Skip to content

Add Open Redirect Fix and DevSecOps Security Scanning - #470

Open
IT24102493 wants to merge 37 commits into
OWASP:masterfrom
Thakshila05:member4/security-scanning
Open

IT24102493 wants to merge 37 commits into
OWASP:masterfrom
Thakshila05:member4/security-scanning

Conversation

@IT24102493

Copy link
Copy Markdown

Description

This pull request implements the Member 4 security improvements for the NodeGoat DevSecOps project.

Changes Made

  • Fixed the Open Redirect vulnerability in the /learn route.
  • Added Semgrep SAST scanning to identify source-code security issues.
  • Added Gitleaks secret scanning to detect exposed secrets and private keys.
  • Added Trivy container vulnerability scanning with HIGH/CRITICAL severity enforcement.
  • Added dependency security auditing using npm audit.
  • Added .env.example for safe environment variable configuration.
  • Updated .gitignore and .dockerignore to prevent sensitive files from being included.
  • Removed the exposed private key from the Docker build context.
  • Updated the Dockerfile with ca-certificates to support secure package installation.
  • Integrated the security checks into the GitHub Actions DevSecOps pipeline.

Testing

  • Verified the Open Redirect exploit before the fix.
  • Verified the malicious redirect was blocked after the fix.
  • Ran Semgrep before and after the fix.
  • Ran Gitleaks secret scanning.
  • Ran Trivy against the Docker image.
  • Verified that the Trivy HIGH/CRITICAL security gate can detect vulnerabilities.

Branch

member4/security-scanning

ThakshilaUddeepana and others added 30 commits September 23, 2026 09:07
Add local Docker setup documentation and architecture
Prevent server-side JavaScript injection in contributions
Fix ReDoS in bank routing validation

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants