关于 GitSecure
GitSecure 是一个 GitHub Action,可用于在推送和拉取请求中警告安全团队任何暴露的 API 密钥。当在 GitHub 仓库中添加或修改文件时,此操作将被触发,并开始在系统中寻找暴露的凭据。找到令牌后,它将通过 Slack Webhook 通知团队。
设置
GitSecure 的设置很简单,不需要太多麻烦。
你可以通过访问 https://api.slack.com 并创建一个应用来创建 Slack Webhook。创建应用时,选择其为传入 Webhook,并将 Webhook 安装到你希望接收警报的频道上。
安装 Webhook 后,复制 Slack 提供的 URL。你只需要复制 https://hooks.slack.com/services/ 之后的内容。
GitHub Actions 使用机密来防止敏感信息泄露。前往你的仓库设置,点击"Secrets"。在那里创建一个机密,并将上面复制的 Webhook 部分粘贴到值中。
要设置一个 Action,在Pull Requests旁边点击Actions。在设置中点击Setup a Workflow Yourself。粘贴以下 YAML 描述:
on:
push:
branches:
- master
jobs:
detect_tests:
runs-on: ubuntu-latest
name: A workflow to test the work of DataSecure
steps:
- name: Checkout
uses: actions/checkout@v1
- name: CodeAnalysis
uses: bugbounty-site/GitSecure@master
with:
slack_hook: ${{ secrets.slack_webhook }}
将 slack_webhook 更改为你在设置中创建的机密名称。