From 18486e86cb2c2e3fcb78237a62cd963549c2e9ed Mon Sep 17 00:00:00 2001 From: Souradip Ghosh Date: Mon, 26 Feb 2024 20:45:01 +0530 Subject: [PATCH 1/8] Create snykScan.yaml --- .github/workflows/snykScan.yaml | 24 ++++++++++++++++++++++++ 1 file changed, 24 insertions(+) create mode 100644 .github/workflows/snykScan.yaml diff --git a/.github/workflows/snykScan.yaml b/.github/workflows/snykScan.yaml new file mode 100644 index 0000000..954b163 --- /dev/null +++ b/.github/workflows/snykScan.yaml @@ -0,0 +1,24 @@ +name: Snyk Security + +on: + push: + branches: ["master" ] + pull_request: + branches: ["master"] + + +jobs: + snyk: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v2 + - uses: snyk/actions/setup@master + - name: Snyk Code Test + continue-on-error: true + run: snyk code test --sarif > snyk_sarif + env: + SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} + - name: Upload results to Github Code Scanning + uses: github/codeql-action/upload-sarif@v1 + with: + sarif_file: snyk_sarif From e10a9421188e109096ab19d048278470524c6b01 Mon Sep 17 00:00:00 2001 From: Souradip Ghosh Date: Mon, 26 Feb 2024 20:47:37 +0530 Subject: [PATCH 2/8] Update snykScan.yaml --- .github/workflows/snykScan.yaml | 8 +++----- 1 file changed, 3 insertions(+), 5 deletions(-) diff --git a/.github/workflows/snykScan.yaml b/.github/workflows/snykScan.yaml index 954b163..10bcf80 100644 --- a/.github/workflows/snykScan.yaml +++ b/.github/workflows/snykScan.yaml @@ -15,10 +15,8 @@ jobs: - uses: snyk/actions/setup@master - name: Snyk Code Test continue-on-error: true - run: snyk code test --sarif > snyk_sarif + run: snyk code test --json > snykResult.json env: SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} - - name: Upload results to Github Code Scanning - uses: github/codeql-action/upload-sarif@v1 - with: - sarif_file: snyk_sarif + - name: Get JSON data + run: cat snykResult.json From 82e427c8222a4dc8269b3d1691f28c0e73a59d20 Mon Sep 17 00:00:00 2001 From: Souradip Ghosh Date: Mon, 26 Feb 2024 20:52:37 +0530 Subject: [PATCH 3/8] Create vulnCode.js --- src/vulnCode.js | 22 ++++++++++++++++++++++ 1 file changed, 22 insertions(+) create mode 100644 src/vulnCode.js diff --git a/src/vulnCode.js b/src/vulnCode.js new file mode 100644 index 0000000..f47403e --- /dev/null +++ b/src/vulnCode.js @@ -0,0 +1,22 @@ +const fetch = require('node-fetch'); + +async function fetchGitHubUserCount(pat, orgName) { + try { + const response = await fetch(`https://api.github.com/orgs/${orgName}/members`, { + headers: { + Authorization: `token ${pat}` + } + }); + const members = await response.json(); + const memberCount = members.length; + console.log(`Total members in ${orgName} organization:`, memberCount); + } catch (error) { + console.error('Error fetching GitHub user count:', error); + } +} + +// Replace 'YOUR_PAT' and 'YOUR_ORG_NAME' with your personal access token and GitHub organization name respectively +const pat = 'YOUR_PAT'; +const orgName = 'YOUR_ORG_NAME'; + +fetchGitHubUserCount(pat, orgName); From f77a53663a85f6dfbbb84c787e81d0b30ac0db8a Mon Sep 17 00:00:00 2001 From: Souradip Ghosh Date: Mon, 26 Feb 2024 21:03:00 +0530 Subject: [PATCH 4/8] Update snykScan.yaml --- .github/workflows/snykScan.