diff --git a/.github/CODE_OF_CONDUCT.md b/.github/CODE_OF_CONDUCT.md index 31cd3af9..3cd88395 100644 --- a/.github/CODE_OF_CONDUCT.md +++ b/.github/CODE_OF_CONDUCT.md @@ -1,10 +1,131 @@ -# Code of Conduct +# Contributor Covenant Code of Conduct -OpenShield is an open, welcoming project. +## Our Pledge -- Be respectful in all interactions -- No harassment, discrimination, or offensive language -- Constructive feedback only — critique code, not people -- All contributions welcome regardless of experience level +We as members, contributors, and leaders pledge to make participation in the +OpenShield community a harassment-free experience for everyone, regardless of +age, body size, visible or invisible disability, ethnicity, sex characteristics, +gender identity and expression, level of experience, education, socio-economic +status, nationality, personal appearance, race, caste, color, religion, or +sexual identity and orientation. -Violations can be reported to the maintainer directly via GitHub. \ No newline at end of file +We pledge to act and interact in ways that contribute to an open, welcoming, +diverse, inclusive, and healthy community. + +## Our Standards + +Examples of behavior that contributes to a positive environment: + +- Demonstrating empathy and kindness toward other people +- Being respectful of differing opinions, viewpoints, and experiences +- Giving and gracefully accepting constructive feedback +- Accepting responsibility and apologizing to those affected by our mistakes, + and learning from the experience +- Focusing on what is best not just for us as individuals, but for the overall + community + +Examples of unacceptable behavior: + +- The use of sexualized language or imagery, and sexual attention or advances of + any kind +- Trolling, insulting or derogatory comments, and personal or political attacks +- Public or private harassment +- Publishing others' private information, such as a physical or electronic + address, without their explicit permission +- Other conduct which could reasonably be considered inappropriate in a + professional setting + +## Enforcement Responsibilities + +Community leaders are responsible for clarifying and enforcing our standards of +acceptable behavior and will take appropriate and fair corrective action in +response to any behavior that they deem inappropriate, threatening, offensive, +or harmful. + +Community leaders have the right and responsibility to remove, edit, or reject +comments, commits, code, wiki edits, issues, and other contributions that are +not aligned to this Code of Conduct, and will communicate reasons for moderation +decisions when appropriate. + +## Scope + +This Code of Conduct applies within all community spaces, and also applies when +an individual is officially representing the community in public spaces. +Examples of representing our community include using an official email address, +posting via an official social media account, or acting as an appointed +representative at an online or offline event. + +## Enforcement + +Instances of abusive, harassing, or otherwise unacceptable behavior may be +reported to the project lead **Vishnu Ajith** at vishnu.ajith@owasp.org, +or contact OWASP directly at . Do not use the +security advisory channel for conduct reports. + +All complaints will be reviewed and investigated promptly and fairly. + +All community leaders are obligated to respect the privacy and security of the +reporter of any incident. + +## Enforcement Guidelines + +Community leaders will follow these Community Impact Guidelines in determining +the consequences for any action they deem in violation of this Code of Conduct: + +### 1. Correction + +**Community Impact:** Use of inappropriate language or other behavior deemed +unprofessional or unwelcome in the community. + +**Consequence:** A private, written warning from community leaders, providing +clarity around the nature of the violation and an explanation of why the +behavior was inappropriate. A public apology may be requested. + +### 2. Warning + +**Community Impact:** A violation through a single incident or series of +actions. + +**Consequence:** A warning with consequences for continued behavior. No +interaction with the people involved, including unsolicited interaction with +those enforcing the Code of Conduct, for a specified period of time. This +includes avoiding interactions in community spaces as well as external channels +like social media. Violating these terms may lead to a temporary or permanent +ban. + +### 3. Temporary Ban + +**Community Impact:** A serious violation of community standards, including +sustained inappropriate behavior. + +**Consequence:** A temporary ban from any sort of interaction or public +communication with the community for a specified period of time. No public or +private interaction with the people involved, including unsolicited interaction +with those enforcing the Code of Conduct, is allowed during this period. +Violating these terms may lead to a permanent ban. + +### 4. Permanent Ban + +**Community Impact:** Demonstrating a pattern of violation of community +standards, including sustained inappropriate behavior, harassment of an +individual, or aggression toward or disparagement of classes of individuals. + +**Consequence:** A permanent ban from any sort of public interaction within the +community. + +## Attribution + +This Code of Conduct is adapted from the [Contributor Covenant][homepage], +version 2.1, available at +[https://www.contributor-covenant.org/version/2/1/code_of_conduct/][v2.1]. + +Community Impact Guidelines were inspired by +[Mozilla's code of conduct enforcement ladder][Mozilla CoC]. + +For answers to common questions about this code of conduct, see the FAQ at +. Translations are available at +. + +[homepage]: https://www.contributor-covenant.org +[v2.1]: https://www.contributor-covenant.org/version/2/1/code_of_conduct/ +[Mozilla CoC]: https://github.com/mozilla/diversity diff --git a/.github/SECURITY.md b/.github/SECURITY.md index 315eebd2..f2a96bba 100644 --- a/.github/SECURITY.md +++ b/.github/SECURITY.md @@ -2,82 +2,94 @@ ## Reporting a Vulnerability -If you discover a security vulnerability in OpenShield, please **do not open a public GitHub issue**. -Opening a public issue exposes the vulnerability to bad actors before a fix is available. +**Do not open a public GitHub issue for security vulnerabilities.