From 4803fc76666061cfa80009e8d46a02cd4e8d5b96 Mon Sep 17 00:00:00 2001 From: Tanvir Farhad Date: Thu, 24 Sep 2026 15:46:06 +0100 Subject: [PATCH 1/2] docs: add CODE_OF_CONDUCT and SECURITY for OpenSSF Silver badge Adds two missing documents required for the OpenSSF Best Practices Silver badge (bestpractices.dev project 13618): - CODE_OF_CONDUCT.md: Contributor Covenant v2.1, covers the code_of_conduct Silver criterion - SECURITY.md: vulnerability reporting process, response timeline, supported versions, and security scope; covers vulnerability_report_process and vulnerability_response_process All other Silver criteria (DCO, Dependabot, coverage enforcement, ruff strict, CodeQL, SBOM) are already implemented in CI and can be marked Met on bestpractices.dev by the badge owner without additional code changes. Closes part of #342. See also #199. Signed-off-by: Tanvir Farhad --- CODE_OF_CONDUCT.md | 127 +++++++++++++++++++++++++++++++++++++++++++++ SECURITY.md | 89 +++++++++++++++++++++++++++++++ 2 files changed, 216 insertions(+) create mode 100644 CODE_OF_CONDUCT.md create mode 100644 SECURITY.md diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md new file mode 100644 index 00000000..327e4305 --- /dev/null +++ b/CODE_OF_CONDUCT.md @@ -0,0 +1,127 @@ +# Contributor Covenant Code of Conduct + +## Our Pledge + +We as members, contributors, and leaders pledge to make participation in the +OpenShield community a harassment-free experience for everyone, regardless of +age, body size, visible or invisible disability, ethnicity, sex characteristics, +gender identity and expression, level of experience, education, socio-economic +status, nationality, personal appearance, race, caste, color, religion, or +sexual identity and orientation. + +We pledge to act and interact in ways that contribute to an open, welcoming, +diverse, inclusive, and healthy community. + +## Our Standards + +Examples of behavior that contributes to a positive environment: + +- Demonstrating empathy and kindness toward other people +- Being respectful of differing opinions, viewpoints, and experiences +- Giving and gracefully accepting constructive feedback +- Accepting responsibility and apologizing to those affected by our mistakes, + and learning from the experience +- Focusing on what is best not just for us as individuals, but for the overall + community + +Examples of unacceptable behavior: + +- The use of sexualized language or imagery, and sexual attention or advances of + any kind +- Trolling, insulting or derogatory comments, and personal or political attacks +- Public or private harassment +- Publishing others' private information, such as a physical or electronic + address, without their explicit permission +- Other conduct which could reasonably be considered inappropriate in a + professional setting + +## Enforcement Responsibilities + +Community leaders are responsible for clarifying and enforcing our standards of +acceptable behavior and will take appropriate and fair corrective action in +response to any behavior that they deem inappropriate, threatening, offensive, +or harmful. + +Community leaders have the right and responsibility to remove, edit, or reject +comments, commits, code, wiki edits, issues, and other contributions that are +not aligned to this Code of Conduct, and will communicate reasons for moderation +decisions when appropriate. + +## Scope + +This Code of Conduct applies within all community spaces, and also applies when +an individual is officially representing the community in public spaces. +Examples of representing our community include using an official email address, +posting via an official social media account, or acting as an appointed +representative at an online or offline event. + +## Enforcement + +Instances of abusive, harassing, or otherwise unacceptable behavior may be +reported to the community leaders responsible for enforcement at the project's +GitHub repository by opening a private security advisory or contacting the +maintainers directly via GitHub. + +All complaints will be reviewed and investigated promptly and fairly. + +All community leaders are obligated to respect the privacy and security of the +reporter of any incident. + +## Enforcement Guidelines + +Community leaders will follow these Community Impact Guidelines in determining +the consequences for any action they deem in violation of this Code of Conduct: + +### 1. Correction + +**Community Impact:** Use of inappropriate language or other behavior deemed +unprofessional or unwelcome in the community. + +**Consequence:** A