b2d0b4
Refactor CSS with Flexbox
SonyaMoisset Jul 11, 2022
1829b4c
chore: manifest file sync
lirantal Nov 8, 2022
83e5cb5
fix: support for Node.js 17 and 18's openssl3 updates
lirantal Nov 10, 2022
146d69a
fix: force mongodb version compat with the project (#1294)
lirantal Jan 19, 2023
b00e701
docs: update README for MongoDB server version compat (#1293)
lirantal Jan 19, 2023
a393a6c
fix: use the latest LTS so we can pass some new command line options …
lirantal Jan 19, 2023
d240896
Update deprecated checkout and upload-sarif actions (#1318)
ericsmalling May 24, 2023
91cfc5d
added duplicate code for sonar test
pstember Jul 19, 2024
bf42248
Merge branch 'main' into feat/sonar-demo
pstember Jul 19, 2024
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
* @snyk/devrel
71 changes: 71 additions & 0 deletions .github/workflows/codeql-analysis.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,71 @@
# For most projects, this workflow file will not need changing; you simply need
# to commit it to your repository.
#
# You may wish to alter this file to override the set of languages analyzed,
# or to provide custom queries or build logic.
#
# ******** NOTE ********
# We have attempted to detect the languages in your repository. Please check
# the `language` matrix defined below to confirm you have the correct set of
# supported CodeQL languages.
#
name: "CodeQL"

on:
push:
branches: [ master ]
pull_request:
# The branches below must be a subset of the branches above
branches: [ master ]
schedule:
- cron: '32 19 * * 4'

jobs:
analyze:
name: Analyze
runs-on: ubuntu-latest
permissions:
actions: read
contents: read
security-events: write

strategy:
fail-fast: false
matrix:
language: [ 'javascript' ]
# CodeQL supports [ 'cpp', 'csharp', 'go', 'java', 'javascript', 'python' ]
# Learn more:
# https://docs.github.com/en/free-pro-team@latest/github/finding-security-vulnerabilities-and-errors-in-your-code/configuring-code-scanning#changing-the-languages-that-are-analyzed

steps:
- name: Checkout repository
uses: actions/checkout@v3

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@v1
with:
languages: ${{ matrix.language }}
# If you wish to specify custom queries, you can do so here or in a config file.
# By default, queries listed here will override any specified in a config file.
# Prefix the list here with "+" to use these queries and those in the config file.
# queries: ./path/to/local/query, your-org/your-repo/queries@main

# Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
# If this step fails, then you should remove it and run the build manually (see below)
- name: Autobuild
uses: github/codeql-action/autobuild@v1

# ℹ️ Command-line programs to run using the OS shell.
# 📚 https://git.io/JvXDl

# ✏️ If the Autobuild fails above, remove it and uncomment the following three lines
# and modify them (or add more) to build your code if your project
# uses a compiled language

#- run: |
# make bootstrap
# make release

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v1
16 changes: 16 additions & 0 deletions .github/workflows/snyk-code-manual.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
name: "snyk code manual test"
on: [push, pull_request]

jobs:
build:
name: sarif testing action
runs-on: ubuntu-latest
permissions:
security-events: write
steps:
- uses: actions/checkout@v3
- name: Upload SARIF
uses: github/codeql-action/upload-sarif@v2
with:
sarif_file: sarif.json
# sarif_file: example111.json
17 changes: 17 additions & 0 deletions .github/workflows/snyk-code.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
name: "snyk code test"
on: [push, pull_request]
jobs:
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: snyk/actions/setup@master
- name: Snyk Test
run: snyk code test --org=${{ secrets.SNYK_ORG }} --sarif > snyk-sarif2.json
continue-on-error: true
env:
SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
- name: Upload SARIF file
uses: github/codeql-action/upload-sarif@v2
with:
sarif_file: snyk-sarif2.json
17 changes: 17 additions & 0 deletions .github/workflows/snyk-test-sarif.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
name: "snyk test"
on: [push, pull_request]
jobs:
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: snyk/actions/setup@master
- name: Snyk Test
run: snyk test --sarif-file-output=snyk-sarif1.json
continue-on-error: true
env:
SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
- name: Upload SARIF file
uses: github/codeql-action/upload-sarif@v2
with:
sarif_file: snyk-sarif1.json
6 changes: 6 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -6,3 +6,9 @@ node_modules
sass
config.rb
npm-debug.log

