Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
514 commits
Select commit Hold shift + click to select a range
62fb716
Lab40: Update header scanning
Rinorragi Feb 14, 2025
c118190
Lab40: Update header scanning
Rinorragi Feb 14, 2025
d454649
Add note to avoid scancode action (#10)
Rinorragi Feb 14, 2025
1e5142f
Lab40: readme update
Rinorragi Feb 14, 2025
86d8960
Lab42: Update timeouts for dast scans
Rinorragi Feb 14, 2025
2101046
ruleset docs (#12)
Rinorragi Feb 14, 2025
c6ea8ba
Merge pull request #14 from Rinorragi/feature/lab42update
Rinorragi Feb 14, 2025
215f841
Merge pull request #11 from Rinorragi/feature/header-scanning
Rinorragi Feb 14, 2025
ca3c032
Lab21: Fix readme
Rinorragi Feb 14, 2025
cfcebf8
ruleset docs
Rinorragi Feb 14, 2025
5bc3840
Initial commit
Rinorragi Feb 14, 2025
7a4acc4
Add urls to code and slides
Rinorragi Feb 14, 2025
6e23ac2
Update readmes
Rinorragi Feb 14, 2025
81b0d27
Add structure for labs
Rinorragi Feb 14, 2025
7b88da5
Move labs under the labs folder
Rinorragi Feb 14, 2025
091575c
init lab01
Rinorragi Feb 14, 2025
5f0b1f6
init lab01
Rinorragi Feb 14, 2025
7f3af66
init lab01
Rinorragi Feb 14, 2025
191392e
test protection
Rinorragi Feb 14, 2025
48986f8
init lab02
Rinorragi Feb 14, 2025
fd8ef2c
init lab02
Rinorragi Feb 14, 2025
ad894e1
init lab02
Rinorragi Feb 14, 2025
f91cb4b
Update readme with lab links
Rinorragi Feb 14, 2025
1ae44cf
Add gitignore
Rinorragi Feb 14, 2025
77ce3e7
Update readme for lab1
Rinorragi Feb 14, 2025
7e8dbb0
Add VS Code configs
Rinorragi Feb 14, 2025
d89b83a
Add dotnet build to lab01 solution
Rinorragi Feb 14, 2025
c5d53c6
Add the dotnet app to build
Rinorragi Feb 14, 2025
98e6c85
Add comments for the lab01 workflow
Rinorragi Feb 14, 2025
a5eef2a
Add .NET native way to test for vulnerabilities
Rinorragi Feb 14, 2025
a8644be
Add .NET native way to test for vulnerabilities
Rinorragi Feb 14, 2025
74c06bd
Add .NET native way to test for vulnerabilities
Rinorragi Feb 14, 2025
862e324
Add .NET native way to test for vulnerabilities
Rinorragi Feb 14, 2025
7fdff78
Add .NET native way to test for vulnerabilities
Rinorragi Feb 14, 2025
8e8705f
Add .NET native way to test for vulnerabilities
Rinorragi Feb 14, 2025
7638773
Add .NET native way to test for vulnerabilities
Rinorragi Feb 14, 2025
4643943
Add .NET native way to test for vulnerabilities
Rinorragi Feb 14, 2025
8123ea5
Add OWASP Dependency Check
Rinorragi Feb 14, 2025
45390db
Add OWASP Dependency Check
Rinorragi Feb 14, 2025
8e47fda
Add RetireJS
Rinorragi Feb 14, 2025
a6ed6ba
Add RetireJS
Rinorragi Feb 14, 2025
c23b3af
Add RetireJS
Rinorragi Feb 14, 2025
8eac087
Add RetireJS
Rinorragi Feb 14, 2025
b965c35
Add RetireJS
Rinorragi Feb 14, 2025
63bc3aa
Add RetireJS
Rinorragi Feb 14, 2025
93d8c89
Update lab01 link references
Rinorragi Feb 14, 2025
807bcb2
Update Lab03 exercise statement and solution links
Rinorragi Feb 14, 2025
8874804
Update Lab03 exercise statement and solution links