private, written warning from community leaders, providing +clarity around the nature of the violation and an explanation of why the +behavior was inappropriate. A public apology may be requested. + +### 2. Warning + +**Community Impact:** A violation through a single incident or series of +actions. + +**Consequence:** A warning with consequences for continued behavior. No +interaction with the people involved, including unsolicited interaction with +those enforcing the Code of Conduct, for a specified period of time. This +includes avoiding interactions in community spaces as well as external channels +like social media. Violating these terms may lead to a temporary or permanent +ban. + +### 3. Temporary Ban + +**Community Impact:** A serious violation of community standards, including +sustained inappropriate behavior. + +**Consequence:** A temporary ban from any sort of interaction or public +communication with the community for a specified period of time. No public or +private interaction with the people involved, including unsolicited interaction +with those enforcing the Code of Conduct, is allowed during this period. +Violating these terms may lead to a permanent ban. + +### 4. Permanent Ban + +**Community Impact:** Demonstrating a pattern of violation of community +standards, including sustained inappropriate behavior, harassment of an +individual, or aggression toward or disparagement of classes of individuals. + +**Consequence:** A permanent ban from any sort of public interaction within the +community. + +## Attribution + +This Code of Conduct is adapted from the [Contributor Covenant][homepage], +version 2.1, available at +[https://www.contributor-covenant.org/version/2/1/code_of_conduct.html][v2.1]. + +Community Impact Guidelines were inspired by +[Mozilla's code of conduct enforcement ladder][Mozilla CoC]. + +[homepage]: https://www.contributor-covenant.org +[v2.1]: https://www.contributor-covenant.org/version/2/1/code_of_conduct.html +[Mozilla CoC]: https://github.com/mozilla/diversity diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 00000000..549e8e73 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,89 @@ +# Security Policy + +## Reporting a Vulnerability + +**Do not open a public GitHub issue for security vulnerabilities.** + +Report security vulnerabilities privately using +[GitHub's private security advisory feature](https://github.com/OWASP/openshield/security/advisories/new). + +Please include: + +- A description of the vulnerability and its potential impact +- Steps to reproduce or a proof-of-concept (if available) +- Affected versions or components +- Any suggested fix (optional) + +### Response timeline + +| Stage | Target | +|---|---| +| Acknowledgement | Within 48 hours | +| Initial triage and severity assessment | Within 5 business days | +| Fix or mitigation | Depends on severity; critical issues within 14 days | +| Public disclosure | Coordinated with reporter after fix is merged | + +We follow coordinated disclosure. We will credit reporters in the release notes +unless they prefer to remain anonymous. + +--- + +## Supported Versions + +We actively maintain the latest release on the `main` branch. Security fixes are +applied to the current release only. We do not backport fixes to older versions. + +| Version | Supported | +|---|---| +| Latest (`main`) | Yes | +| Older releases | No | + +--- + +## Security Scope + +OpenShield is a **read-only Azure security posture scanner**. Understanding its +scope helps set accurate expectations: + +### What OpenShield does + +- Reads Azure resource configuration via the Azure SDK using a provided + credential (service principal or managed identity) +- Evaluates configuration against security rules and compliance frameworks +- Reports findings; it does not modify, remediate, or deploy anything + +### What OpenShield does not guarantee + +- OpenShield is a scanning and reporting tool, not a security enforcement + mechanism. A clean scan result does not certify that a tenant is secure or + compliant with any regulatory framework. +- Compliance framework mappings (CIS, NIST, ISO 27001, SOC 2) are provided as + guidance only. They are not a substitute for a formal audit. +- OpenShield requires a credential with read access to your Azure subscription. + Protect that credential according to your organization's secret management + policy. OpenShield does not store, transmit, or log credentials beyond the + running process. + +### Out of scope + +The following are not considered vulnerabilities in OpenShield: + +- Findings that are false positives