Skip to content

Create semgrep-vulns.py - testing Semgrep Diff-aware Scans workflow - #79

Open
akashkumarmg wants to merge 7 commits into
mainfrom
akashkumarmg-patch-6
Open

akashkumarmg wants to merge 7 commits into
mainfrom
akashkumarmg-patch-6

Conversation

@akashkumarmg

Copy link
Copy Markdown
Owner

Create semgrep-vulns.py - testing Semgrep Diff-aware Scans workflow

Create semgrep-vulns.py - testing Semgrep Diff-aware Scans workflow
@github-actions

Copy link
Copy Markdown

🔐 Gitleaks docker Findings: 2 issue(s) detected

🔸 Rule: slack-webhook-url
📄 File: gitleaks-test-file1.sh:4
📝 Description: Discovered a Slack Webhook, which could lead to unauthorized message posting and data leakage in Slack channels.
🔑 Secret: **********
🔗 Path: gitleaks-test-file1.sh:4

🔸 Rule: stripe-access-token
📄 File: semgrep-vulns.py:6
📝 Description: Found a Stripe Access Token, posing a risk to payment processing services and sensitive financial data.
🔑 Secret: **********
🔗 Path: semgrep-vulns.py:6

@github-actions

Copy link
Copy Markdown

🔐 Gitleaks Findings: 2 issue(s) detected

🔸 Rule: slack-webhook-url
📄 File: gitleaks-test-file1.sh:null
📝 Description: Discovered a Slack Webhook, which could lead to unauthorized message posting and data leakage in Slack channels.
🔑 Secret: **********
🔗 Path: gitleaks-test-file1.sh:null

🔸 Rule: stripe-access-token
📄 File: semgrep-vulns.py:null
📝 Description: Found a Stripe Access Token, posing a risk to payment processing services and sensitive financial data.
🔑 Secret: **********
🔗 Path: semgrep-vulns.py:null

@github-actions

Copy link
Copy Markdown

GoSec Findings: No issues found, Good to merge.

@github-actions

Copy link
Copy Markdown

Semgrep-new findings: Issues are found, Please resolve the issues before merging.

@github-actions

Copy link
Copy Markdown

🛡️ Semgrep Findings — 1 issue(s) found

Showing first 3 findings below. [Download full JSON report to view all findings from Artifacts in summary.]


⚠️ Issue 1 — ERROR

📄 semgrep-vulns.py:14
🔗 View in PR
📘 Rule Documentation
💬 "Found 'subprocess' function 'call' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead."


@github-actions

Copy link
Copy Markdown

🔐 Gitleaks Findings: 2 issue(s) detected

🔸 Rule: slack-webhook-url
📄 File: gitleaks-test-file1.sh:null
📝 Description: Discovered a Slack Webhook, which could lead to unauthorized message posting and data leakage in Slack channels.
🔑 Secret: **********
🔗 Path: gitleaks-test-file1.sh:null

🔸 Rule: stripe-access-token
📄 File: semgrep-vulns.py:null
📝 Description: Found a Stripe Access Token, posing a risk to payment processing services and sensitive financial data.
🔑 Secret: **********
🔗 Path: semgrep-vulns.py:null

@github-actions

Copy link
Copy Markdown

🔐 Gitleaks docker Findings: 2 issue(s) detected

🔸 Rule: slack-webhook-url
📄 File: gitleaks-test-file1.sh:4
📝 Description: Discovered a Slack Webhook, which could lead to unauthorized message posting and data leakage in Slack channels.
🔑 Secret: **********
🔗 Path: gitleaks-test-file1.sh:4

🔸 Rule: stripe-access-token
📄 File: semgrep-vulns.py:6
📝 Description: Found a Stripe Access Token, posing a risk to payment processing services and sensitive financial data.
🔑 Secret: **********
🔗 Path: semgrep-vulns.py:6

@github-actions

Copy link
Copy Markdown

🔐 Gitleaks Findings: 1 issue(s) detected

🔸 Rule: stripe-access-token
📄 File: semgrep-vulns.py:null
📝 Description: Found a Stripe Access Token, posing a risk to payment processing services and sensitive financial data.
🔑 Secret: **********
🔗 Path: semgrep-vulns.py:null

@github-actions

Copy link
Copy Markdown

GoSec Findings: No issues found, Good to merge.

