Detailed guide

A step-by-step guide to integrating GitHub Actions

1. Add XEIZE_TOKEN

Add the XEIZE_TOKEN secret for GitHub Actions as shown below.

GitHub Actions secret settings

2. Add a GitHub Actions workflow

Click the + button to create a file.

Creating a workflow file

Add the workflow content, then select Commit changes to save and enable the workflow.

Use the configuration on the GitHub Actions page.

Saving the workflow

3. Verify with a PR

Clone the repository

Clone the repository containing the GitHub Actions workflow. In git clone REPOSITORY_URL, replace REPOSITORY_URL with the copied repository URL.

Find the clone URL as shown below.

Repository clone URL

Create a branch

Prepare the pull request in your terminal.

  1. Run cd repository to enter the cloned directory, replacing repository with its actual name.
  2. Run git checkout -b pr-test to create the pr-test branch.
  3. Create the following intentionally vulnerable files in that directory.

vuln_crypto.py

python
# Unsafe Crypto Algorithm + Hardcoded key
from Crypto.Cipher import DES
ENCRYPTION_KEY = b"weak_key"
cipher = DES.new(ENCRYPTION_KEY, DES.MODE_ECB)

vuln_exec.py

python
# Unsafe Flask RCE
from flask import Flask, request

app = Flask(__name__)

@app.route('/exec')
def unsafe_exec():
    code = request.args.get('code')
    eval(code)
    return "Dangerous Code executed"
  1. After creating the files, run:
text
git add . 
git commit -m "add tests"
git push origin pr-test
  1. Return to the repository, open Pull requests, and select New pull request.
Opening a pull request
  1. Select pr-test, then choose Create pull request.
Selecting the test branch
  1. Once GitHub Actions finishes, check that comments appear as shown below.
XEIZE comments on the pull request