Rinorragi Feb 14, 2025
b54df92
Add lab04
Rinorragi Feb 14, 2025
a8fe35a
Add lab04
Rinorragi Feb 14, 2025
d2c831d
Remove unneccessary comments
Rinorragi Feb 14, 2025
eaeabc5
Add lab05
Rinorragi Feb 14, 2025
a6f654e
Add lab05
Rinorragi Feb 14, 2025
0b9ef17
Add lab05
Rinorragi Feb 14, 2025
c32b31b
Add lab05
Rinorragi Feb 14, 2025
984b785
Add lab05
Rinorragi Feb 14, 2025
9f4be9d
Add lab05
Rinorragi Feb 14, 2025
0f604d2
Add lab05
Rinorragi Feb 14, 2025
bd69826
Add lab05
Rinorragi Feb 14, 2025
310aa91
Add lab05
Rinorragi Feb 14, 2025
6e1b5ff
Add lab05
Rinorragi Feb 14, 2025
a1717ca
Add lab05
Rinorragi Feb 14, 2025
adab5d1
Add lab05
Rinorragi Feb 14, 2025
f8f8d46
Add lab05
Rinorragi Feb 14, 2025
a71e127
Add lab05
Rinorragi Feb 14, 2025
f02d71e
Add lab05
Rinorragi Feb 14, 2025
50eba01
Add lab05
Rinorragi Feb 14, 2025
ad41aa2
Add lab05
Rinorragi Feb 14, 2025
e35633c
Update readme about apps
Rinorragi Feb 14, 2025
341d540
Update readme about purpose
Rinorragi Feb 14, 2025
a32bf97
Lab05 - upload scancode test results
Rinorragi Feb 14, 2025
14b51cf
Lab05 - upload scancode test results
Rinorragi Feb 14, 2025
d3c0e1c
Remove accidental licenses.json
Rinorragi Feb 14, 2025
499f9a8
Reduce amount of data in scancode
Rinorragi Feb 14, 2025
51e1bb6
Add build failure for scancode too
Rinorragi Feb 14, 2025
076a4fe
Remove unneccessary file
Rinorragi Feb 14, 2025
8249378
Lab02 - Add something for workflow
Rinorragi Feb 14, 2025
4d3f14f
Lab02 - Add something for workflow
Rinorragi Feb 14, 2025
dccaa89
Lab02 - Add something for workflow
Rinorragi Feb 14, 2025
cf8a500
Lab02 - Add something for workflow
Rinorragi Feb 14, 2025
12bc88e
Lab02 - Add github token for auth
Rinorragi Feb 14, 2025
75cdf86
Lab05 - Fix script path
Rinorragi Feb 14, 2025
99928b2
Lab02 - Fix graphql query
Rinorragi Feb 14, 2025
e2a72f0
Lab02 - Rights for ci-pipeline
Rinorragi Feb 14, 2025
7472aa2
Lab02 - Rights for ci-pipeline
Rinorragi Feb 14, 2025
9ea670e
Lab02 - change graphql
Rinorragi Feb 14, 2025
1d08545
Lab02 - change graphql
Rinorragi Feb 14, 2025
45d9342
Lab02 - Update links
Rinorragi Feb 14, 2025
d038cb1
Lab06 - first test
Rinorragi Feb 14, 2025
cf865c8
Lab02 - Update links
Rinorragi Feb 14, 2025
ab9cf01
Lab06 - GHAS first attempt
Rinorragi Feb 14, 2025
1fe855d
Lab06 - Example solutions to lab links
Rinorragi Feb 14, 2025
d0e166a
Lab07 - init
Rinorragi Feb 14, 2025
0c533e8
Lab03 - dependabot and dependency review
Rinorragi Feb 14, 2025
1e19490
Lab08 - IaC scanning
Rinorragi Feb 14, 2025
65b7b00
Fix checkov finding about top-level permissions
Rinorragi Feb 14, 2025
b6a9a7c
Lab08 - HTTP scanning
Rinorragi Feb 14, 2025
f4f87c7
Lab09 - HTTP scanning
Rinorragi Feb 14, 2025
7804ab5
Lab10 - TLS scanning
Rinorragi Feb 14, 2025
e56804d
Lab10 - TLS scanning
Rinorragi Feb 14, 2025
ff1d347
Lab10 - TLS scanning
Rinorragi Feb 14, 2025
fdf0407
Lab10 - TLS scanning
Rinorragi Feb 14, 2025
e855ac3
Lab10 - TLS scanning
Rinorragi Feb 14, 2025