due to unsupported Azure API versions or + preview features +- Rate limiting or throttling by the Azure ARM API +- Security posture of the Azure tenant being scanned (that is what the tool + reports on, not a vulnerability in OpenShield itself) + +--- + +## Security Controls in This Repository + +| Control | Implementation | +|---|---| +| Static analysis (SAST) | Semgrep, Bandit, CodeQL on every PR | +| Dependency scanning | Dependabot alerts + pip-audit in CI | +| Secret scanning | Gitleaks in CI | +| Container scanning | Trivy in CI | +| SBOM generation | Syft in CI | +| DCO sign-off | Enforced on every commit | +| Branch protection | Required reviews and passing CI before merge | From 5a6eebefbf750e694c2708f296da879dd830d8c1 Mon Sep 17 00:00:00 2001 From: Tanvir Farhad Date: Thu, 1 Oct 2026 00:29:33 +0100 Subject: [PATCH 2/2] fix(docs): update .github/ policy files in place, fix scope and PVR note - Delete root-level SECURITY.md and CODE_OF_CONDUCT.md; GitHub resolves these to .github/ copies, so root files were diverging and ignored - SECURITY.md: add PVR-not-yet-enabled note with email fallback, expand scope section to accurately list api/, playbooks/, sentinel/ and AI endpoints, remove false read-only-only claim, remove unverified branch protection claim, credit reporters via SECURITY_ACKNOWLEDGEMENTS.md - CODE_OF_CONDUCT.md: replace weak 5-line stub with full Contributor Covenant v2.1, fix enforcement contact to use GitHub DM not security advisory channel (wrong channel for conduct reports) Signed-off-by: Tanvir Farhad --- .github/CODE_OF_CONDUCT.md | 131 +++++++++++++++++++++++++++++++++++-- .github/SECURITY.md | 106 ++++++++++++++++-------------- CODE_OF_CONDUCT.md | 127 ----------------------------------- SECURITY.md | 89 ------------------------- 4 files changed, 182 insertions(+), 271 deletions(-) delete mode 100644 CODE_OF_CONDUCT.md delete mode 100644 SECURITY.md diff --git a/.github/CODE_OF_CONDUCT.md b/.github/CODE_OF_CONDUCT.md index 31cd3af9..267243bc 100644 --- a/.github/CODE_OF_CONDUCT.md +++ b/.github/CODE_OF_CONDUCT.md @@ -1,10 +1,127 @@ -# Code of Conduct +# Contributor Covenant Code of Conduct -OpenShield is an open, welcoming project. +## Our Pledge -- Be respectful in all interactions -- No harassment, discrimination, or offensive language -- Constructive feedback only — critique code, not people -- All contributions welcome regardless of experience level +We as members, contributors, and leaders pledge to make participation in the +OpenShield community a harassment-free experience for everyone, regardless of +age, body size, visible or invisible disability, ethnicity, sex characteristics, +gender identity and expression, level of experience, education, socio-economic +status, nationality, personal appearance, race, caste, color, religion, or +sexual identity and orientation. -Violations can be reported to the maintainer directly via GitHub. \ No newline at end of file +We pledge to act and interact in ways that contribute to an open, welcoming, +diverse, inclusive, and healthy community. + +## Our Standards + +Examples of behavior that contributes to a positive environment: + +- Demonstrating empathy and kindness toward other people +- Being respectful of differing opinions, viewpoints, and experiences +- Giving and gracefully accepting constructive feedback +- Accepting responsibility and apologizing to those affected by our mistakes, + and learning from the experience +- Focusing on what is best not just for us as individuals, but for the overall + community + +Examples of unacceptable behavior: + +- The use of sexualized language or imagery, and sexual attention or advances of + any kind +- Trolling, insulting or derogatory comments, and personal or political attacks +- Public or private harassment +- Publishing others' private information, such as a physical or electronic + address, without their explicit permission +- Other conduct which could reasonably be considered inappropriate in a + professional setting + +## Enforcement Responsibilities + +Community leaders are responsible for clarifying and enforcing our standards of +acceptable behavior and will take appropriate and fair corrective action in +response to any behavior that they deem inappropriate, threatening, offensive, +or harmful. + +Community leaders have the right and responsibility to remove, edit, or reject +comments, commits, code, wiki edits, issues, and other contributions that are +not aligned to this Code of Conduct, and will communicate reasons for moderation +decisions when appropriate. + +## Scope + +This