** +Email **vishnu.ajith@owasp.org** with your report. This is the current primary +channel while GitHub private vulnerability reporting (PVR) is being enabled for +this organization. -We will acknowledge your report within 48 hours and work with you to coordinate a fix and responsible disclosure timeline. +Once PVR is active, you will also be able to report via +[GitHub's private security advisory feature](https://github.com/OWASP/openshield/security/advisories/new). -### What to include in your report - -To help us triage quickly, please include: +Please include: - A description of the vulnerability and its potential impact -- The affected component (scanner engine, REST API, auth logic, playbooks) -- Steps to reproduce the issue -- Any relevant logs, proof-of-concept code, or screenshots -- The version of OpenShield you were testing (check `git log --oneline -1`) +- The affected component (scanner engine, REST API, auth logic, playbooks, sentinel) +- Steps to reproduce or a proof-of-concept (if available) +- Affected versions or components +- Any suggested fix (optional) -The more detail you provide, the faster we can respond. +### Response timeline ---- +| Stage | Target | +|---|---| +| Acknowledgement | Within 48 hours | +| Initial triage and severity assessment | Within 5 business days | +| Fix or mitigation | Depends on severity; critical issues within 14 days | +| Public disclosure | Coordinated with reporter after fix is merged | -## Supported Versions - -| Version | Supported | -|---------|-----------| -| 0.3.x | Yes | -| 0.1.x | No | - -Older versions are not patched unless a GitHub Security Advisory explicitly says otherwise. Upgrade to the latest release before filing a report. +We follow coordinated disclosure. We will credit reporters in +[SECURITY_ACKNOWLEDGEMENTS.md](https://github.com/OWASP/openshield/blob/main/SECURITY_ACKNOWLEDGEMENTS.md) +unless they prefer to remain anonymous. --- -## Disclosure Process - -We follow a coordinated disclosure model: +## Supported Versions -1. **Report received** -- you email the vulnerability privately -2. **Acknowledgement** -- we respond within 48 hours to confirm receipt -3. **Investigation** -- we reproduce and assess the impact -4. **Fix developed** -- we write and test a patch -5. **Coordinated release** -- we agree a disclosure date with you (typically 7-14 days after fix) -6. **Public advisory** -- we publish a GitHub Security Advisory and release the fix +We actively maintain the latest release on the `main` branch. Security fixes are +applied to the current release only. We do not backport fixes to older versions. -We ask that you do not publicly disclose the vulnerability until step 6 is complete. +| Version | Supported | +|---|---| +| Latest (`main`) | Yes | +| Older releases | No | --- -## Scope +## Security Scope + +OpenShield is a multi-component security tool. Understanding what each component +does helps reporters accurately scope their findings. ### In scope -- Scanner engine (`scanner/`) -- rule logic, Azure SDK calls, output handling -- REST API (`api/`) -- authentication, authorisation, input validation, JWT handling -- Compliance framework mappings (`compliance/`) -- data integrity -- Sentinel integration (`sentinel/`) -- HMAC signing, data upload logic -- Hardcoded secrets or credentials anywhere in the codebase +| Component | What it does | Security relevance | +|---|---|---| +| `api/` | REST API with JWT/OIDC authentication and role-based access control | Auth bypass, privilege escalation, input validation, JWT handling | +| `scanner/` | Reads Azure resource configuration via the Azure SDK; does not write | Credential handling, cross-tenant isolation, output integrity | +| `playbooks/cli/` | Remediation scripts that modify Azure resources when run manually | Command injection, privilege escalation, unsafe Azure mutations | +| `sentinel/` | Signs and uploads scan data to Azure Log Analytics via HMAC | HMAC signing, credential handling, data integrity | +| `ai/` | RAG pipeline (embedding, retrieval, chunking) invoked by the API AI endpoints | Prompt injection, data leakage, path traversal on document loading | +| `compliance/` | Compliance framework mappings consumed by the API and scanner | Logic errors that incorrectly map controls, suppressing true positives | +| `frontend/` | React dashboard that displays scan results and compliance reports | XSS, CSRF, insecure API consumption, auth state handling | +| `website/` | Astro project website and documentation | XSS, content injection, dependency vulnerabilities | +| Hardcoded secrets | Anywhere in the codebase | Any real credential committed to the repo | ### Out of scope -- Vulnerabilities in third-party dependencies -- report those to the upstream maintainer +- Vulnerabilities in third-party dependencies — report those to the upstream maintainer - Security issues in infrastructure you deploy OpenShield to (your Azure environment, your PostgreSQL instance) +- False-positive scan findings due to unsupported Azure API versions or preview features +- Rate limiting or throttling by the Azure ARM API - Social engineering attacks - Physical security ---- - -## Recognition - -We value responsible disclosure. Researchers who report valid vulnerabilities will be: - -- Acknowledged by name (or pseudonym if preferred) in the release notes for the fix -- Listed in [`SECURITY_ACKNOWLEDGEMENTS.md`](../SECURITY_ACKNOWLEDGEMENTS.md) +### Clarification on read-only behavior -We do not currently offer a bug bounty programme, but we are grateful for every report. +The `scanner/` component is read-only: it reads Azure configuration and does not +modify resources. The `playbooks/cli/` scripts are separate executables that a +human operator runs manually; they do modify Azure resources. The REST API and +sentinel components are active network services. --- -## Contact +## Security Controls in This Repository -**Email: vishnu.ajith@owasp.org** +| Control | Implementation | +|---|---| +| Static analysis (SAST) | Semgrep, Bandit in CI + CodeQL (separate workflow) on every PR | +| Dependency scanning | Dependabot alerts (GitHub) + pip-audit in CI | +| Secret scanning | Gitleaks in CI | +| Container scanning | Trivy in CI | +| SBOM generation | Syft in CI | +| DCO sign-off | DCO check runs on every pull request |