Pinned
1,083 contributions in the last year
Less
More
Activity overview
Contributed to
SAP/fosstars-rating-core,
github/codeql,
artem-smotrakov/ql-fun
and 5 other
repositories
Contribution activity
June 2021
Created 44 commits in 3 repositories
Created 1 repository
Created a pull request in github/codeql that received 38 comments
Java: Timing attacks while comparing results of cryptographic operations
A constant time algorithm should be used when comparing results of cryptographic operations such as hashes, MACs, signatures and ciphertexts. In ot…
+493
−0
•
38
comments
Opened 14 other pull requests in 4 repositories
SAP/fosstars-rating-core
2
open
8
merged
netplex/json-smart-v1
2
open
github/codeql
1
merged
SAP/fosstars-rating-core-action
1
merged
Reviewed 16 pull requests in 2 repositories
SAP/fosstars-rating-core 13 pull requests
- Better OSS RoP action
- Better command line tool
- OSS Rules of Play gets option to create issues for findings
- Bump github-api from 1.130 to 1.131
- Bump mockito-core from 3.11.0 to 3.11.1
- Security review score
- Bump dependency-check-core from 6.2.1 to 6.2.2
- Bump dependency-check-core from 6.2.0 to 6.2.1
- Bump org.eclipse.jgit from 5.11.1.202105131744-r to 5.12.0.202106070339-r
- OWASP Dependency Check integration with Maven artifact
- Subject support to Artifacts and updated CLI for multi-Subject handling
- Fixes sorting comparator bug
- Bump github-api from 1.129 to 1.130
Created an issue in SAP/fosstars-rating-core that received 4 comments
Smarter Vulnerability.createVersionRange()
fosstars-rating-core/src/main/java/com/sap/oss/phosphor/fosstars/model/value/Vulnerability.java Line 423 in b53ef2d
Vulnerability.create…
4
comments
Opened 18 other issues in 3 repositories
SAP/fosstars-rating-core
8
open
8
closed
- Use VULNERABILITIES_IN_ARTIFACT feature in the artifact security rating
- Remove UnpatchedVulnerabilities.isUnpatched()
- Check if a token is available in the GitHub action for OSS RoP
- GitHub action for OSS RoP unnecessarily updates .gitignore
- CLI doesn't print reports if --config is used
- Better guess for GitHub projects
- Better checks for signed artifacts in the security ratings
- Create issues for RoP when CLI runs with a config
- NPE in LicenseInfo
- Better tests for the command-line tool
- Refactor the command-line tool
- SecurityReviewScore can consider changes in the project
- NPM support in the command-line tool
- OssSecurityScoreWeights.json should contain immutable weights
- Don't store URL in GitHubProject
- Updated the OSS security score to consider info about security reviews