Code of Conduct applies within all community spaces, and also applies when +an individual is officially representing the community in public spaces. +Examples of representing our community include using an official email address, +posting via an official social media account, or acting as an appointed +representative at an online or offline event. + +## Enforcement + +Instances of abusive, harassing, or otherwise unacceptable behavior may be +reported to the community leaders responsible for enforcement by contacting the +maintainers directly via GitHub (open a private discussion or direct message a +maintainer). Do not use the security advisory channel for conduct reports. + +All complaints will be reviewed and investigated promptly and fairly. + +All community leaders are obligated to respect the privacy and security of the +reporter of any incident. + +## Enforcement Guidelines + +Community leaders will follow these Community Impact Guidelines in determining +the consequences for any action they deem in violation of this Code of Conduct: + +### 1. Correction + +**Community Impact:** Use of inappropriate language or other behavior deemed +unprofessional or unwelcome in the community. + +**Consequence:** A private, written warning from community leaders, providing +clarity around the nature of the violation and an explanation of why the +behavior was inappropriate. A public apology may be requested. + +### 2. Warning + +**Community Impact:** A violation through a single incident or series of +actions. + +**Consequence:** A warning with consequences for continued behavior. No +interaction with the people involved, including unsolicited interaction with +those enforcing the Code of Conduct, for a specified period of time. This +includes avoiding interactions in community spaces as well as external channels +like social media. Violating these terms may lead to a temporary or permanent +ban. + +### 3. Temporary Ban + +**Community Impact:** A serious violation of community standards, including +sustained inappropriate behavior. + +**Consequence:** A temporary ban from any sort of interaction or public +communication with the community for a specified period of time. No public or +private interaction with the people involved, including unsolicited interaction +with those enforcing the Code of Conduct, is allowed during this period. +Violating these terms may lead to a permanent ban. + +### 4. Permanent Ban + +**Community Impact:** Demonstrating a pattern of violation of community +standards, including sustained inappropriate behavior, harassment of an +individual, or aggression toward or disparagement of classes of individuals. + +**Consequence:** A permanent ban from any sort of public interaction within the +community. + +## Attribution + +This Code of Conduct is adapted from the [Contributor Covenant][homepage], +version 2.1, available at +[https://www.contributor-covenant.org/version/2/1/code_of_conduct.html][v2.1]. + +Community Impact Guidelines were inspired by +[Mozilla's code of conduct enforcement ladder][Mozilla CoC]. + +[homepage]: https://www.contributor-covenant.org +[v2.1]: https://www.contributor-covenant.org/version/2/1/code_of_conduct.html +[Mozilla CoC]: https://github.com/mozilla/diversity diff --git a/.github/SECURITY.md b/.github/SECURITY.md index 315eebd2..b001a608 100644 --- a/.github/SECURITY.md +++ b/.github/SECURITY.md @@ -2,82 +2,92 @@ ## Reporting a Vulnerability -If you discover a security vulnerability in OpenShield, please **do not open a public GitHub issue**. -Opening a public issue exposes the vulnerability to bad actors before a fix is available. +**Do not open a public GitHub issue for security vulnerabilities.** +Report security vulnerabilities privately using +[GitHub's private security advisory feature](https://github.com/OWASP/openshield/security/advisories/new). -We will acknowledge your report within 48 hours and work with you to coordinate a fix and responsible disclosure timeline. +> **Note for reporters:** Private vulnerability reporting must be enabled by an +> organisation owner (Settings > Code security > Private vulnerability reporting) +> before this link accepts reports from outside collaborators. If the link does +> not work, email **vishnu.ajith@owasp.org** directly. -### What to include in your report - -To help us triage quickly, please include: +Please include: - A description of the vulnerability and its potential impact -- The affected component (scanner engine, REST API, auth logic, playbooks) -- Steps to reproduce the issue -- Any relevant logs, proof-of-concept