Skip to content

Secret management - #471

Open
Ravindu-orzo wants to merge 27 commits into
OWASP:masterfrom
Ravindu-orzo:IT24103645
Open

Ravindu-orzo wants to merge 27 commits into
OWASP:masterfrom
Ravindu-orzo:IT24103645

Conversation

@Ravindu-orzo

Copy link
Copy Markdown

No description provided.

Ravindu-orzo and others added 27 commits August 23, 2026 05:31
Updated Node.js version and repository URL in setup instructions.
Clarified setup instructions for NodeGoat, emphasizing the use of IntelliJ Ultimate and SSH key setup for GitHub.
Updated instructions for running NodeGoat and MongoDB.
Updated comments for clarity regarding the scanning processes and their implications.
Updated GitHub Actions workflow to use newer versions of actions and added Semgrep installation step.
Updated Node.js version in the workflow configuration.
If this causes issues then revert to the commit before this
Updated DAST scanning step to use Docker Compose for starting the NodeGoat application and added waiting logic.
Added permissions for DAST scan to write results to GitHub issues.
Fix IDOR vulnerability in allocations route
Fix NoSQL injection in allocations-dao (CWE-943)
Added secrets scanning step using Gitleaks CLI before npm ci to catch existing secrets in files.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants