-
Notifications
You must be signed in to change notification settings - Fork 2.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Security Policy violation Binary Artifacts #14721
Comments
@JamieMagee @viceice do you think we're justified in ignoring it? |
Maybe... If yes, we might open an issue upstream asking if we can configure ignore patterns. If no, we should see if there is an alternative to having gradle files in the repo |
We should ignore them. |
There are issues asking for ignore lists already: |
Seems like Maybe we could make |
Updating issue after ping interval. Status: Rule Description Remediation Steps Artifacts Found
Additional Information |
2 similar comments
Updating issue after ping interval. Status: Rule Description Remediation Steps Artifacts Found
Additional Information |
Updating issue after ping interval. Status: Rule Description Remediation Steps Artifacts Found
Additional Information |
FYI I've now suspended this app due to the noise caused by this false positive |
You can also simply remove subscription hen no more notifications will be sent. 😅 |
I spoke with @jeffmendoza, and it should now1 be possible to set an ignore list of files. If I am reading the documentation correctly, we need to add a IgnorePaths:
- ...
- ... Footnotes |
This issue was automatically created by Allstar.
Security Policy Violation
Project is out of compliance with Binary Artifacts policy: binaries present in source code
Rule Description
Binary Artifacts are an increased security risk in your repository. Binary artifacts cannot be reviewed, allowing the introduction of possibly obsolete or maliciously subverted executables. For more information see the Security Scorecards Documentation for Binary Artifacts.
Remediation Steps
To remediate, remove the generated executable artifacts from the repository.
Artifacts Found
Additional Information
This policy is drawn from Security Scorecards, which is a tool that scores a project's adherence to security best practices. You may wish to run a Scorecards scan directly on this repository for more details.
This issue will auto resolve when the policy is in compliance.
Issue created by Allstar. See https://github.com/ossf/allstar/ for more information. For questions specific to the repository, please contact the owner or maintainer.
The text was updated successfully, but these errors were encountered: