{"repo":"apiiro/PRevent","free":true,"listed":false,"github":"https://github.com/apiiro/PRevent","clone":"git clone https://github.com/apiiro/PRevent.git","description":"Prevent merging of malicious code in pull requests","language":"Python","stars":259,"topics":["block-merging","cicd-security","cloud-security","code-integrity","code-security","dynamic-execution","github-app","malicious-code","malware-detection","obfuscation"],"license":"MIT","category":"self-hosted-apps","readme_excerpt":"PRevent A self-hosted GitHub app that listens for pull request events, scans them for malicious code, and comments detections directly on the pull request. The tj-actions/changed-file malicious commit as would have been detected by PRevent: - PRevent - Why Use a GitHub Application - Malicious Code Detection - Extra Capabilities - Supported languages - Setup - Non-Containerized Setup - Containerized Setup - 1. Secret Manager - Secret Manager Setup Instructions - 2. GitHub App - 3. Deployment - Optional Parameters - Docs - Contributing - Known Limitations - License Why Use a GitHub Application Typically, security scans are run by workflow files. However, files can be modified, and when dealing with source modification attacks, should be avoided. A GitHub-app approach addresses this gap, ensuring the scan is not bypassed while providing better flexibility. The app's logic can be leveraged to run any scan. All you need is to add a scanner method to the scan logic. Malicious Code Detection Currently, PRevent detects dynamic code execution and obfuscation, patterns found in nearly 100% of malicious code attacks reported to this day, while being rare in benign code, making the scan very effective. It uses Apiiro's malicious-code-ruleset for Semgrep, alongside additional Python-based detectors. Only rules and detectors with low false-positive rates are included. When a false-positive occurs, it's almost always due to poor coding practices. Extra Capabilities Optional features: - Sele","default_branch":null,"files":null,"tree":[],"storefront":"/r/apiiro","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/apiiro/PRevent/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}