Skip to content
#

Security

Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.

Here are 853 public repositories matching this topic...

caddy
tgelite
tgelite commented Mar 11, 2021

I’m trying to script setup and configuration of caddy server based on a custom download that includes additional plugins (caddy-auth-portal, caddy-auth-jwt, caddy-trace, and various caddy-dns modules ).

During setup, the caddy unit file is configured to run caddy as a non priveledged user (by design).

To get certificates configured properly we are attempting to use the caddy trust command

grega
grega commented Sep 9, 2021

The docs at https://www.ory.sh/hydra/docs/cli/hydra-clients-import state as a description:

"Imports cryptographic keys of any format to the JSON Web Key Store

This appears to be incorrect. The description would be expected to be:

"Import OAuth 2.0 Clients from one or more JSON files"

(and this is confirmed by an earlier version of the docs for this CLI interface: https://www.ory.sh/hyd

ChrisASE
ChrisASE commented Aug 10, 2021

What version of Gophish are you using?:
0.11.0

Brief description of the issue:
When editing existing templates/sending profiles/landing pages etc, the title of the popup boxes all begin with 'New'.

What are you expecting to see happen? :
When creating new (or copying) templates/sending profiles/landing pages they are titled 'New xxxxxx'. When editing existing templates/sending profi

buixor
buixor commented Jun 2, 2021

Is your feature request related to a problem? Please describe.
When the user is running cscli dashboard setup and the available resources are obviously lacking (people tend to think that the dashboard might not require more resources than crowdsec itself), we should warn the user.

Describe the solution you'd like
Warn the user and/or ask for a confirmation if the available res

certificates
mkkeffeler
mkkeffeler commented Aug 28, 2021

What would you like to be added

We can't query smallstep for anything related to certs because the only thing in the DB is the bytes of the cert. Storing the cert alongside more columns like the common name, not after date, and more, would let us enable more complex queries, and optimize performance for future use cases.

Why this is needed

Enable searching of Certificates signed by attrib

mccutchen
mccutchen commented May 1, 2019

Is your feature request related to a problem? Please describe.

The public key-based request signing functionality added to sso_proxy in buzzfeed/sso#106 is undocumented. In particular, it's not immediately obvious how to a) generate an appropriate keypair or b) validate a signed request in an upstream service.

Describe the solution you'd like

New documenta

terrascan
adegoodyer
adegoodyer commented Aug 11, 2021
  • terrascan version: 1.9.0
  • terraform version: 1.0.1

Enhancement Request

Other security scanning tools (e.g. checkov and tfsec) have a --soft-fail flag or equivalent option that allows you to always exit with 0 status.

Extremely useful when running the tool without halting a pipeline for example.

I currently use a workaround, but something more concrete would be very desira

Wikipedia
Wikipedia

Security apps

WhiteSource Bolt

Detect open source vulnerabilities in real time with suggested fixes for quick remediation

BackHub Backups by Rewind

Backup your GitHub repos & metadata automatically. Get daily backups that can be restored in seconds – AWS storage available

LGTM

Find and prevent zero-days and other critical bugs, with customizable alerts and automated code review

Semgrep

Code scanning at ludicrous speed. Find bugs, apply guardrails across your repos, and get feedback in PRs, Slack, or email

Sonatype Lift

Lift helps you find and fix your most elusive bugs so you can spend time writing great code, not debugging it

Sonatype DepShield

Monitor your open source components for security vulnerabilities - goodbye muda, hello kaizen

Snyk

Find, fix (and prevent!) known vulnerabilities in your code

Renovate

Keep dependencies up-to-date with automated Pull Requests

GuardRails

GuardRails provides continuous security feedback for modern development teams

See more Security apps