a922ba7
Lab10 - TLS scanning
Rinorragi Feb 14, 2025
4c908d2
lab10 - readme
Rinorragi Feb 14, 2025
0943d53
Update readme to also have link to lab10
Rinorragi Feb 14, 2025
a48cdf3
Update readme to also have link to lab10
Rinorragi Feb 14, 2025
8e53363
Readme updates
Rinorragi Feb 14, 2025
74d21b8
short pipeline intro
Rinorragi Feb 14, 2025
f130481
Merge pull request #2 from Rinorragi/feat/ph
Rinorragi Feb 14, 2025
2fc2e90
lab11 - is awesome
Rinorragi Feb 14, 2025
4fe06a0
Add lab11 to readme
Rinorragi Feb 14, 2025
fc3c51c
Update lab11 readme
Rinorragi Feb 14, 2025
ecf7e0e
Update scan targets to huuhkanet
Rinorragi Feb 14, 2025
8a13021
Update upload-sarif version
Rinorragi Feb 14, 2025
d397d56
Update sarif
Rinorragi Feb 14, 2025
09d3fae
Update rules to sarif format
Rinorragi Feb 14, 2025
6b6cb13
Update rules to sarif format
Rinorragi Feb 14, 2025
eca444f
Update rules to sarif format
Rinorragi Feb 14, 2025
d98b208
Update rules to sarif format
Rinorragi Feb 14, 2025
c927313
Update rules to sarif format
Rinorragi Feb 14, 2025
a1fa294
Update rules to sarif format
Rinorragi Feb 14, 2025
05c1b42
Update rules to sarif format
Rinorragi Feb 14, 2025
6cc52db
Update rules to sarif format
Rinorragi Feb 14, 2025
c8e053a
Check checkov output
Rinorragi Feb 14, 2025
ff884b3
Update rules to sarif format
Rinorragi Feb 14, 2025
9290cf0
Add vulnerable pipeline for checkov
Rinorragi Feb 14, 2025
58b17f1
Update rules to sarif format
Rinorragi Feb 14, 2025
20b0da1
Remove checkov sarif upload
Rinorragi Feb 14, 2025
e192f0c
Update rules to sarif format
Rinorragi Feb 14, 2025
5fdbca5
Update rules to sarif format
Rinorragi Feb 14, 2025
f5e6097
Update rules to sarif format
Rinorragi Feb 14, 2025
f84ffa6
Update rules to sarif format
Rinorragi Feb 14, 2025
54081c9
Update rules to sarif format
Rinorragi Feb 14, 2025
c2b1318
Update rules to sarif format
Rinorragi Feb 14, 2025
1973438
Update rules to sarif format
Rinorragi Feb 14, 2025
ea7a9bd
Add terraform files for checkov scans (#3)
Rinorragi Feb 14, 2025
7fd1c1f
Lab11 - Remove unneccessary debug
Rinorragi Feb 14, 2025
19194b7
Lab12: ZAP DAST
Rinorragi Feb 14, 2025
3d08d70
Lab12: Update github output to powershell style
Rinorragi Feb 14, 2025
79bb2df
Lab12: Fix ambiguous docker parameter
Rinorragi Feb 14, 2025
dfb3f35
Lab12: Fix lining
Rinorragi Feb 14, 2025
50c4261
Lab12: Fix Dockerfile location
Rinorragi Feb 14, 2025
dd15d31
Lab12: Try ZAP with docker instead of action
Rinorragi Feb 14, 2025
77d4fe3
Lab12: Try ZAP with docker instead of action
Rinorragi Feb 14, 2025
86232af
Lab12: Try ZAP with docker instead of action
Rinorragi Feb 14, 2025
7bfb001
Lab12: Try ZAP with docker instead of action
Rinorragi Feb 14, 2025
5f8312c
Lab12: Try ZAP with docker instead of action
Rinorragi Feb 14, 2025
9d4b64f
Lab12: Try ZAP with docker instead of action
Rinorragi Feb 14, 2025
3234f17
Lab12: Try ZAP with docker instead of action
Rinorragi Feb 14, 2025
4958fe2