@github-actions

Copy link
Copy Markdown

Semgrep-new findings: Issues are found, Please resolve the issues before merging.

@github-actions

Copy link
Copy Markdown

🛡️ Semgrep Findings — 1 issue(s) found

Showing first 3 findings below. [Download full JSON report to view all findings from Artifacts in summary.]


⚠️ Issue 1 — ERROR

📄 semgrep-vulns.py:14
🔗 View in PR
📘 Rule Documentation
💬 "Found 'subprocess' function 'call' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead."


@github-actions

Copy link
Copy Markdown

🔐 Gitleaks docker Findings: 2 issue(s) detected

🔸 Rule: slack-webhook-url
📄 File: gitleaks-test-file1.sh:4
📝 Description: Discovered a Slack Webhook, which could lead to unauthorized message posting and data leakage in Slack channels.
🔑 Secret: **********
🔗 Path: gitleaks-test-file1.sh:4

🔸 Rule: stripe-access-token
📄 File: semgrep-vulns.py:6
📝 Description: Found a Stripe Access Token, posing a risk to payment processing services and sensitive financial data.
🔑 Secret: **********
🔗 Path: semgrep-vulns.py:6

@github-actions

Copy link
Copy Markdown

🔐 Gitleaks Findings: 2 issue(s) detected

🔸 Rule: slack-webhook-url
📄 File: gitleaks-test-file1.sh:null
📝 Description: Discovered a Slack Webhook, which could lead to unauthorized message posting and data leakage in Slack channels.
🔑 Secret: **********
🔗 Path: gitleaks-test-file1.sh:null

🔸 Rule: stripe-access-token
📄 File: semgrep-vulns.py:null
📝 Description: Found a Stripe Access Token, posing a risk to payment processing services and sensitive financial data.
🔑 Secret: **********
🔗 Path: semgrep-vulns.py:null

@github-actions

Copy link
Copy Markdown

GoSec Findings: No issues found, Good to merge.

@github-actions

Copy link
Copy Markdown

Semgrep-new findings: Issues are found, Please resolve the issues before merging.

@github-actions

Copy link
Copy Markdown

🛡️ Semgrep Findings — 1 issue(s) found

Showing first 3 findings below. [Download full JSON report to view all findings from Artifacts in summary.]


⚠️ Issue 1 — ERROR

📄 semgrep-vulns.py:14
🔗 View in PR
📘 Rule Documentation
💬 "Found 'subprocess' function 'call' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead."


@github-actions

Copy link
Copy Markdown

🔐 Gitleaks Findings: 1 issue(s) detected

🔸 Rule: stripe-access-token
📄 File: semgrep-vulns.py:null
📝 Description: Found a Stripe Access Token, posing a risk to payment processing services and sensitive financial data.
🔑 Secret: **********
🔗 Path: semgrep-vulns.py:null

@github-actions

Copy link
Copy Markdown

🔐 Gitleaks docker Findings: 2 issue(s) detected

🔸 Rule: slack-webhook-url
📄 File: gitleaks-test-file1.sh:4
📝 Description: Discovered a Slack Webhook, which could lead to unauthorized message posting and data leakage in Slack channels.
🔑 Secret: **********
🔗 Path: gitleaks-test-file1.sh:4

🔸 Rule: stripe-access-token
📄 File: semgrep-vulns.py:6
📝 Description: Found a Stripe Access Token, posing a risk to payment processing services and sensitive financial data.
🔑 Secret: **********
🔗 Path: semgrep-vulns.py:6

@github-actions

Copy link
Copy Markdown

🔐 Gitleaks Findings: 2 issue(s) detected

🔸 Rule: stripe-access-token
📄 File: semgrep-vulns.py:null
📝 Description: Found a Stripe Access Token, posing a risk to payment processing services and sensitive financial data.
🔑 Secret: **********
🔗 Path: semgrep-vulns.py:null

🔸 Rule: slack-webhook-url
📄 File: gitleaks-test-file1.sh:null
📝 Description: Discovered a Slack Webhook, which could lead to unauthorized message posting and data leakage in Slack channels.
🔑 Secret: **********
🔗 Path: gitleaks-test-file1.sh:null

@github-actions

Copy link
Copy Markdown

GoSec Findings: No issues found, Good to merge.

