Skip to content

Commit

Permalink
Merge pull request #474 from Privado-Inc/dev
Browse files Browse the repository at this point in the history
Release PR
  • Loading branch information
khemrajrathore committed Jul 1, 2024
2 parents cc92876 + d84a439 commit d41e353
Show file tree
Hide file tree
Showing 2 changed files with 25 additions and 0 deletions.
17 changes: 17 additions & 0 deletions .github/workflows/vulnerability-scan.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
name: Vulnerability Scan
on: pull_request_target
jobs:
security:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@master
with:
ref: ${{ github.head_ref }}
- run: docker build -t privado-main-oss -f Dockerfile .
- name: Run Snyk to check for vulnerabilities
uses: snyk/actions/docker@master
env:
SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
with:
image: privado-main-oss
args: --severity-threshold=high
8 changes: 8 additions & 0 deletions config/semantics/python.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
# 1->-1 => 1st parameter taints the return value
# 0->0 => 0th parameter taints itself back
# empty flow => no tainting done by method
# 1->-1 2->-1 => 1st and 2nd parameter both taints the return value

semantics:
- signature: "__builtin.len"
flow: "1->1"

0 comments on commit d41e353

Please sign in to comment.