Lab12: Try ZAP with docker instead of action
Rinorragi Feb 14, 2025
9ecc234
Lab13 - generate sboms
Rinorragi Feb 14, 2025
e68bcd0
Lab13 - generate sboms
Rinorragi Feb 14, 2025
8f46bc1
Lab13 - generate sboms
Rinorragi Feb 14, 2025
132ccd6
Lab13 - generate sboms
Rinorragi Feb 14, 2025
7eaf965
Lab13 - generate sboms
Rinorragi Feb 14, 2025
2af7e87
Lab13 - generate sboms
Rinorragi Feb 14, 2025
77e5c50
Lab13 - generate sboms
Rinorragi Feb 14, 2025
f13a750
Lab13 - generate sboms
Rinorragi Feb 14, 2025
58dcaa8
Lab13 - generate sboms
Rinorragi Feb 14, 2025
b46f4cc
Lab13 - Remove unneccessary report files from version control
Rinorragi Feb 14, 2025
5094585
Labs 1-7: Readme table
Rinorragi Feb 14, 2025
b517234
Lab 8: Readme table
Rinorragi Feb 14, 2025
bed0395
Lab 9-13: Readme table
Rinorragi Feb 14, 2025
6266512
Rename vulnerable pipelines job so it is not overlapping with lab1
Rinorragi Feb 14, 2025
b3c43ba
Update lab12-14 readmes
Rinorragi Feb 14, 2025
5e629c0
Update main readme
Rinorragi Feb 14, 2025
69de281
Update main readme
Rinorragi Feb 14, 2025
f8a5156
Lab14: CRLF and LF warnings for the lab
Rinorragi Feb 14, 2025
562d311
Lab12: Nuclei
Rinorragi Feb 14, 2025
5e266fa
Lab12: ffuf
Rinorragi Feb 14, 2025
49145bb
Lab12: ffuf
Rinorragi Feb 14, 2025
c2ae0d3
Lab12: ffuf
Rinorragi Feb 14, 2025
893606f
Lab12: ffuf
Rinorragi Feb 14, 2025
be53918
Update readme
Rinorragi Feb 14, 2025
cc54bb8
Add file to vulnerable app
Rinorragi Feb 14, 2025
f3f7f03
Add file to vulnerable app
Rinorragi Feb 14, 2025
c868157
Update lab12 links
Rinorragi Feb 14, 2025
0d09423
Refactor: Group labs
Rinorragi Feb 14, 2025
e86423d
Add lab53 placeholder
Rinorragi Feb 14, 2025
0b43735
Update labs with TODOs
Rinorragi Feb 14, 2025
0345cde
Update labs with TODOs
Rinorragi Feb 14, 2025
032f499
Leave only stubs of pipelines to main
Rinorragi Feb 14, 2025
7e7acd8
Update references to solutions to point into examples branch
Rinorragi Feb 14, 2025
1acc169
Update workflow stubs to have workflow_dispatch
Rinorragi Feb 14, 2025
4638454
Remove scripts
Rinorragi Feb 14, 2025
ac7d2e1
Remove lab10 todos
Rinorragi Feb 14, 2025
23a69a4
Lab30: Move infrastructure files to better place
Rinorragi Feb 14, 2025
4f07425
lab00: Update readme
Rinorragi Feb 14, 2025
ce00355
lab21: actual vulns for the app
Rinorragi Feb 14, 2025
41fe9c8
lab21: Add rce
Rinorragi Feb 14, 2025
8d128d1
Save editorconfig
Rinorragi Feb 14, 2025
104a9ba
lab21: remove unneccessary comment
Rinorragi Feb 14, 2025
f32bac6
lab21: Remove todos
Rinorragi Feb 14, 2025
4a4318e
Update vulnerable app pipeline
Rinorragi Feb 14, 2025
94c6062
Update vulnerable app pipeline
Rinorragi Feb 14, 2025
4802116
Update vulnerable app pipeline
Rinorragi Feb 14, 2025
a82e621
Update vulnerable app pipeline
Rinorragi Feb 14, 2025
2833c14
Update vulnerable app pipeline
Rinorragi Feb 14, 2025
c4b424e
Update vulnerable app pipeline
Rinorragi Feb 14, 2025
517be67
Update vulnerable app pipeline
