SecureSECO / SearchSECOController

GNU Affero General Public License v3.0
6 stars 8 forks source link

Project Selection #24

Open slingerbv opened 2 years ago

slingerbv commented 2 years ago

To check whether a project has already been uploaded the controller asks for the most recent version of the project. This however does not mean that all previous versions have been uploaded, or that this is a complete version, as it might be a vulnerability. It would be good to implement a better check by retrieving all versions and checking whether the exact version is already in the database, instead of a newer one.

slingerbv commented 2 years ago

Ah, so to clarify:

This is especially relevant for jobs that never finished before, but due to bug fixing have now become finishable.

ethzx commented 2 years ago

How do I run SecureSECO? Is there any documentation to refer to?

slingerbv commented 2 years ago

Yes, I use the docker way, but there are other ways as well. All can be found here: https://github.com/SecureSECO/SearchSECOController

In the read.me

On Sun, Aug 28, 2022 at 7:31 AM ethzx @.***> wrote:

How do I run SecureSECO? Is there any documentation to refer to?

— Reply to this email directly, view it on GitHub https://github.com/SecureSECO/SearchSECOController/issues/24#issuecomment-1229380384, or unsubscribe https://github.com/notifications/unsubscribe-auth/AAERHLD4DRKDAT24CWTUMSLV3L2RHANCNFSM57AXCTBA . You are receiving this because you authored the thread.Message ID: @.***>

-- dr. Slinger Jansen (Roijackers) Do you want to secure software ecosystems https://secureseco.org/ with us? Software Production Research Group https://www.uu.nl/en/research/software-systems/organization-and-information , Utrecht University http://www.slingerjansen.nl +31 6 19 884 880 book me through YouCanBook.me http://slingerroijackers.YouCanBook.me

ethzx commented 2 years ago

image But when try to run docker-compose -f [docker-compose.yml](https://github.com/SecureSECO/SearchSECODatabaseAPI/blob/master/docker-compose.yml) up, I got it.

slingerbv commented 2 years ago

Not sure if I understand your question. I just use:

docker run --name controller-container -e "github_token=[mytoken]" -e "worker_name=YourWorkerName" searchseco/controller

Feel free to approach https://github.com/SecureSECO/SearchSECOController/commits?author=musicismyalibi for any questions.

Slinger

On Tue, Aug 30, 2022 at 2:51 PM ethzx @.***> wrote:

[image: image] https://user-images.githubusercontent.com/112263510/187440912-dbcaac00-692c-4236-9332-36e9e21f8533.png But when try to run docker-compose -f docker-compose.yml up, I got it.

— Reply to this email directly, view it on GitHub https://github.com/SecureSECO/SearchSECOController/issues/24#issuecomment-1231624129, or unsubscribe https://github.com/notifications/unsubscribe-auth/AAERHLBKEPDWFHGFK7QJDM3V3X7VTANCNFSM57AXCTBA . You are receiving this because you authored the thread.Message ID: @.***>

-- dr. Slinger Jansen (Roijackers) Do you want to secure software ecosystems https://secureseco.org/ with us? Software Production Research Group https://www.uu.nl/en/research/software-systems/organization-and-information , Utrecht University http://www.slingerjansen.nl +31 6 19 884 880 book me through YouCanBook.me http://slingerroijackers.YouCanBook.me

ethzx commented 2 years ago

Thanks, I already ran it.

gitcoinbot commented 2 years ago

Issue Status: 1. Open 2. Started 3. Submitted 4. Done


Workers have applied to start work.

These users each claimed they can complete the work by 3 weeks, 1 day from now. Please review their action plans below:

1) richelleji has applied to start work _(Funders only: approve worker | reject worker)_.

Hey I am interested in this bounty, is there a github issue where we could learn more? 2) kiranraoboinapally has applied to start work _(Funders only: approve worker | reject worker)_.

Hey there can i have access give me a chance let me try

Learn more on the Gitcoin Issue Details page.

danishyasin33 commented 1 year ago

Hi @slingerbv,

Is this issue still relevant? If so, I can work on it.

I understand that you want the project versions to be matched more accurately rather than just matching with the most recent.

It's a simple enough fix that'll involve extracting all versions of the project in an array then matching them with the versions that have already been mined.

I can work on this task and get it done fairly quickly. For some reason, I am unable to apply on GitCoin.

Thank you

slingerbv commented 1 year ago

The bounty's been reopened on Gitcoin.

On Tue, Oct 11, 2022 at 11:02 AM Danish Yasin @.***> wrote:

Hi @slingerbv https://github.com/slingerbv,

Is this issue still relevant? If so, I can work on it.

I understand that you want the project versions to be matched more accurately rather than just matching with the most recent.

It's a simple enough fix that'll involve extracting all versions of the project in an array then matching them with the versions that have already been mined.

I can work on this task and get it done fairly quickly. For some reason, I am unable to apply on GitCoin.

Thank you

— Reply to this email directly, view it on GitHub https://github.com/SecureSECO/SearchSECOController/issues/24#issuecomment-1274353867, or unsubscribe https://github.com/notifications/unsubscribe-auth/AAERHLF7Y6HOQGC7ON2Y4QLWCUUJPANCNFSM57AXCTBA . You are receiving this because you were mentioned.Message ID: @.***>

-- dr. Slinger Jansen (Roijackers) Do you want to secure software ecosystems https://secureseco.org/ with us? Software Production Research Group https://www.uu.nl/en/research/software-systems/organization-and-information , Utrecht University http://www.slingerjansen.nl +31 6 19 884 880 book me through YouCanBook.me http://slingerroijackers.YouCanBook.me

danishyasin33 commented 1 year ago

Hi @slingerbv,

Is paypal the only acceptable payment method for bounties? I would love to work on this but do not have PayPal.

Have you heard of wise?

slingerbv commented 1 year ago

Hi Danish,

I'm experimenting with Eth these days, so we can change the bounty to that if you wish.

Slinger

On Wed, Oct 12, 2022 at 11:28 PM Danish Yasin @.***> wrote:

Hi @slingerbv https://github.com/slingerbv,

Is paypal the only acceptable payment method for bounties? I would love to work on this but do not have PayPal.

Have you heard of wise?

— Reply to this email directly, view it on GitHub https://github.com/SecureSECO/SearchSECOController/issues/24#issuecomment-1276755263, or unsubscribe https://github.com/notifications/unsubscribe-auth/AAERHLEUS2EBR33DVEKISYTWC4UP5ANCNFSM57AXCTBA . You are receiving this because you were mentioned.Message ID: @.***>

-- dr. Slinger Jansen (Roijackers) Do you want to secure software ecosystems https://secureseco.org/ with us? Software Production Research Group https://www.uu.nl/en/research/software-systems/organization-and-information , Utrecht University http://www.slingerjansen.nl +31 6 19 884 880 book me through YouCanBook.me http://slingerroijackers.YouCanBook.me

danishyasin33 commented 1 year ago

Hi @slingerbv,

Unfortunately that won't work.

Can we not use the conventional channels?

slingerbv commented 1 year ago

Sure.