.dccache
.dcignore
.idea/
.dccache

2 changes: 1 addition & 1 deletion Dockerfile
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
FROM node:8-slim
FROM node:18.13.0

RUN mkdir /usr/src/goof
RUN mkdir /tmp/extracted_files
Expand Down
201 changes: 201 additions & 0 deletions LICENSE
Original file line number Diff line number Diff line change
@@ -0,0 +1,201 @@
Apache License
Version 2.0, January 2004
http://www.apache.org/licenses/

TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION

1. Definitions.

"License" shall mean the terms and conditions for use, reproduction,
and distribution as defined by Sections 1 through 9 of this document.

"Licensor" shall mean the copyright owner or entity authorized by
the copyright owner that is granting the License.

"Legal Entity" shall mean the union of the acting entity and all
other entities that control, are controlled by, or are under common
control with that entity. For the purposes of this definition,
"control" means (i) the power, direct or indirect, to cause the
direction or management of such entity, whether by contract or
otherwise, or (ii) ownership of fifty percent (50%) or more of the
outstanding shares, or (iii) beneficial ownership of such entity.

"You" (or "Your") shall mean an individual or Legal Entity
exercising permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation
source, and configuration files.

"Object" form shall mean any form resulting from mechanical
transformation or translation of a Source form, including but
not limited to compiled object code, generated documentation,
and conversions to other media types.

"Work" shall mean the work of authorship, whether in Source or
Object form, made available under the License, as indicated by a
copyright notice that is included in or attached to the work
(an example is provided in the Appendix below).

"Derivative Works" shall mean any work, whether in Source or Object
form, that is based on (or derived from) the Work and for which the
editorial revisions, annotations, elaborations, or other modifications
represent, as a whole, an original work of authorship. For the purposes
of this License, Derivative Works shall not include works that remain
separable from, or merely link (or bind by name) to the interfaces of,
the Work and Derivative Works thereof.

"Contribution" shall mean any work of authorship, including
the original version of the Work and any modifications or additions
to that Work or Derivative Works thereof, that is intentionally
submitted to Licensor for inclusion in the Work by the copyright owner
or by an individual or Legal Entity authorized to submit on behalf of
the copyright owner. For the purposes of this definition, "submitted"
means any form of electronic, verbal, or written communication sent
to the Licensor or its representatives, including but not limited to
communication on electronic mailing lists, source code control systems,
and issue tracking systems that are managed by, or on behalf of, the
Licensor for the purpose of discussing and improving the Work, but
excluding communication that is conspicuously marked or otherwise
designated in writing by the copyright owner as "Not a Contribution."

"Contributor" shall mean Licensor and any individual or Legal Entity
on behalf of whom a Contribution has been received by Licensor and
subsequently incorporated within the Work.

2. Grant of Copyright License. Subject to the terms and conditions of
this License, each Contributor hereby grants to You a perpetual,
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
copyright license to reproduce, prepare Derivative Works of,
publicly display, publicly perform, sublicense, and distribute the
Work and such Derivative Works in Source or Object form.

3. Grant of Patent License. Subject to the terms and conditions of
this License, each Contributor hereby grants to You a perpetual,
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
(except as stated in this section) patent license to make, have made,
use, offer to sell, sell, import, and otherwise transfer the Work,
where such license applies only to those patent claims licensable
by such Contributor that are necessarily infringed by their
Contribution(s) alone or by combination of their Contribution(s)
with the Work to which such Contribution(s) was submitted. If You
institute patent litigation against any entity (including a
cross-claim or counterclaim in a lawsuit) alleging that the Work
or a Contribution incorporated within the Work constitutes direct
or contributory patent infringement, then any patent licenses
granted to You under this License for that Work shall terminate
as of the date such litigation is filed.