Rinorragi Feb 14, 2025
d4e166e
Update vulnerable app pipeline
Rinorragi Feb 14, 2025
b896539
Lab41 and Lab42 Update readme
Rinorragi Feb 14, 2025
37a23ad
Calling templates
Rinorragi Feb 14, 2025
c8050fa
artifact
Rinorragi Feb 14, 2025
aa772af
lab02 text
Rinorragi Feb 14, 2025
c598df6
Create lab01-calling-templates.yml
Rinorragi Feb 14, 2025
dd24dc9
Update and rename lab01-calling-templates.yml to lab01-variables-and-…
Rinorragi Feb 14, 2025
35b3643
Create lab02-reuse-and-artifacts
Rinorragi Feb 14, 2025
1540357
Rename lab02-reuse-and-artifacts to lab02-reuse-and-artifacts.yml
Rinorragi Feb 14, 2025
c712ab2
Merge pull request #6 from Rinorragi/feature/lab0102
Rinorragi Feb 14, 2025
5f022a6
Update readme for labs 01 and 02
Rinorragi Feb 14, 2025
3bf17fa
Update readme and readmes for labs 52 and 53
Rinorragi Feb 14, 2025
5a8cfc8
add secrets
Rinorragi Feb 14, 2025
b3bb5ef
fix readme
Rinorragi Feb 14, 2025
b9b5b9e
Add gitattributes
Rinorragi Feb 14, 2025
07102cc
Merge pull request #7 from Rinorragi/feature/addSecrets
Rinorragi Feb 14, 2025
d3c8a86
Lab51: Add more details about the solution
Rinorragi Feb 14, 2025
6c3bbbc
Fix readmes
Rinorragi Feb 14, 2025
b608b3f
Remove unneccessary todos
Rinorragi Feb 14, 2025
bff1a14
Merge pull request #9 from Rinorragi/feature/readme-update
Rinorragi Feb 14, 2025
275f818
Update readme
Rinorragi Feb 14, 2025
bbdd98b
Add note to avoid scancode action (#10)
Rinorragi Feb 14, 2025
1bae38d
Lab40: readme update
Rinorragi Feb 14, 2025
5f88c0a
Add github actions vscode extensions to recommended extensions
Rinorragi Feb 14, 2025
b3969a6
add link to script (#16)
Rinorragi Feb 14, 2025
9193bf0
Update readme and add github actions extension to vscode recommendations
Rinorragi Feb 14, 2025
c7bda1f
Lab40: Update where the venom file origin is
Rinorragi Feb 14, 2025
0459a71
ruleset docs (#12)
Rinorragi Feb 14, 2025
d95eb84
lab13: Add mention about dependency track
Rinorragi Feb 14, 2025
508a001
Merge pull request #14 from Rinorragi/feature/lab42update
Rinorragi Feb 14, 2025
227d4a1
Lab21: Fix readme
Rinorragi Feb 14, 2025
74c99db
Update readmes
Rinorragi Feb 14, 2025
2fe9a5f
Add github actions vscode extensions to recommended extensions
Rinorragi Feb 14, 2025
cae4414
add link to script (#16)
Rinorragi Feb 14, 2025
8603c07
Update readme and add github actions extension to vscode recommendations
Rinorragi Feb 14, 2025
82110ef
Lab40: Update where the venom file origin is
Rinorragi Feb 14, 2025
12a7706
lab13: Add mention about dependency track
Rinorragi Feb 14, 2025
43608d6
Merge branch 'main' of https://github.com/Rinorragi/ci-security
Rinorragi Feb 14, 2025
0babce4
Merge branch 'main' into release/examples
Rinorragi Feb 14, 2025
2fda12d
Merge pull request #13 from Rinorragi/feature/rulesetExample
Rinorragi Feb 14, 2025
ab3d909
Merge branch 'main' into release/examples
Rinorragi Feb 14, 2025
908153c
Merge branch 'main' into release/examples
Rinorragi Feb 14, 2025
5c4d6ae