code, or screenshots -- The version of OpenShield you were testing (check `git log --oneline -1`) +- The affected component (scanner engine, REST API, auth logic, playbooks, sentinel) +- Steps to reproduce or a proof-of-concept (if available) +- Affected versions or components +- Any suggested fix (optional) -The more detail you provide, the faster we can respond. +### Response timeline ---- +| Stage | Target | +|---|---| +| Acknowledgement | Within 48 hours | +| Initial triage and severity assessment | Within 5 business days | +| Fix or mitigation | Depends on severity; critical issues within 14 days | +| Public disclosure | Coordinated with reporter after fix is merged | -## Supported Versions - -| Version | Supported | -|---------|-----------| -| 0.3.x | Yes | -| 0.1.x | No | - -Older versions are not patched unless a GitHub Security Advisory explicitly says otherwise. Upgrade to the latest release before filing a report. +We follow coordinated disclosure. We will credit reporters in +[`SECURITY_ACKNOWLEDGEMENTS.md`](../SECURITY_ACKNOWLEDGEMENTS.md) +unless they prefer to remain anonymous. --- -## Disclosure Process - -We follow a coordinated disclosure model: +## Supported Versions -1. **Report received** -- you email the vulnerability privately -2. **Acknowledgement** -- we respond within 48 hours to confirm receipt -3. **Investigation** -- we reproduce and assess the impact -4. **Fix developed** -- we write and test a patch -5. **Coordinated release** -- we agree a disclosure date with you (typically 7-14 days after fix) -6. **Public advisory** -- we publish a GitHub Security Advisory and release the fix +We actively maintain the latest release on the `main` branch. Security fixes are +applied to the current release only. We do not backport fixes to older versions. -We ask that you do not publicly disclose the vulnerability until step 6 is complete. +| Version | Supported | +|---|---| +| Latest (`main`) | Yes | +| Older releases | No | --- -## Scope +## Security Scope + +OpenShield is a multi-component security tool. Understanding what each component +does helps reporters accurately scope their findings. ### In scope -- Scanner engine (`scanner/`) -- rule logic, Azure SDK calls, output handling -- REST API (`api/`) -- authentication, authorisation, input validation, JWT handling -- Compliance framework mappings (`compliance/`) -- data integrity -- Sentinel integration (`sentinel/`) -- HMAC signing, data upload logic -- Hardcoded secrets or credentials anywhere in the codebase +| Component | What it does | Security relevance | +|---|---|---| +| `api/` | REST API with JWT/OIDC authentication and role-based access control | Auth bypass, privilege escalation, input validation, JWT handling | +| `scanner/` | Reads Azure resource configuration via the Azure SDK; does not write | Credential handling, cross-tenant isolation, output integrity | +| `playbooks/cli/` | Remediation scripts that modify Azure resources when run manually | Command injection, privilege escalation, unsafe Azure mutations | +| `sentinel/` | Signs and uploads scan data to Azure Log Analytics via HMAC | HMAC signing, credential handling, data integrity | +| `api/` AI endpoints | Process untrusted finding text through LLM calls | Prompt injection, data leakage | +| Hardcoded secrets | Anywhere in the codebase | Any real credential committed to the repo | ### Out of scope -- Vulnerabilities in third-party dependencies -- report those to the upstream maintainer +- Vulnerabilities in third-party dependencies — report those to the upstream maintainer - Security issues in infrastructure you deploy OpenShield to (your Azure environment, your PostgreSQL instance) +- False-positive scan findings due to unsupported Azure API versions or preview features +- Rate limiting or throttling by the Azure ARM API - Social engineering attacks - Physical security ---- - -## Recognition - -We value responsible disclosure. Researchers who report valid vulnerabilities will be: - -- Acknowledged by name (or pseudonym if preferred) in the release notes for the fix -- Listed in [`SECURITY_ACKNOWLEDGEMENTS.md`](../SECURITY_ACKNOWLEDGEMENTS.md) +### Clarification on read-only behaviour -We do not currently offer a bug bounty programme, but we are grateful for every report. +The `scanner/` component is read-only: it reads Azure configuration and does not +modify resources. The `playbooks/cli/` scripts are separate executables that a +human operator runs manually; they do modify Azure resources. The REST API and +sentinel components are active network services. --- -## Contact +## Security Controls in This Repository -**Email: vishnu.ajith@owasp.org** +| Control | Implementation | +|---|---| +| Static analysis (SAST) | Semgrep, Bandit, CodeQL on every PR | +| Dependency scanning | Dependabot alerts + pip-audit in CI | +| Secret scanning | Gitleaks in CI | +| Container scanning | Trivy in CI | +| SBOM generation | Syft in CI | +| DCO sign-off | Enforced on every commit | diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md deleted file mode 100644 index 327e4305..00000000 --- a/CODE_OF_CONDUCT.md +++ /dev/null @@ -1,127 +0,0 @@ -# Contributor Covenant Code of Conduct - -## Our Pledge - -We as members, contributors, and leaders pledge to make participation in the -OpenShield community a harassment-free experience for everyone, regardless of -age, body size, visible or invisible disability, ethnicity, sex characteristics, -gender identity and expression, level of experience, education, socio-economic -status, nationality, personal appearance, race, caste, color, religion, or -sexual identity and orientation. - -We pledge to act and interact in ways that contribute to an open, welcoming, -diverse, inclusive, and healthy community. - -## Our Standards - -Examples of behavior that contributes to a positive environment: - -- Demonstrating empathy and kindness toward other people -- Being respectful of differing opinions, viewpoints, and experiences -- Giving and gracefully accepting constructive feedback -- Accepting responsibility and apologizing to those affected by our mistakes, - and learning from the experience -- Focusing on what is best not just for us as individuals, but for the overall - community - -Examples of unacceptable behavior: - -- The use of sexualized language or imagery, and sexual attention or advances of - any kind -- Trolling, insulting or derogatory comments, and personal or political attacks -- Public or private harassment -- Publishing others' private information, such as a physical or electronic - address, without their explicit permission -- Other conduct which could reasonably be considered inappropriate in a - professional setting - -## Enforcement Responsibilities - -Community leaders are responsible for clarifying and enforcing our standards of -acceptable behavior and will take appropriate and fair corrective action in -response to any behavior that they deem inappropriate, threatening, offensive, -or harmful. - -Community leaders have the right and responsibility to remove, edit, or reject -comments, commits, code, wiki edits, issues, and other contributions that are -not aligned to this Code of Conduct, and will communicate reasons for moderation -decisions when appropriate. - -## Scope - -This Code of Conduct applies within all community spaces, and also applies when -an individual is officially representing the community in public spaces. -Examples of representing our community include using an official email address, -posting via an official social media account, or acting as an appointed -representative at an online or offline event. - -## Enforcement - -Instances of abusive, harassing, or otherwise unacceptable behavior may be -reported to the community leaders responsible for enforcement at the project's -GitHub repository by opening a private security advisory or contacting the -maintainers directly via GitHub. - -All complaints will be reviewed and investigated promptly and fairly. - -All community leaders are obligated to respect the privacy and security of the -reporter of any incident. - -## Enforcement Guidelines - -Community leaders will follow these Community Impact Guidelines in determining -the consequences for any action they deem in violation of this Code of Conduct: - -### 1. Correction - -**Community Impact:** Use of inappropriate language or other behavior deemed -unprofessional or unwelcome in the community. - -**Consequence:** A private, written warning from community leaders, providing -clarity around the nature of the violation and an explanation of why the -behavior was inappropriate. A public apology may be requested. - -### 2. Warning - -**Community Impact:** A violation through a single incident or series of -actions. - -**Consequence:** A warning with consequences for continued behavior. No -interaction with the people involved, including unsolicited interaction with -those enforcing the Code of Conduct, for a specified period of time. This -includes avoiding interactions in community spaces as well as external channels -like social media. Violating these terms may lead to a temporary or permanent -ban. - -### 