bitwarden / directory-connector

A tool for syncing a directory (AD, LDAP, Azure, G Suite, Okta) to an organization.
https://bitwarden.com
GNU General Public License v3.0
249 stars 84 forks source link

DEVOPS-1800 - Migrate Secrets #461

Closed vgrassia closed 6 months ago

vgrassia commented 6 months ago

Type of change

- [ ] Bug fix
- [ ] New feature development
- [ ] Tech debt (refactoring, code cleanup, dependency upgrades, etc)
- [X] Build/deploy pipeline (DevOps)
- [ ] Other

Objective

This PR removes the .github/secrets directory and moves all of the certificates to the bitwarden-ci Key Vault.

Code changes

Before you submit

bitwarden-bot commented 6 months ago

Logo Checkmarx One – Scan Summary & Detailsf8613fdb-204b-4829-ba46-05c858731f0c

New Issues

Severity Issue Source File / Package Checkmarx Insight
MEDIUM SSRF /src/services/onelogin-directory.service.ts: 178 Attack Vector
MEDIUM Unpinned Actions Full Length Commit SHA /build.yml: 664 Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...

Fixed Issues

Severity Issue Source File / Package
MEDIUM Unpinned Actions Full Length Commit SHA /build.yml: 665
LOW Use_of_Broken_or_Risky_Cryptographic_Algorithm /jslib/node/src/services/nodeCryptoFunction.service.ts: 138
LOW Use_of_Broken_or_Risky_Cryptographic_Algorithm /jslib/node/src/services/nodeCryptoFunction.service.ts: 178
LOW Use_of_Broken_or_Risky_Cryptographic_Algorithm /jslib/node/src/services/nodeCryptoFunction.service.ts: 99
LOW Use_of_Broken_or_Risky_Cryptographic_Algorithm /jslib/node/src/services/nodeCryptoFunction.service.ts: 87
LOW Use_of_Broken_or_Risky_Cryptographic_Algorithm /jslib/node/src/services/nodeCryptoFunction.service.ts: 21