Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security issues reported from GH #1281

Closed
morri-son opened this issue Feb 4, 2025 · 3 comments · Fixed by #1282
Closed

Security issues reported from GH #1281

morri-son opened this issue Feb 4, 2025 · 3 comments · Fixed by #1282
Assignees
Labels
area/ipcei Important Project of Common European Interest area/security Security relevant lifecycle/icebox Temporarily on hold (will not age; may have dependencies, lack priority, miss feedback, etc.)
Milestone

Comments

@morri-son
Copy link
Contributor

morri-son commented Feb 4, 2025

Description

The gardener team reported issues with regards to SAST checks on the ocm repo: https://github.tools.sap/kubernetes/compliance-reporting/issues/7731. Since we have GH Advanced security in place and in addition to that added gosec, we should be save watching the security alerts in the GH UI as it displays result of all scans.

In https://github.com/open-component-model/ocm/security/code-scanning there are issues reported with severity high. Copilot generated proposals how to fix the issues. All PRs are linked to this issue. Please carefully check the Copilot proposal for correctness.

Check if the alerts are even relevant and not a false-positive. In case they don't need to be fixed, go to https://github.com/open-component-model/ocm/security/code-scanning, select the error and use the "Dismiss Alert" button on the upper right corner of the UI and select the reason for the dismissal.

@maximilianbraun
Copy link
Member

Can you please give me access?

@morri-son
Copy link
Contributor Author

Can you please give me access?

@maximilianbraun done

@ccwienk
Copy link
Contributor

ccwienk commented Feb 5, 2025

related: #1233

@fabianburth fabianburth moved this from 🆕 ToDo to 📋 Next-UP in OCM Backlog Board Feb 5, 2025
@fabianburth fabianburth moved this from 📋 Next-UP to 🏗 In Progress in OCM Backlog Board Feb 5, 2025
@morri-son morri-son linked a pull request Feb 5, 2025 that will close this issue
morri-son pushed a commit that referenced this issue Feb 5, 2025
<!-- markdownlint-disable MD041 -->
#### What this PR does / why we need it

#### Which issue(s) this PR fixes
<!--
Usage: `Fixes #<issue number>`, or `Fixes (paste link of issue)`.
-->
#1281
@github-project-automation github-project-automation bot moved this from 🏗 In Progress to 🍺 Done in OCM Backlog Board Feb 5, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/ipcei Important Project of Common European Interest area/security Security relevant lifecycle/icebox Temporarily on hold (will not age; may have dependencies, lack priority, miss feedback, etc.)
Projects
Status: 🍺 Done
Development

Successfully merging a pull request may close this issue.

5 participants