Comments (5)
Thanks @ajh-
- Did this happen for only one policy?
- Can you paste a few lines above the remediation steps (starting from the policy title)
- Can you attach logs?
from legitify.
@ajh- thanks to @sagic-orca your bug was fixed in version 1.0.9.
from legitify.
@royb-legit @sagic-orca thanks for taking this on. I should've been more specific upfront. This happens for all policies when outputted as markdown. Unfortunately, just tested v1.0.9 and still have the same issue.
I'm assuming applying @sagic-orca's fix to formatter_markdown.go
should also remediate my current issue?
from legitify.
@ajh- thanks for resurfacing this.
Version 1.0.10 should fix it, could you please check it?
from legitify.
@royb-legit Perfect, just tested it and it looks like it is fixed. Thanks!
I will add, with this formatting update, the blockquote section is now displayed as multiple sections instead of being one contiguous section. Not the end of the world, but just wanted to let you know.
For example:
Default Branch Should Require Code Review ⛔
In order to comply with separation of duties principle and enforce secure code practices, a code review should be mandatory using the source-code-management system's built-in enforcement. This option is found in the branch protection setting of the repository.
Policy Name: code_review_not_required
Namespace: repository
Severity: HIGH ⛔Threat:
- Users can merge code without being reviewed, which can lead to insecure code reaching the main branch and production.
Remediation Steps:
Note: The remediation steps apply to legacy branch protections, rules set-based protection should be updated from the rules set page
- Make sure you have admin permissions
- Go to the repo's settings page
- Enter 'Branches' tab
- Under 'Branch protection rules'
- Click 'Edit' on the default branch rule
- Check 'Require a pull request before merging'
- Check 'Require approvals'
- Set 'Required number of approvals before merging' to 1 or more
- Click 'Save changes'
Violations:
Link to repository: https://test.com/test
Auxiliary Info:
- Entity Id: 77
- Entity Name: test
from legitify.
Related Issues (20)
- Report Script HOT 1
- Policy Skip Support for GitHub Action HOT 1
- Parameterize output report name in GH action HOT 2
- legitify analyze --repo doesn't support gitlab projects within subgroups HOT 5
- When the "ignore-policies" option is enabled, GitHub Action disregards the "extra" parameter HOT 4
- SARIF format results do no supply the actual violation results? HOT 2
- legitify doesn't support nested GitLab projects completely HOT 8
- "organization_has_too_many_admins" policy doesn't flag an organization with 8 owners HOT 5
- Add the needed permissions/scopes to the custom action documentation HOT 4
- Running the GitHub action with ` scorecard: verbose` fails with error `failed to enrich scorecard: expecting []ScorecardCheck` HOT 1
- Support using legitify action with GITHUB_TOKEN HOT 1
- 1.0.5 release did not get completed HOT 2
- "Reaching out" Message comes with every usage of legitify convert HOT 1
- Unmet prerequisite: premium, but premium license is used HOT 6
- Restricting email notifications (GitHub) HOT 2
- Skip evaluating archived GitHub repos in an org HOT 2
- GHA - unable to add extra: --namespace -unknown flag HOT 2
- GitHub Ruleset awareness HOT 1
- Gitlab group license discovery fails with 1.0.8 HOT 2
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from legitify.