Security
Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.
Here are 1,464 public repositories matching this topic...
Please agree to the following
- I have searched existing issues for duplicates
- I agree to follow this project's Code of Conduct
Summary
Incorrect link to docs.cryptomator.org on welcome screen (Windows app)
What software is involved
I have noticed when ingesting backlog(older timestamped data) that the "Messages per minute" line graph and "sources" data do not line up.
The Messages per minute appear to be correct for the ingest rate, but the sources breakdown below it only show messages for each type from within the time window via timestamp. This means in the last hour if you've ingested logs from 2 days ago, the data is
-
Updated
Jul 8, 2022 - Java
-
Updated
Nov 6, 2021 - Java
-
Updated
Jun 30, 2022 - Java
-
Updated
Jul 7, 2022 - Java
-
Updated
Jun 23, 2022 - Java
Description
BeanUtils is a library that is doing automatic mapping to Java object.
It can cause arm when the attack controls part of the list of properties being sets. BeanUtils does not blacklist properties like class, classloader or other objects that are likely to load arbitrary classes and possibly run code.
Code
import org.apache.commons.beanutils.BeanUtils;
public-
Updated
Jun 20, 2022 - Java
-
Updated
Jul 6, 2022 - Java
-
Updated
Jul 8, 2022 - Java
-
Updated
Jun 2, 2022 - Java
Current Behavior:
As identified in #1727, there may be multiple fields of CycloneDX BOMs that we currently don't ingest or display.
Proposed Behavior:
Assess DT's coverage of CycloneDX v1.4 fields and add support for ingesting and displaying missing fields.
-
Updated
Jan 11, 2022 - Java
Summary
Dependabot has identified several security vulnerabilities in the 3rd party libraries Pacbot relies on. In most cases, these vulnerabilities can be resolved by upgrading the library to the most current version.
Maintainers, if you're internal to T-Mobile, you should have been seeing these security alerts coming in over the last several weeks. *Please respond to these in a timely ma
-
Updated
May 26, 2022 - Java
-
Updated
Jul 8, 2022 - Java
-
Updated
Jul 8, 2022 - Java
-
Updated
Jan 15, 2022 - Java
-
Updated
Apr 8, 2022 - Java
-
Updated
Jul 2, 2022 - Java
-
Updated
Dec 15, 2021 - Java
- Wikipedia
- Wikipedia
Security apps
Cloudback Backup
Automatic backups of your repos, metadata and even LFS. Backup to AWS, Azure, OneDrive, GCP, and more. Instant restores
Rewind Backups for GitHub (Formerly BackHub)
Daily, automatic backups of your repos & metadata. Restore your backups with metadata in seconds + Sync to your S3 or Azure
GitProtect.io Backup
Automatic, daily repo and metadata backup - no maintenance needed: fast restore, DR, AWS, and S3 cloud storage support
GuardRails
GuardRails provides continuous security feedback for modern development teams
Renovate
Keep dependencies up-to-date with automated Pull Requests
LGTM
Find and prevent zero-days and other critical bugs, with customizable alerts and automated code review
Mend Bolt
Detect open source vulnerabilities in real time with suggested fixes for quick remediation
Semgrep
Code scanning at ludicrous speed. Find bugs and enforce code standards
Snyk
Find, fix (and prevent!) known vulnerabilities in your code
Is your feature request related to a problem?
The Traditional and Traditional Plus JSON reports treat "Other Info" as consistent between alerts which is not always the case. A new JSON report should be added which treats "Other Info" as potentially unique per alert instance.
As per the original issue a perfect way to test/experience this need is the Retire.JS passive scan alerts which i