github-actions-goat
github-actions-goat copied to clipboard
Add section to simulate past attacks
trafficstars
Organize the project into two parts
- Simulation of past attacks
- [ ] SolarWinds (SUNPOST) - already exists
- [ ] Codecov (tampering of artifact in storage account) - to be added
- [ ] Dependency confusion - to be added
- [ ] Malicious npm package to exfiltrate data on install step (simulation of malicious packages published after account take over/ typosquatting) - already exists
- [ ] Pipeline injection in GitHub Actions (simulation of VS Code bug bounty issue) - to be added
- Solutions