@github-actions

Copy link
Copy Markdown

Semgrep-new findings: Issues are found, Please resolve the issues before merging.

@github-actions

Copy link
Copy Markdown

🛡️ Semgrep Findings — 1 issue(s) found

Showing first 3 findings below. [Download full JSON report to view all findings from Artifacts in summary.]


⚠️ Issue 1 — ERROR

📄 semgrep-vulns.py:14
🔗 View in PR
📘 Rule Documentation
💬 "Found 'subprocess' function 'call' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead."


@github-actions

Copy link
Copy Markdown

🔐 Gitleaks Findings: 2 issue(s) detected

🔸 Rule: slack-webhook-url
📄 File: gitleaks-test-file1.sh:null
📝 Description: Discovered a Slack Webhook, which could lead to unauthorized message posting and data leakage in Slack channels.
🔑 Secret: **********
🔗 Path: gitleaks-test-file1.sh:null

🔸 Rule: stripe-access-token
📄 File: semgrep-vulns.py:null
📝 Description: Found a Stripe Access Token, posing a risk to payment processing services and sensitive financial data.
🔑 Secret: **********
🔗 Path: semgrep-vulns.py:null

@github-actions

Copy link
Copy Markdown

🔐 Gitleaks Findings: 1 issue(s) detected

🔸 Rule: stripe-access-token
📄 File: semgrep-vulns.py:null
📝 Description: Found a Stripe Access Token, posing a risk to payment processing services and sensitive financial data.
🔑 Secret: **********
🔗 Path: semgrep-vulns.py:null

@github-actions

Copy link
Copy Markdown

🔐 Gitleaks docker Findings: 2 issue(s) detected

🔸 Rule: slack-webhook-url
📄 File: gitleaks-test-file1.sh:4
📝 Description: Discovered a Slack Webhook, which could lead to unauthorized message posting and data leakage in Slack channels.
🔑 Secret: **********
🔗 Path: gitleaks-test-file1.sh:4

🔸 Rule: stripe-access-token
📄 File: semgrep-vulns.py:6
📝 Description: Found a Stripe Access Token, posing a risk to payment processing services and sensitive financial data.
🔑 Secret: **********
🔗 Path: semgrep-vulns.py:6

@github-actions

Copy link
Copy Markdown

GoSec Findings: No issues found, Good to merge.

@github-actions

Copy link
Copy Markdown

Semgrep-new findings: Issues are found, Please resolve the issues before merging.

@github-actions

Copy link
Copy Markdown

🛡️ Semgrep Findings — 1 issue(s) found

Showing first 3 findings below. [Download full JSON report to view all findings from Artifacts in summary.]


⚠️ Issue 1 — ERROR

📄 semgrep-vulns.py:14
🔗 View in PR
📘 Rule Documentation
💬 "Found 'subprocess' function 'call' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead."


@github-actions

Copy link
Copy Markdown

🔐 Gitleaks Findings: 2 issue(s) detected

🔸 Rule: stripe-access-token
📄 File: semgrep-vulns.py:null
📝 Description: Found a Stripe Access Token, posing a risk to payment processing services and sensitive financial data.
🔑 Secret: **********
🔗 Path: semgrep-vulns.py:null

🔸 Rule: slack-webhook-url
📄 File: gitleaks-test-file1.sh:null
📝 Description: Discovered a Slack Webhook, which could lead to unauthorized message posting and data leakage in Slack channels.
🔑 Secret: **********
🔗 Path: gitleaks-test-file1.sh:null

@github-actions

Copy link
Copy Markdown

🔐 Gitleaks docker Findings: 2 issue(s) detected

🔸 Rule: slack-webhook-url
📄 File: gitleaks-test-file1.sh:4
📝 Description: Discovered a Slack Webhook, which could lead to unauthorized message posting and data leakage in Slack channels.
🔑 Secret: **********
🔗 Path: gitleaks-test-file1.sh:4

🔸 Rule: stripe-access-token
📄 File: semgrep-vulns.py:6
📝 Description: Found a Stripe Access Token, posing a risk to payment processing services and sensitive financial data.
🔑 Secret: **********
🔗 Path: semgrep-vulns.py:6

@github-actions

Copy link
Copy Markdown

🔐 Gitleaks Findings: 1 issue(s) detected

🔸 Rule: stripe-access-token
📄 File: semgrep-vulns.py:null
📝 Description: Found a Stripe Access Token, posing a risk to payment processing services and sensitive financial data.
🔑 Secret: **********
🔗 Path: semgrep-vulns.py:null

@github-actions

Copy link
Copy Markdown

GoSec Findings: No issues found, Good to merge.

