Explore >> Select a destination


You are here

xvnpw.github.io
| | securitylab.github.com
2.1 parsecs away

Travel
| | In this article, well discuss some common security malpractices for GitHub Actions and workflows, and how to best avoid them. Our examples are based on real-world GitHub workflow implementation vulnerabilities the GitHub Security Lab has reported to maintainers.
| | code.dblock.org
2.5 parsecs away

Travel
| | The OpenSearch API specification is authored in OpenAPI and used to auto-generate OpenSearch language clients. I wanted to know how much of the API was described in it vs. the actual API implemented in the default distribution of OpenSearch that includes all plugins. To do so, I have exposed an iterator over REST handlers in OpenSearch core, and wrote a plugin that rendered a very minimal OpenAPI spec at runtime. All that was left was to compare the manually authored OpenAPI spec in opensearch-api-specification to the runtime one, added in opensearch-api-specification#179. The comparison workflow output a total and relative number of APIs described.
| | tech.michaelaltfield.net
2.8 parsecs away

Travel
| | How to detect malicious bidirectional unicode characters in PR commits using a GitHub Actions workflow (Defending against Trojan Source attacks)
| | jeffpaul.com
16.5 parsecs away

Travel
| Just over 7 years ago, Gutenberg was "born". Congrats to Matías Ventura for that initial commit and the 1,099 contributors for achieving this milestone. Hopefully the new Props Bot will bring significantly more credited contributors over the next year such that we're celebrating and even more successful 8th birthday next year!