Security
Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.
Here are 853 public repositories matching this topic...
The docs at https://www.ory.sh/hydra/docs/cli/hydra-clients-import state as a description:
"Imports cryptographic keys of any format to the JSON Web Key Store
This appears to be incorrect. The description would be expected to be:
"Import OAuth 2.0 Clients from one or more JSON files"
(and this is confirmed by an earlier version of the docs for this CLI interface: https://www.ory.sh/hyd
-
Updated
Sep 14, 2021 - Go
-
Updated
Sep 12, 2021 - Go
-
Updated
Sep 15, 2021 - Go
-
Updated
Sep 15, 2021 - Go
-
Updated
Sep 14, 2021 - Go
AlmaLinux should be detected as RHEL/CentOS. Trivy should be able to detect RHEL/CentOS vulnerabilities
Create CHANGELOG.md
Describe the solution you'd like
I'd like to go back to using a CHANGELOG.md to track changes. This will be the first step in updating the ci/cd process to increase the frequency of patches/deploys.
Additional context
Go through https://github.com/zricethezav/gitleaks/releases and create a CHANGELOG.md file
cc @zricethezav
-
Updated
Sep 13, 2021 - Go
What version of Gophish are you using?:
0.11.0
Brief description of the issue:
When editing existing templates/sending profiles/landing pages etc, the title of the popup boxes all begin with 'New'.
What are you expecting to see happen? :
When creating new (or copying) templates/sending profiles/landing pages they are titled 'New xxxxxx'. When editing existing templates/sending profi
-
Updated
Sep 13, 2021 - Go
-
Updated
Jul 19, 2021 - Go
-
Updated
Sep 11, 2021 - Go
-
Updated
Sep 15, 2021 - Go
-
Updated
Apr 9, 2021 - Go
-
Updated
May 1, 2021 - Go
Is your feature request related to a problem? Please describe.
When the user is running cscli dashboard setup and the available resources are obviously lacking (people tend to think that the dashboard might not require more resources than crowdsec itself), we should warn the user.
Describe the solution you'd like
Warn the user and/or ask for a confirmation if the available res
-
Updated
Sep 15, 2021 - Go
-
Updated
Sep 14, 2021 - Go
What would you like to be added
We can't query smallstep for anything related to certs because the only thing in the DB is the bytes of the cert. Storing the cert alongside more columns like the common name, not after date, and more, would let us enable more complex queries, and optimize performance for future use cases.
Why this is needed
Enable searching of Certificates signed by attrib
-
Updated
Sep 14, 2021 - Go
Is your feature request related to a problem? Please describe.
The public key-based request signing functionality added to sso_proxy in buzzfeed/sso#106 is undocumented. In particular, it's not immediately obvious how to a) generate an appropriate keypair or b) validate a signed request in an upstream service.
Describe the solution you'd like
New documenta
-
Updated
Sep 15, 2021 - Go
Is there a way to skip the nmap scan and go straight to the attacking routes? In case i already know the target list is full of open rtsp port IPs.
- terrascan version: 1.9.0
- terraform version: 1.0.1
Enhancement Request
Other security scanning tools (e.g. checkov and tfsec) have a --soft-fail flag or equivalent option that allows you to always exit with 0 status.
Extremely useful when running the tool without halting a pipeline for example.
I currently use a workaround, but something more concrete would be very desira
-
Updated
May 30, 2021 - Go
- Wikipedia
- Wikipedia
GitHub은 글로벌 소프트웨어 개발공간으로서
September 28, 2021 • Online
Security apps
WhiteSource Bolt
Detect open source vulnerabilities in real time with suggested fixes for quick remediation
BackHub Backups by Rewind
Backup your GitHub repos & metadata automatically. Get daily backups that can be restored in seconds – AWS storage available
LGTM
Find and prevent zero-days and other critical bugs, with customizable alerts and automated code review
Semgrep
Code scanning at ludicrous speed. Find bugs, apply guardrails across your repos, and get feedback in PRs, Slack, or email
Sonatype Lift
Lift helps you find and fix your most elusive bugs so you can spend time writing great code, not debugging it
Sonatype DepShield
Monitor your open source components for security vulnerabilities - goodbye muda, hello kaizen
GitProtect.io Backup
Fully manageable, most professional repository and metadata backup and recovery
Snyk
Find, fix (and prevent!) known vulnerabilities in your code
Renovate
Keep dependencies up-to-date with automated Pull Requests
Cloudback Backup
Backups your GitHub repositories, fast and secure
GuardRails
GuardRails provides continuous security feedback for modern development teams

I’m trying to script setup and configuration of caddy server based on a custom download that includes additional plugins (caddy-auth-portal, caddy-auth-jwt, caddy-trace, and various caddy-dns modules ).
During setup, the caddy unit file is configured to run caddy as a non priveledged user (by design).
To get certificates configured properly we are attempting to use the caddy trust command