4. Redistribution. You may reproduce and distribute copies of the
Work or Derivative Works thereof in any medium, with or without
modifications, and in Source or Object form, provided that You
meet the following conditions:

(a) You must give any other recipients of the Work or
Derivative Works a copy of this License; and

(b) You must cause any modified files to carry prominent notices
stating that You changed the files; and

(c) You must retain, in the Source form of any Derivative Works
that You distribute, all copyright, patent, trademark, and
attribution notices from the Source form of the Work,
excluding those notices that do not pertain to any part of
the Derivative Works; and

(d) If the Work includes a "NOTICE" text file as part of its
distribution, then any Derivative Works that You distribute must
include a readable copy of the attribution notices contained
within such NOTICE file, excluding those notices that do not
pertain to any part of the Derivative Works, in at least one
of the following places: within a NOTICE text file distributed
as part of the Derivative Works; within the Source form or
documentation, if provided along with the Derivative Works; or,
within a display generated by the Derivative Works, if and
wherever such third-party notices normally appear. The contents
of the NOTICE file are for informational purposes only and
do not modify the License. You may add Your own attribution
notices within Derivative Works that You distribute, alongside
or as an addendum to the NOTICE text from the Work, provided
that such additional attribution notices cannot be construed
as modifying the License.

You may add Your own copyright statement to Your modifications and
may provide additional or different license terms and conditions
for use, reproduction, or distribution of Your modifications, or
for any such Derivative Works as a whole, provided Your use,
reproduction, and distribution of the Work otherwise complies with
the conditions stated in this License.

5. Submission of Contributions. Unless You explicitly state otherwise,
any Contribution intentionally submitted for inclusion in the Work
by You to the Licensor shall be under the terms and conditions of
this License, without any additional terms or conditions.
Notwithstanding the above, nothing herein shall supersede or modify
the terms of any separate license agreement you may have executed
with Licensor regarding such Contributions.

6. Trademarks. This License does not grant permission to use the trade
names, trademarks, service marks, or product names of the Licensor,
except as required for reasonable and customary use in describing the
origin of the Work and reproducing the content of the NOTICE file.

7. Disclaimer of Warranty. Unless required by applicable law or
agreed to in writing, Licensor provides the Work (and each
Contributor provides its Contributions) on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
implied, including, without limitation, any warranties or conditions
of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
PARTICULAR PURPOSE. You are solely responsible for determining the
appropriateness of using or redistributing the Work and assume any
risks associated with Your exercise of permissions under this License.

8. Limitation of Liability. In no event and under no legal theory,
whether in tort (including negligence), contract, or otherwise,
unless required by applicable law (such as deliberate and grossly
negligent acts) or agreed to in writing, shall any Contributor be
liable to You for damages, including any direct, indirect, special,
incidental, or consequential damages of any character arising as a
result of this License or out of the use or inability to use the
Work (including but not limited to damages for loss of goodwill,
work stoppage, computer failure or malfunction, or any and all
other commercial damages or losses), even if such Contributor
has been advised of the possibility of such damages.

9. Accepting Warranty or Additional Liability. While redistributing
the Work or Derivative Works thereof, You may choose to offer,
and charge a fee for, acceptance of support, warranty, indemnity,
or other liability obligations and/or rights consistent with this
License. However, in accepting such obligations, You may act only
on Your own behalf and on Your sole responsibility, not on behalf
of any other Contributor, and only if You agree to indemnify,
defend, and hold each Contributor harmless for any liability
incurred by, or claims asserted against, such Contributor by reason
of your accepting any such warranty or additional liability.

END OF TERMS AND CONDITIONS

APPENDIX: How to apply the Apache License to your work.

To apply the Apache License to your work, attach the following
boilerplate notice, with the fields enclosed by brackets "[]"
replaced with your own identifying information. (Don't include
the brackets!) The text should be enclosed in the appropriate
comment syntax for the file format. We also recommend that a
file or class name and description of purpose be included on the
same "printed page" as the copyright notice for easier
identification within third-party archives.

Copyright [yyyy] [name of copyright owner]

Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
Loading
Loading