Skip to content

Security Policy violation Binary Artifacts #16

Closed
@allstar-app

Description

@allstar-app

This issue was automatically created by Allstar.

Security Policy Violation
Project is out of compliance with Binary Artifacts policy: binaries present in source code

Rule Description
Binary Artifacts are an increased security risk in your repository. Binary artifacts cannot be reviewed, allowing the introduction of possibly obsolete or maliciously subverted executables. For more information see the Security Scorecards Documentation for Binary Artifacts.

Remediation Steps
To remediate, remove the generated executable artifacts from the repository.

First 10 Artifacts Found

  • google-cloud-sdk/bin/gcloud-crc32c
  • google-cloud-sdk/platform/bundledpythonunix/bin/python3
  • google-cloud-sdk/platform/bundledpythonunix/bin/python3.9
  • google-cloud-sdk/platform/bundledpythonunix/lib/libpython3.9.so
  • google-cloud-sdk/platform/bundledpythonunix/lib/libpython3.9.so.1.0
  • google-cloud-sdk/platform/bundledpythonunix/lib/libpython3.so
  • google-cloud-sdk/platform/bundledpythonunix/lib/python3.9/config-3.9-x86_64-linux-gnu/python.o
  • google-cloud-sdk/platform/bundledpythonunix/lib/python3.9/ensurepip/_bundled/pip-22.0.4-py3-none-any.whl
  • google-cloud-sdk/platform/bundledpythonunix/lib/python3.9/ensurepip/_bundled/setuptools-58.1.0-py3-none-any.whl
  • google-cloud-sdk/platform/bundledpythonunix/lib/python3.9/lib-dynload/_testcapi.cpython-39-x86_64-linux-gnu.so
  • Run a Scorecards scan to see full list.

Additional Information
This policy is drawn from Security Scorecards, which is a tool that scores a project's adherence to security best practices. You may wish to run a Scorecards scan directly on this repository for more details.


⚠️ There is an updated version of this policy result! Click here to see the latest update


This issue will auto resolve when the policy is in compliance.

Issue created by Allstar. See https://github.com/ossf/allstar/ for more information. For questions specific to the repository, please contact the owner or maintainer.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions