Details
-
Type:
Task
-
Status: Resolved (View Workflow)
-
Priority:
Minor
-
Resolution: Fixed
-
Component/s: github
-
Labels:
-
Similar Issues:
Description
- https://github.com/jenkinsci/credentials-plugin
- https://github.com/jenkinsci/extended-security-settings-plugin
- https://github.com/jenkinsci/audit-log-plugin
- https://github.com/jenkinsci/jackson2-api-plugin
- https://github.com/jenkinsci/instance-identity-module
- https://github.com/jenkinsci/jenkins and https://github.com/jenkinsci/remoting
- https://github.com/jenkinsci/pam-auth-plugin
- https://github.com/jenkinsci/ssh-cli-auth-module
- https://github.com/jenkinsci/ssh-credentials-plugin
- https://github.com/jenkinsci/sshd-module
I'm not sure if any of these are worth enabling yet, but I also have access to the following which seem relevant:
- https://github.com/jenkinsci/domain-discovery-module
- https://github.com/jenkinsci/extras-executable-war
- https://github.com/jenkinsci/icon-shim-plugin
- https://github.com/jenkinsci/jna
- https://github.com/jenkinsci/launchd-slave-installer-module
- https://github.com/jenkinsci/lib-crypto-util
- https://github.com/jenkinsci/lib-version-number
- https://github.com/jenkinsci/lib-commons-httpclient
- https://github.com/jenkinsci/maven-hpi-plugin
- https://github.com/jenkinsci/slave-installer-module
- https://github.com/jenkinsci/systemd-slave-installer-module
- https://github.com/jenkinsci/upstart-slave-installer-module
- https://github.com/jenkinsci/windows-slave-installer-module
Thanks for signing up!
Release permissions only, not just committer access. Sorry.
Which means the following repos are signed up:
SSH Credentials and PAM Auth already were, the rest is new.
An initial scan is finished, and I added the repo(s) to the list for future re-scans.
Unresolved findings are shown with an "unread indicator" on the "Security" tab on each repo.
If you think a finding is a true positive security issue, please file those in the SECURITY tracker so we can review the fix and coordinate a release.
We're using GitHub's CodeQL as the tool for this, but only execute our own, Jenkins-specific queries. For general purpose queries, you can check out the plugin repos on lgtm.com, or add regular CodeQL code scanning to your plugins.
If you have questions or feedback, as a security team member, please file issues in jenkinsci-cert/codeql.