merge main
Rinorragi Feb 14, 2025
9c74493
lab23: small change
Rinorragi Feb 14, 2025
6cb7ea9
Lab13: Fix spdx
Rinorragi Feb 15, 2025
c65d65b
Lab13: Fix spdx
Rinorragi Feb 15, 2025
adc17e2
Merge pull request #19 from Rinorragi/feature/spdx-fix
Rinorragi Feb 15, 2025
2ac4b3f
add dotnet 7 for tool requirements
DrBushyTop Feb 15, 2025
49412e8
Merge pull request #20 from Rinorragi/feature/dotnetlicensefix
Rinorragi Feb 15, 2025
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .editorconfig
Original file line number Diff line number Diff line change
Expand Up @@ -14,3 +14,7 @@ trim_trailing_whitespace = true
# Markdown
[*.md]
trim_trailing_whitespace = false

[/.githooks/**]
end_of_line = lf
insert_final_newline = false
3 changes: 3 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -1 +1,4 @@
* text=auto eol=crlf

# Force githooks to be LF
.githooks/* eol=lf
3 changes: 3 additions & 0 deletions .githooks/commit-msg
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
#!/bin/sh
COMMIT_MSG_FILE=$1
pwsh -ExecutionPolicy RemoteSigned -File 'scripts/githooks/commit-msg-check.ps1' "$COMMIT_MSG_FILE"
2 changes: 2 additions & 0 deletions .githooks/pre-commit
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
#!/bin/sh
pwsh -ExecutionPolicy RemoteSigned -File 'scripts/githooks/pre-commit-file-list.ps1'
31 changes: 30 additions & 1 deletion .github/workflows/lab00-hello-github-actions.yml
Original file line number Diff line number Diff line change
@@ -1,11 +1,40 @@
# Name of the workflow
name: Lab00 Hello GitHub Actions
# How the workflow run is named in GitHub
run-name: Lab00 - ${{ github.actor }} is testing out GitHub Actions 🚀
permissions: read-all
# Set your preferences for the script
defaults:
run:
shell: pwsh
on:
# Make it possible to other workflows to call this
workflow_call:
# Make it possible to manually run this workflow
workflow_dispatch:
# The actual jobs
jobs:
example-job:
# Job named Hello-job that runs on ubuntu-latest virtual machine
Hello-Job:
runs-on: ubuntu-latest
# Steps that are being run to complete the job
steps:
- name: Run hello world
run: echo "🎉 Step of the job is running on ${{ runner.os }}!"
# Job named Build-Job that builds the example applications
Build-Job:
runs-on: ubuntu-latest
# Steps to actually build the application
steps:
# Check out the git repository
- name: Checkout
uses: actions/checkout@v4
# Ensure proper version of .NET
- name: Setup dotnet
uses: actions/setup-dotnet@v3
with:
dotnet-version: "8.0.x"
- name: Install .NET dependencies
run: dotnet restore
- name: Build application
run: dotnet build
26 changes: 23 additions & 3 deletions .github/workflows/lab01-variables-and-secrets.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,28 @@ permissions: read-all
on:
workflow_dispatch:
jobs:
example-job:
demo:
runs-on: ubuntu-latest
# Define a global environment variable for this job
env:
MY_VARIABLE: "Hello from the environment variable!"

