From b22b79c209304645b2f335b5bdbf16bdc550ffdd Mon Sep 17 00:00:00 2001 From: qwietdemouser <130526760+qwietdemouser@users.noreply.github.com> Date: Mon, 17 Apr 2023 20:03:51 -0400 Subject: [PATCH 1/6] Create qwiet.yml --- .github/workflows/qwiet.yml | 52 +++++++++++++++++++++++++++++++++++++ 1 file changed, 52 insertions(+) create mode 100644 .github/workflows/qwiet.yml diff --git a/.github/workflows/qwiet.yml b/.github/workflows/qwiet.yml new file mode 100644 index 00000000..edbf014e --- /dev/null +++ b/.github/workflows/qwiet.yml @@ -0,0 +1,52 @@ +--- +# This workflow integrates ShiftLeft NG SAST with GitHub +# Visit https://docs.shiftleft.io for help +name: ShiftLeft + +on: + push: + branches: + - main + - master + pull_request: + workflow_dispatch: + +jobs: + NextGen-Static-Analyis: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v2 + # We are building this application with Java 11 + - name: Setup Java JDK + uses: actions/setup-java@v1.4.3 + with: + java-version: 11.0.x + - name: Build and package with Maven + run: mvn clean package -DskipTests + - name: Download ShiftLeft CLI + run: | + curl https://cdn.shiftleft.io/download/sl > ${GITHUB_WORKSPACE}/sl && chmod a+rx ${GITHUB_WORKSPACE}/sl + # ShiftLeft requires Java 1.8. Post the package step override the version + - name: Setup Java JDK + uses: actions/setup-java@v1.4.3 + with: + java-version: 1.8 + - name: Extract branch name + shell: bash + run: echo "##[set-output name=branch;]$(echo ${GITHUB_REF#refs/heads/})" + id: extract_branch + - name: NextGen Static Analysis + run: ${GITHUB_WORKSPACE}/sl analyze --wait --app java-sec-code --tag branch=${{ github.head_ref || steps.extract_branch.outputs.branch }} --remediation-config remediation.yaml --vcs-prefix-correction "*=/src/main/java" --java ./target/java-sec-code-1.0.0.jar + env: + SHIFTLEFT_ACCESS_TOKEN: ${{ secrets.SHIFTLEFT_ACCESS_TOKEN }} + + - name: Validate Build Rules + run: | + ${GITHUB_WORKSPACE}/sl check-analysis --v2 --app java-sec-code \ + --report \ + --github-pr-number=${{github.event.number}} \ + --github-pr-user=${{ github.repository_owner }} \ + --github-pr-repo=${{ github.event.repository.name }} \ + --github-token=${{ secrets.GITHUB_TOKEN }} + env: + SHIFTLEFT_ACCESS_TOKEN: ${{ secrets.SHIFTLEFT_ACCESS_TOKEN }} From 1edca5a9da325ba044aec62d279dab512f1270dc Mon Sep 17 00:00:00 2001 From: qwietdemouser <130526760+qwietdemouser@users.noreply.github.com> Date: Mon, 17 Apr 2023 20:09:30 -0400 Subject: [PATCH 2/6] Update qwiet.yml --- .github/workflows/qwiet.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/qwiet.yml b/.github/workflows/qwiet.yml index edbf014e..e1d5311e 100644 --- a/.github/workflows/qwiet.yml +++ b/.github/workflows/qwiet.yml @@ -36,7 +36,7 @@ jobs: run: echo "##[set-output name=branch;]$(echo ${GITHUB_REF#refs/heads/})" id: extract_branch - name: NextGen Static Analysis - run: ${GITHUB_WORKSPACE}/sl analyze --wait --app java-sec-code --tag branch=${{ github.head_ref || steps.extract_branch.outputs.branch }} --remediation-config remediation.yaml --vcs-prefix-correction "*=/src/main/java" --java ./target/java-sec-code-1.0.0.jar + run: ${GITHUB_WORKSPACE}/sl analyze --wait --app java-sec-code --tag branch=${{ github.head_ref || steps.extract_branch.outputs.branch }} --vcs-prefix-correction "*=/src/main/java" --java ./target/java-sec-code-1.0.0.jar env: SHIFTLEFT_ACCESS_TOKEN: ${{ secrets.SHIFTLEFT_ACCESS_TOKEN }} From 25e1a03aac510583ed70756d1fa40886f8f32e02 Mon Sep 17 00:00:00 2001 From: qwietdemouser <130526760+qwietdemouser@users.noreply.github.com> Date: Mon, 17 Apr 2023 20:20:06 -0400 Subject: [PATCH 3/6] Update SSRF.java --- src/main/java/org/joychou/controller/SSRF.java | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/main/java/org/joychou/controller/SSRF.java b/src/main/java/org/joychou/controller/SSRF.java index f28b8b91..a1a631d9 100644 --- a/src/main/java/org/joychou/controller/SSRF.java +++ b/src/main/java/org/joychou/controller/SSRF.java @@ -2,7 +2,7 @@ import cn.hutool.http.HttpUtil; import org.joychou.security.SecurityUtil; -import org.joychou.security.ssrf.SSRFException; +//import org.joychou.security.ssrf.SSRFException; import org.joychou.service.HttpService; import org.joychou.util.HttpUtils; import org.joychou.util.WebUtils; From 95adf0f65313de5eb1c29a800996a1a210e30c8d Mon Sep 17 00:00:00 2001 From: qwietdemouser <130526760+qwietdemouser@users.noreply.github.com> Date: Mon, 17 Apr 2023 20:22:36 -0400 Subject: [PATCH 4/6] Update SSRF.java --- src/main/java/org/joychou/controller/SSRF.java | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/main/java/org/joychou/controller/SSRF.java b/src/main/java/org/joychou/controller/SSRF.java index a1a631d9..f28b8b91 100644 --- a/src/main/java/org/joychou/controller/SSRF.java +++ b/src/main/java/org/joychou/controller/SSRF.java @@ -2,7 +2,7 @@ import cn.hutool.http.HttpUtil; import org.joychou.security.SecurityUtil; -//import org.joychou.security.ssrf.SSRFException; +import org.joychou.security.ssrf.SSRFException; import org.joychou.service.HttpService; import org.joychou.util.HttpUtils; import org.joychou.util.WebUtils; From e15dc18ad62fa418cf2e55a7f906e88012a1e5ed Mon Sep 17 00:00:00 2001 From: qwietdemouser <130526760+qwietdemouser@users.noreply.github.com> Date: Mon, 17 Apr 2023 20:29:53 -0400 Subject: [PATCH 5/6] Update SSRF.java --- src/main/java/org/joychou/controller/SSRF.java | 1 + 1 file changed, 1 insertion(+) diff --git a/src/main/java/org/joychou/controller/SSRF.java b/src/main/java/org/joychou/controller/SSRF.java index f28b8b91..94e2bff1 100644 --- a/src/main/java/org/joychou/controller/SSRF.java +++ b/src/main/java/org/joychou/controller/SSRF.java @@ -1,3 +1,4 @@ +//TestPackage package org.joychou.controller; import cn.hutool.http.HttpUtil; From cf3b4d1bcd0ae061a532acf1c362fab14c76950b Mon Sep 17 00:00:00 2001 From: qwietdemouser <130526760+qwietdemouser@users.noreply.github.com> Date: Mon, 17 Apr 2023 20:50:38 -0400 Subject: [PATCH 6/6] Update SSRF.java --- src/main/java/org/joychou/controller/SSRF.java | 1 - 1 file changed, 1 deletion(-) diff --git a/src/main/java/org/joychou/controller/SSRF.java b/src/main/java/org/joychou/controller/SSRF.java index 94e2bff1..f28b8b91 100644 --- a/src/main/java/org/joychou/controller/SSRF.java +++ b/src/main/java/org/joychou/controller/SSRF.java @@ -1,4 +1,3 @@ -//TestPackage package org.joychou.controller; import cn.hutool.http.HttpUtil;