Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
131 changes: 124 additions & 7 deletions .github/CODE_OF_CONDUCT.md
Original file line number Diff line number Diff line change
@@ -1,10 +1,127 @@
# Code of Conduct
# Contributor Covenant Code of Conduct

OpenShield is an open, welcoming project.
## Our Pledge

- Be respectful in all interactions
- No harassment, discrimination, or offensive language
- Constructive feedback only — critique code, not people
- All contributions welcome regardless of experience level
We as members, contributors, and leaders pledge to make participation in the
OpenShield community a harassment-free experience for everyone, regardless of
age, body size, visible or invisible disability, ethnicity, sex characteristics,
gender identity and expression, level of experience, education, socio-economic
status, nationality, personal appearance, race, caste, color, religion, or
sexual identity and orientation.

Violations can be reported to the maintainer directly via GitHub.
We pledge to act and interact in ways that contribute to an open, welcoming,
diverse, inclusive, and healthy community.

## Our Standards

Examples of behavior that contributes to a positive environment:

- Demonstrating empathy and kindness toward other people
- Being respectful of differing opinions, viewpoints, and experiences
- Giving and gracefully accepting constructive feedback
- Accepting responsibility and apologizing to those affected by our mistakes,
and learning from the experience
- Focusing on what is best not just for us as individuals, but for the overall
community

Examples of unacceptable behavior:

- The use of sexualized language or imagery, and sexual attention or advances of
any kind
- Trolling, insulting or derogatory comments, and personal or political attacks
- Public or private harassment
- Publishing others' private information, such as a physical or electronic
address, without their explicit permission
- Other conduct which could reasonably be considered inappropriate in a
professional setting

## Enforcement Responsibilities

Community leaders are responsible for clarifying and enforcing our standards of
acceptable behavior and will take appropriate and fair corrective action in
response to any behavior that they deem inappropriate, threatening, offensive,
or harmful.

Community leaders have the right and responsibility to remove, edit, or reject
comments, commits, code, wiki edits, issues, and other contributions that are
not aligned to this Code of Conduct, and will communicate reasons for moderation
decisions when appropriate.

## Scope

This Code of Conduct applies within all community spaces, and also applies when
an individual is officially representing the community in public spaces.
Examples of representing our community include using an official email address,
posting via an official social media account, or acting as an appointed
representative at an online or offline event.

## Enforcement

Instances of abusive, harassing, or otherwise unacceptable behavior may be
reported to the community leaders responsible for enforcement by contacting the
maintainers directly via GitHub (open a private discussion or direct message a
maintainer). Do not use the security advisory channel for conduct reports.

All complaints will be reviewed and investigated promptly and fairly.

All community leaders are obligated to respect the privacy and security of the
reporter of any incident.

## Enforcement Guidelines

Community leaders will follow these Community Impact Guidelines in determining
the consequences for any action they deem in violation of this Code of Conduct:

### 1. Correction

**Community Impact:** Use of inappropriate language or other behavior deemed
unprofessional or unwelcome in the community.

**Consequence:** A private, written warning from community leaders, providing
clarity around the nature of the violation and an explanation of why the
behavior was inappropriate. A public apology may be requested.

### 2. Warning

**Community Impact:** A violation through a single incident or series of
actions.

**Consequence:** A warning with consequences for continued behavior. No
interaction with the people involved, including unsolicited interaction with
those enforcing the Code of Conduct, for a specified period of time. This
includes avoiding interactions in community spaces as well as external channels
like social media. Violating these terms may lead to a temporary or permanent
ban.

### 3. Temporary Ban

**Community Impact:** A serious violation of community standards, including
sustained inappropriate behavior.

**Consequence:** A temporary ban from any sort of interaction or public
communication with the community for a specified period of time. No public or
private interaction with the people involved, including unsolicited interaction
with those enforcing the Code of Conduct, is allowed during this period.
Violating these terms may lead to a permanent ban.

### 4. Permanent Ban

**Community Impact:** Demonstrating a pattern of violation of community
standards, including sustained inappropriate behavior, harassment of an
individual, or aggression toward or disparagement of classes of individuals.

**Consequence:** A permanent ban from any sort of public interaction within the
community.

## Attribution

This Code of Conduct is adapted from the [Contributor Covenant][homepage],
version 2.1, available at
[https://www.contributor-covenant.org/version/2/1/code_of_conduct.html][v2.1].

Community Impact Guidelines were inspired by
[Mozilla's code of conduct enforcement ladder][Mozilla CoC].

[homepage]: https://www.contributor-covenant.org
[v2.1]: https://www.contributor-covenant.org/version/2/1/code_of_conduct.html
[Mozilla CoC]: https://github.com/mozilla/diversity
106 changes: 58 additions & 48 deletions .github/SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,82 +2,92 @@

## Reporting a Vulnerability

If you discover a security vulnerability in OpenShield, please **do not open a public GitHub issue**.
Opening a public issue exposes the vulnerability to bad actors before a fix is available.
**Do not open a public GitHub issue for security vulnerabilities.**

Report security vulnerabilities privately using
[GitHub's private security advisory feature](https://github.com/OWASP/openshield/security/advisories/new).