steps:
- name: Run hello world
run: echo "🎉 Step of the job is running on ${{ runner.os }}!"
- name: Checkout Code
uses: actions/checkout@v4

- name: Echo Variable and Secret
env:
# For this to work, you need to create a repository secret on GitHub.com
# 1. Go to your repository on GitHub.com
# 2. Navigate to Settings > Secrets and variables > Actions
# 3. Click "New repository secret"
# 4. Name: DEMO_SECRET
# 5. Secret: your-secret-value

# Assign the repository secret to an environment variable for this step
DEMO_SECRET: ${{ secrets.DEMO_SECRET }}
run: |
echo "Environment Variable: $MY_VARIABLE"
echo "Secret Value: $DEMO_SECRET"
echo "Note how the secret value is not printed to the log"
23 changes: 20 additions & 3 deletions .github/workflows/lab02-reuse-and-artifacts.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,25 @@ permissions: read-all
on:
workflow_dispatch:
jobs:
example-job:
run-composite:
runs-on: ubuntu-latest
steps:
- name: Run hello world
run: echo "🎉 Step of the job is running on ${{ runner.os }}!"
# Checkout the repository to the GitHub Actions runner
- name: Checkout
uses: actions/checkout@v4
# Run the template with parameters
- id: dotnet-build
uses: ./.github/actions/build-dotnet-app
with:
folder-path: "apps/uptodate-app"
# Publish output folder as an artifact
- name: Publish Artifact
uses: actions/upload-artifact@v4
with:
name: dotnet-app
path: ${{ steps.dotnet-build.outputs.output-directory-path }}

greeter:
uses: ./.github/workflows/greeter.yml
with:
person-name: "${{ github.actor }}"
131 changes: 128 additions & 3 deletions .github/workflows/lab10-software-composition-analysis.yml
Original file line number Diff line number Diff line change
@@ -1,11 +1,136 @@
# Name of the workflow
name: Lab10 SCA
# How the workflow run is named in GitHub
run-name: Lab10 - ${{ github.actor }} is finding vulns🚀
permissions: read-all
# Set your preferences for the script
defaults:
run:
shell: pwsh
on:
# Make it possible to other workflows to call this
workflow_call:
# Make it possible to manually run this workflow
workflow_dispatch:
# Dependency review is meant to work with prs
pull_request:
jobs:
example-job:
Test-Vulnerabilities-With-Dependency-Check:
name: OWASP Dependency Check
runs-on: ubuntu-latest
# Steps to actually build the application
steps:
- name: Run hello world
run: echo "🎉 Step of the job is running on ${{ runner.os }}!"
# Check out the git repository
- name: Checkout
uses: actions/checkout@v4
# Ensure proper version of .NET
- name: Setup dotnet
uses: actions/setup-dotnet@v3
with:
dotnet-version: "8.0.x"
# Ensure this to make sure to actually test against real deal
- name: Install .NET dependencies
run: dotnet restore
# Sometimes (even when considered as a bad practice) part of the dependencies are fetched during build, so better to build first
- name: Build application
run: dotnet build
# Run OWASP Dependency check
- name: Dependency Check
uses: dependency-check/Dependency-Check_Action@main
id: Depcheck
with:
project: "ci-security"
path: "."
