|
You are here |
xvnpw.github.io | ||
| | | | |
securitylab.github.com
|
|
| | | | | In this article, well discuss some common security malpractices for GitHub Actions and workflows, and how to best avoid them. Our examples are based on real-world GitHub workflow implementation vulnerabilities the GitHub Security Lab has reported to maintainers. | |
| | | | |
code.dblock.org
|
|
| | | | | The OpenSearch API specification is authored in OpenAPI and used to auto-generate OpenSearch language clients. I wanted to know how much of the API was described in it vs. the actual API implemented in the default distribution of OpenSearch that includes all plugins. To do so, I have exposed an iterator over REST handlers in OpenSearch core, and wrote a plugin that rendered a very minimal OpenAPI spec at runtime. All that was left was to compare the manually authored OpenAPI spec in opensearch-api-specification to the runtime one, added in opensearch-api-specification#179. The comparison workflow output a total and relative number of APIs described. | |
| | | | |
tech.michaelaltfield.net
|
|
| | | | | How to detect malicious bidirectional unicode characters in PR commits using a GitHub Actions workflow (Defending against Trojan Source attacks) | |
| | | | |
jeffpaul.com
|
|
| | | Just over 7 years ago, Gutenberg was "born". Congrats to MatÃas Ventura for that initial commit and the 1,099 contributors for achieving this milestone. Hopefully the new Props Bot will bring significantly more credited contributors over the next year such that we're celebrating and even more successful 8th birthday next year! | ||