We will acknowledge your report within 48 hours and work with you to coordinate a fix and responsible disclosure timeline.
> **Note for reporters:** Private vulnerability reporting must be enabled by an
> organisation owner (Settings > Code security > Private vulnerability reporting)
> before this link accepts reports from outside collaborators. If the link does
> not work, email **vishnu.ajith@owasp.org** directly.

### What to include in your report

To help us triage quickly, please include:
Please include:

- A description of the vulnerability and its potential impact
- The affected component (scanner engine, REST API, auth logic, playbooks)
- Steps to reproduce the issue
- Any relevant logs, proof-of-concept code, or screenshots
- The version of OpenShield you were testing (check `git log --oneline -1`)
- The affected component (scanner engine, REST API, auth logic, playbooks, sentinel)
- Steps to reproduce or a proof-of-concept (if available)
- Affected versions or components
- Any suggested fix (optional)

The more detail you provide, the faster we can respond.
### Response timeline

---
| Stage | Target |
|---|---|
| Acknowledgement | Within 48 hours |
| Initial triage and severity assessment | Within 5 business days |
| Fix or mitigation | Depends on severity; critical issues within 14 days |
| Public disclosure | Coordinated with reporter after fix is merged |

## Supported Versions

| Version | Supported |
|---------|-----------|
| 0.3.x | Yes |
| 0.1.x | No |

Older versions are not patched unless a GitHub Security Advisory explicitly says otherwise. Upgrade to the latest release before filing a report.
We follow coordinated disclosure. We will credit reporters in
[`SECURITY_ACKNOWLEDGEMENTS.md`](../SECURITY_ACKNOWLEDGEMENTS.md)
unless they prefer to remain anonymous.

---

## Disclosure Process

We follow a coordinated disclosure model:
## Supported Versions

1. **Report received** -- you email the vulnerability privately
2. **Acknowledgement** -- we respond within 48 hours to confirm receipt
3. **Investigation** -- we reproduce and assess the impact
4. **Fix developed** -- we write and test a patch
5. **Coordinated release** -- we agree a disclosure date with you (typically 7-14 days after fix)
6. **Public advisory** -- we publish a GitHub Security Advisory and release the fix
We actively maintain the latest release on the `main` branch. Security fixes are
applied to the current release only. We do not backport fixes to older versions.

We ask that you do not publicly disclose the vulnerability until step 6 is complete.
| Version | Supported |
|---|---|
| Latest (`main`) | Yes |
| Older releases | No |

---

## Scope
## Security Scope

OpenShield is a multi-component security tool. Understanding what each component
does helps reporters accurately scope their findings.

### In scope

- Scanner engine (`scanner/`) -- rule logic, Azure SDK calls, output handling
- REST API (`api/`) -- authentication, authorisation, input validation, JWT handling
- Compliance framework mappings (`compliance/`) -- data integrity
- Sentinel integration (`sentinel/`) -- HMAC signing, data upload logic
- Hardcoded secrets or credentials anywhere in the codebase
| Component | What it does | Security relevance |
|---|---|---|
| `api/` | REST API with JWT/OIDC authentication and role-based access control | Auth bypass, privilege escalation, input validation, JWT handling |
| `scanner/` | Reads Azure resource configuration via the Azure SDK; does not write | Credential handling, cross-tenant isolation, output integrity |
| `playbooks/cli/` | Remediation scripts that modify Azure resources when run manually | Command injection, privilege escalation, unsafe Azure mutations |
| `sentinel/` | Signs and uploads scan data to Azure Log Analytics via HMAC | HMAC signing, credential handling, data integrity |
| `api/` AI endpoints | Process untrusted finding text through LLM calls | Prompt injection, data leakage |
| Hardcoded secrets | Anywhere in the codebase | Any real credential committed to the repo |

### Out of scope

- Vulnerabilities in third-party dependencies -- report those to the upstream maintainer
- Vulnerabilities in third-party dependencies — report those to the upstream maintainer
- Security issues in infrastructure you deploy OpenShield to (your Azure environment, your PostgreSQL instance)
- False-positive scan findings due to unsupported Azure API versions or preview features
- Rate limiting or throttling by the Azure ARM API
- Social engineering attacks
- Physical security

---

## Recognition

We value responsible disclosure. Researchers who report valid vulnerabilities will be:

- Acknowledged by name (or pseudonym if preferred) in the release notes for the fix
- Listed in [`SECURITY_ACKNOWLEDGEMENTS.md`](../SECURITY_ACKNOWLEDGEMENTS.md)
### Clarification on read-only behaviour

We do not currently offer a bug bounty programme, but we are grateful for every report.
The `scanner/` component is read-only: it reads Azure configuration and does not
modify resources. The `playbooks/cli/` scripts are separate executables that a
human operator runs manually; they do modify Azure resources. The REST API and
sentinel components are active network services.

---

## Contact
## Security Controls in This Repository

**Email: vishnu.ajith@owasp.org**
| Control | Implementation |
|---|---|
| Static analysis (SAST) | Semgrep, Bandit, CodeQL on every PR |
| Dependency scanning | Dependabot alerts + pip-audit in CI |
| Secret scanning | Gitleaks in CI |
| Container scanning | Trivy in CI |
| SBOM generation | Syft in CI |
| DCO sign-off | Enforced on every commit |
Loading