format: "HTML"
out: "reports" # this is the default, no need to specify unless you wish to override it
args: >
--failOnCVSS 7
--enableRetired
# Use always() to ensure that even if the above fails on threshold the results are uploaded
- name: Upload Test results
uses: actions/upload-artifact@master
if: ${{ always() }}
with:
name: OWASP Dependency Check report
path: ${{github.workspace}}/reports

Test-Vulnerabilities-Natively:
name: "dotnet native check"
runs-on: ubuntu-latest
# Steps to actually build the application
steps:
# Check out the git repository
- name: Checkout
uses: actions/checkout@v4
# Ensure proper version of .NET
- name: Setup dotnet
uses: actions/setup-dotnet@v3
with:
dotnet-version: "8.0.x"
# Ensure this to make sure to actually test against real deal
- name: Install .NET dependencies
run: dotnet restore
# Sometimes (even when considered as a bad practice) part of the dependencies are fetched during build, so better to build first
- name: Build application
run: dotnet build
- name: Use dotnet tools to test vulns and to fail the job
run: | # Use | to tell github actions that this is multiline operation
$vulnCount = .\scripts\dotnetaudit.ps1
Write-Host "Run dotnetaudit.ps1 with total of $vulnCount vulnerabilities"
Write-Host "---OUTPUT---"
Get-content vulnerable.out
if ($vulnCount -gt 0) {
# Set proper error message
echo "::error file=scripts/dotnetaudit.ps1,line=19,col=1,endColumn=21,title=Vulnerabilities above zero::Vulnerabilities found for total of $vulnCount"
# Error message does not fail the job, use exit 1 to actually make it fail
exit 1
}

Test-Vulnerabilities-With-RetireJS:
name: "RetireJS check"
runs-on: ubuntu-latest
# Steps to actually build the application
steps:
# Check out the git repository
- name: Checkout
uses: actions/checkout@v4
# Ensure proper version of .NET
- name: Setup dotnet
uses: actions/setup-dotnet@v3
with:
dotnet-version: "8.0.x"
# Ensure this to make sure to actually test against real deal
- name: Install .NET dependencies
run: dotnet restore
# Sometimes (even when considered as a bad practice) part of the dependencies are fetched during build, so better to build first
- name: Build application
run: dotnet build
# Setup Node
- name: Use Node.js
uses: actions/setup-node@v4
with:
node-version: "23.x"
- name: Setup RetireJS and create folder for reports
run: |
npm install -g retire
mkdir reports
- name: Run RetireJS
run: retire --path . --outputformat text --outputpath ./reports/output.txt --severity low --exitwith 1 --deep
- name: Upload Test results
uses: actions/upload-artifact@master
if: ${{ always() }}
with:
name: RetireJS report
path: ${{github.workspace}}/reports

Test-with-dependency-review:
runs-on: ubuntu-latest
steps:
- name: "Checkout Repository"
uses: actions/checkout@v4
- name: "Dependency Review"
uses: actions/dependency-review-action@v4
with:
fail-on-severity: low
#allow-licenses: MIT
#deny-licenses: AGPL
39 changes: 36 additions & 3 deletions .github/workflows/lab11-create-package-lock.yml
Original file line number Diff line number Diff line change
@@ -1,11 +1,44 @@
# Name of the workflow
name: Lab11 Package Locks
# How the workflow run is named in GitHub
run-name: Lab11 - ${{ github.actor }} is locking packages 🔒
permissions: read-all
# Set your preferences for the script
defaults:
run:
shell: pwsh
on:
# Make it possible to other workflows to call this
workflow_call:
# Make it possible to manually run this workflow
workflow_dispatch:
# The actual jobs
jobs:
example-job:
Create-Package-Locks:
name: "Create Package Lock"
runs-on: ubuntu-latest
# Steps to actually build the application
steps:
- name: Run hello world
run: echo "🎉 Step of the job is running on ${{ runner.os }}!"
# Check out the git repository
- name: Checkout
uses: actions/checkout@v4
# Ensure proper version of .NET
- name: Setup dotnet
uses: actions/setup-dotnet@v3
with:
dotnet-version: "8.0.x"
# Generate lock file
- name: Generate lock file
run: dotnet restore --force --use-lock-file
# Test restore with locked mode
- name: Restore with locked mode
run: dotnet restore --locked-mode
# Dotnet by default restores implicitly if missing something. It is unneccessary and unwanted in CI-situations.
- name: Build application
run: dotnet build --no-restore
- name: Print the package locks
run: |
get-childitem *.lock.json -Recurse | % {
Write-Host $_
Get-Content $_
}
Loading