3. Temporary Ban - -**Community Impact:** A serious violation of community standards, including -sustained inappropriate behavior. - -**Consequence:** A temporary ban from any sort of interaction or public -communication with the community for a specified period of time. No public or -private interaction with the people involved, including unsolicited interaction -with those enforcing the Code of Conduct, is allowed during this period. -Violating these terms may lead to a permanent ban. - -### 4. Permanent Ban - -**Community Impact:** Demonstrating a pattern of violation of community -standards, including sustained inappropriate behavior, harassment of an -individual, or aggression toward or disparagement of classes of individuals. - -**Consequence:** A permanent ban from any sort of public interaction within the -community. - -## Attribution - -This Code of Conduct is adapted from the [Contributor Covenant][homepage], -version 2.1, available at -[https://www.contributor-covenant.org/version/2/1/code_of_conduct.html][v2.1]. - -Community Impact Guidelines were inspired by -[Mozilla's code of conduct enforcement ladder][Mozilla CoC]. - -[homepage]: https://www.contributor-covenant.org -[v2.1]: https://www.contributor-covenant.org/version/2/1/code_of_conduct.html -[Mozilla CoC]: https://github.com/mozilla/diversity diff --git a/SECURITY.md b/SECURITY.md deleted file mode 100644 index 549e8e73..00000000 --- a/SECURITY.md +++ /dev/null @@ -1,89 +0,0 @@ -# Security Policy - -## Reporting a Vulnerability - -**Do not open a public GitHub issue for security vulnerabilities.** - -Report security vulnerabilities privately using -[GitHub's private security advisory feature](https://github.com/OWASP/openshield/security/advisories/new). - -Please include: - -- A description of the vulnerability and its potential impact -- Steps to reproduce or a proof-of-concept (if available) -- Affected versions or components -- Any suggested fix (optional) - -### Response timeline - -| Stage | Target | -|---|---| -| Acknowledgement | Within 48 hours | -| Initial triage and severity assessment | Within 5 business days | -| Fix or mitigation | Depends on severity; critical issues within 14 days | -| Public disclosure | Coordinated with reporter after fix is merged | - -We follow coordinated disclosure. We will credit reporters in the release notes -unless they prefer to remain anonymous. - ---- - -## Supported Versions - -We actively maintain the latest release on the `main` branch. Security fixes are -applied to the current release only. We do not backport fixes to older versions. - -| Version | Supported | -|---|---| -| Latest (`main`) | Yes | -| Older releases | No | - ---- - -## Security Scope - -OpenShield is a **read-only Azure security posture scanner**. Understanding its -scope helps set accurate expectations: - -### What OpenShield does - -- Reads Azure resource configuration via the Azure SDK using a provided - credential (service principal or managed identity) -- Evaluates configuration against security rules and compliance frameworks -- Reports findings; it does not modify, remediate, or deploy anything - -### What OpenShield does not guarantee - -- OpenShield is a scanning and reporting tool, not a security enforcement - mechanism. A clean scan result does not certify that a tenant is secure or - compliant with any regulatory framework. -- Compliance framework mappings (CIS, NIST, ISO 27001, SOC 2) are provided as - guidance only. They are not a substitute for a formal audit. -- OpenShield requires a credential with read access to your Azure subscription. - Protect that credential according to your organization's secret management - policy. OpenShield does not store, transmit, or log credentials beyond the - running process. - -### Out of scope - -The following are not considered vulnerabilities in OpenShield: - -- Findings that are false positives due to unsupported Azure API versions or - preview features -- Rate limiting or throttling by the Azure ARM API -- Security posture of the Azure tenant being scanned (that is what the tool - reports on, not a vulnerability in OpenShield itself) - ---- - -## Security Controls in This Repository - -| Control | Implementation | -|---|---| -| Static analysis (SAST) | Semgrep, Bandit, CodeQL on every PR | -| Dependency scanning | Dependabot alerts + pip-audit in CI | -| Secret scanning | Gitleaks in CI | -| Container scanning | Trivy in CI | -| SBOM generation | Syft in CI | -| DCO sign-off | Enforced on every commit | -| Branch protection | Required reviews and passing CI before merge |