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/snykScan.yaml b/.github/workflows/snykScan.yaml index 10bcf80..40d6ef1 100644 --- a/.github/workflows/snykScan.yaml +++ b/.github/workflows/snykScan.yaml @@ -15,7 +15,7 @@ jobs: - uses: snyk/actions/setup@master - name: Snyk Code Test continue-on-error: true - run: snyk code test --json > snykResult.json + run: snyk code test env: SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} - name: Get JSON data From 321996dc7d1b816ee582a48e0374e8c35223855a Mon Sep 17 00:00:00 2001 From: Souradip Ghosh Date: Mon, 26 Feb 2024 21:09:08 +0530 Subject: [PATCH 5/8] Create keys --- keys | 44 ++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 44 insertions(+) create mode 100644 keys diff --git a/keys b/keys new file mode 100644 index 0000000..866bd4d --- /dev/null +++ b/keys @@ -0,0 +1,44 @@ +Basic auth: + +https://admin:admin@the-internet.herokuapp.com/basic_auth + +Private key: +-----BEGIN OPENSSH PRIVATE KEY----- +b3BlbnNzaC1rZXktdjEAAAAACmFlczI1Ni1jdHIAAAAGYmNyeXB0AAAAGAAAABAjNIZuun +xgLkM8KuzfmQuRAAAAEAAAAAEAAAGXAAAAB3NzaC1yc2EAAAADAQABAAABgQDe3Al0EMPz +utVNk5DixaYrGMK56RqUoqGBinke6SWVWmqom1lBcJWzor6HlnMRPPr7YCEsJKL4IpuVwu +inRa5kdtNTyM7yyQTSR2xXCS0fUItNuq8pUktsH8VUggpMeew8hJv7rFA7tnIg3UXCl6iF +OLZKbDA5aa24idpcD8b1I9/RzTOB1fu0of5xd9vgODzGw5JvHQSJ0FaA42aNBMGwrDhDB3 +sgnRNdWf6NNIh8KpXXMKJADf3klsyn6He8L2bPMp8a4wwys2YB35p5zQ0JURovsdewlOxH +NT7eP19eVf4dCreibxUmRUaob5DEoHEk8WrxjKWIYUuLeD6AfcW6oXyRU2Yy8Vrt6SqFl5 +WAi47VMFTkDZYS/eCvG53q9UBHpCj7Qvb0vSkCZXBvBIhlw193F3PX4WvO1IXsMwvQ1D1X +lmomsItbqM0cJyKw6LU18QWiBHvE7BqcphaoL5E08W2ATTSRIMCp6rt4rptM7KyGK8rc6W +UYrCnWt6KlCA8AAAWQXk+lVx6bH5itIKKYmQr6cR/5xtZ2GHAxnYtvlW3xnGhU0MHv+lJ2 +uoWlT2RXE5pdMUQj7rNWAMqkwifSKZs9wBfYeo1TaFDmC3nW7yHSN3XTuO78mPIW5JyvmE +Rj5qjsUn7fNmzECoAxnVERhwnF3KqUBEPzIAc6/7v/na9NTiiGaJPco9lvCoPWbVLN08WG +SuyU+0x5zc3ebzuPcYqu5/c5nmiGxhALrIhjIS0OV1mtAAFhvdMjMIHOijOzSKVCC7rRk5 +kG9EMLNvOn/DUVSRHamw5gs2V3V+Zq2g5nYWfgq8aDSTB8XlIzOj1cz3HwfN6pfSNQ/3Qe +wOQfWfTWdO+JSL8aoBN5Wg8tDbgmvmbFrINsJfFfSm0wZgcHhC7Ul4U3v4c8PoNdK9HXwi +TKKzJ9nxLYb+vDh50cnkseu2gt0KwVpjIorxEqeK755mKPao3JmOMr6uFTQsb+g+ZNgPwl +nRHA4Igx+zADFj3twldnKIiRpBQ5J4acur3uQ+saanBTXgul1TiFiUGT2cnz+IiCsdPovg +TAMt868W5LmzpfH4Cy54JtaRC4/UuMnkTGbWgutVDnWj2stOAzsQ1YmhH5igUmc94mUL+W +8vQDCKpeI8n+quDS9zxTvy4L4H5Iz7OZlh0h6N13BDvCYXKcNF/ugkfxZbu8mZsZQQzXNR +wOrEtKoHc4AnXYNzsuHEoEyLyJxGfFRDSTLbyN9wFOS/c0k9Gjte+kQRZjBVGORE5sN6X3 +akUnTF76RhbEc+LamrwM1h5340bwosRbR8I+UrsQdFfJBEj1ZSyMRJlMkFUNi6blt7bhyx +ea+Pm2A614nlYUBjw2KKzzn8N/0H2NpJjIptvDsbrx3BS/rKwOeJwavRrGnIlEzuAag4vx +Zb2TPVta45uz7fQP5IBl83b0BJKI5Zv/fniUeLI78W/UsZqb64YQbfRyBzFtI1T/SsCi0B +e0EyKMzbxtSceT1Mb8eJiVIq04Xpwez9fIUt5rSedZD8KPq8P6s0cGsR7Qmw6eXZ/dBR/a +s5vPhfIUmQawmnwAVuWNRdQQ79jUBSn5M+ZRVVTgEG+vFyvxr/bZqOo1JCoq5BmQhLWGRJ +Dk9TolbeFIVFrkuXkcu99a079ux7XSkON64oPzHrcsEzjPA1GPqs9CGBSO16wq/nI3zg+E +kcOCaurc9yHJJPwduem0+8WLX3WoGNfQRKurtQze2ppy8KarEtDhDd96sKkhYaqOg3GOX8 +Yx827L4vuWSJSIqKuO2kH6kOCMUNO16piv0z/8u3CJxOGh9+4FZIop81fiFTKLhV3/gwLm +fzFY++KIZrLfZcUjzd80NNEja69F452Eb9HrI5BurN/PznDEi9bzM598Y7beyl4/kd4R2e +S7SW9/LOrGw5UgxtiU+kV8nPz1PdgxO4sRlnntSBEwkQBzMkLOpq2h2BuJ2TlMP/TWuwLQ +sDkv1Yk1pD0roGmtMzbujnURGxqRJ8gUmuIot4hpfyRSssvnRQQZ3lQCQCwHiE+HJxXWf5 +c58zOMjW7o21tI8e13uUnbRoQVJM9XYqk1usPXIkYPYL9uOw3AW/Zn+cnDrsXvTK9ZxgGD +/90b1BNwVqMlUK+QggHNwl5qD8eoXK5cDvav66te+E+V7FYFQ06w3tytRVz8SjoaiChN02 +muIjvl6G7Hoj1hObM2t/ZheN1EShS11z868hhS6Mx7GvIdtkXuvdiBYMiBLOshJQxB8Mzx +iug9W+Di3upLf0UMC1TqADGphsIHRU7RbmHQ8Rwp7dogswmDfpRSapPt9p0D+6Ad5VBzi3 +f3BPXj76UBLMEJCrZR1P28vnAA7AyNHaLvMPlWDMG5v3V/UV+ugyFcoBAOyjiQgYST8F3e +Hx7UPVlTK8dyvk1Z+Yw0nrfNClI= +-----END OPENSSH PRIVATE KEY----- From 691fec3553a1855ed2c24656debf2b55bd33992e Mon Sep 17 00:00:00 2001 From: Souradip Ghosh Date: Mon, 26 Feb 2024 21:20:28 +0530 Subject: [PATCH 6/8] Update snykScan.yaml --- .github/workflows/snykScan.yaml | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/.github/workflows/snykScan.yaml b/.github/workflows/snykScan.yaml index 40d6ef1..ac6bfaf 100644 --- a/.github/workflows/snykScan.yaml +++ b/.github/workflows/snykScan.yaml @@ -15,8 +15,7 @@ jobs: - uses: snyk/actions/setup@master - name: Snyk Code Test continue-on-error: true - run: snyk code test + run: snyk code test --all-projects env: SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} - - name: Get JSON data - run: cat snykResult.json + From 8d5f1f3dea56ad161b9b772093d718f89451380a Mon Sep 17 00:00:00 2001 From: Souradip Ghosh Date: Mon, 26 Feb 2024 21:22:47 +0530 Subject: [PATCH 7/8] Update snykScan.yaml --- .github/workflows/snykScan.yaml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/snykScan.yaml b/.github/workflows/snykScan.yaml index ac6bfaf..3f967f9 100644 --- a/.github/workflows/snykScan.yaml +++ b/.github/workflows/snykScan.yaml @@ -18,4 +18,7 @@ jobs: run: snyk code test --all-projects env: SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} + - name: get code + run: | + ls From a73e6b46f3767d2f509b14123d97c17d8192e200 Mon Sep 17 00:00:00 2001 From: Souradip Ghosh Date: Mon, 13 May 2024 15:02:43 +0530 Subject: [PATCH 8/8] Update keys --- keys | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/keys b/keys index 866bd4d..f5cf0ae 100644 --- a/keys +++ b/keys @@ -1,6 +1,6 @@ Basic auth: -https://admin:admin@the-internet.herokuapp.com/basic_auth +http://admin:admin@the-internet.herokuapp.com/basic_auth Private key: -----BEGIN OPENSSH PRIVATE KEY-----