@github-actions

Copy link
Copy Markdown

Semgrep-new findings: Issues are found, Please resolve the issues before merging.

@github-actions

Copy link
Copy Markdown

🛡️ Semgrep Findings — 1 issue(s) found

Showing first 3 findings below. [Download full JSON report to view all findings from Artifacts in summary.]


⚠️ Issue 1 — ERROR

📄 semgrep-vulns.py:14
🔗 View in PR
📘 Rule Documentation
💬 "Found 'subprocess' function 'call' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead."


@github-actions

Copy link
Copy Markdown

🔐 Gitleaks Findings: 2 issue(s) detected

🔸 Rule: stripe-access-token
📄 File: semgrep-vulns.py:null
📝 Description: Found a Stripe Access Token, posing a risk to payment processing services and sensitive financial data.
🔑 Secret: **********
🔗 Path: semgrep-vulns.py:null

🔸 Rule: slack-webhook-url
📄 File: gitleaks-test-file1.sh:null
📝 Description: Discovered a Slack Webhook, which could lead to unauthorized message posting and data leakage in Slack channels.
🔑 Secret: **********
🔗 Path: gitleaks-test-file1.sh:null

@github-actions

Copy link
Copy Markdown

🔐 Gitleaks Findings: 1 issue(s) detected

🔸 Rule: stripe-access-token
📄 File: semgrep-vulns.py:null
📝 Description: Found a Stripe Access Token, posing a risk to payment processing services and sensitive financial data.
🔑 Secret: **********
🔗 Path: semgrep-vulns.py:null

@github-actions

Copy link
Copy Markdown

🔐 Gitleaks docker Findings: 2 issue(s) detected

🔸 Rule: slack-webhook-url
📄 File: gitleaks-test-file1.sh:4
📝 Description: Discovered a Slack Webhook, which could lead to unauthorized message posting and data leakage in Slack channels.
🔑 Secret: **********
🔗 Path: gitleaks-test-file1.sh:4

🔸 Rule: stripe-access-token
📄 File: semgrep-vulns.py:6
📝 Description: Found a Stripe Access Token, posing a risk to payment processing services and sensitive financial data.
🔑 Secret: **********
🔗 Path: semgrep-vulns.py:6

@github-actions

Copy link
Copy Markdown

GoSec Findings: No issues found, Good to merge.

@github-actions

Copy link
Copy Markdown

Semgrep-new findings: Issues are found, Please resolve the issues before merging.

@github-actions

Copy link
Copy Markdown

🛡️ Semgrep Findings — 5 issue(s) found

Showing first 3 findings below. [Download full JSON report to view all findings from Artifacts in summary.]


⚠️ Issue 1 — WARNING

📄 cloud_run/skyflow/main.go:1246
🔗 View in PR
📘 Rule Documentation
💬 "Detected directly writing or similar in 'http.ResponseWriter.write()'. This bypasses HTML escaping that prevents cross-site scripting vulnerabilities. Instead, use the 'html/template' package and render data using 'template.Execute()'."


⚠️ Issue 2 — WARNING

📄 cloud_run/skyflow/main.go:1250
🔗 View in PR
📘 Rule Documentation
💬 "File creation in shared tmp directory without using io.CreateTemp."


⚠️ Issue 3 — WARNING

📄 cloud_run/skyflow/main.go:1257
🔗 View in PR
📘 Rule Documentation
💬 "Found an HTTP server without TLS. Use 'http.ListenAndServeTLS' instead. See https://golang.org/pkg/net/http/#ListenAndServeTLS for more information."


⚠️ Issue 4 — WARNING

📄 semgrep-vulns.py:10
🔗 View in PR
📘 Rule Documentation
💬 "Detected the use of eval(). eval() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources."


⚠️ Issue 5 — WARNING

📄 semgrep-vulns.py:19
🔗 View in PR
📘 Rule Documentation
💬 "Avoid using pickle, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format."


Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant