• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

bleedingdeacons / integrity-sharp
91%

Build:
DEFAULT BRANCH: main
Repo Added 21 Jul 2026 08:56PM UTC
Files 25
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

LAST BUILD ON BRANCH main
branch: main
CHANGE BRANCH
x
Reset
  • main
  • chore/add-dependabot
  • chore/pin-action-shas
  • chore/semgrep-gate-and-scheduled-scan
  • ci/bump-actions-v5
  • ci/credential-probe
  • ci/publish-with-pat
  • ci/release-nuget-github-packages
  • ci/release-script
  • dependabot/github_actions/actions-e3ee0ff57b
  • dependabot/nuget/dependencies-137e1cce5e
  • dependabot/nuget/dependencies-78915d0028
  • dependabot/nuget/dependencies-cfdccdc611
  • feat/member-landline-preferred-contact
  • fix/release-tag-flag-binding
  • security/audit-2026-09
  • security/audit-2026-09-part2
  • test/xunit-v3-mtp-coverlet-coveralls
  • tests/raise-coverage

09 Sep 2026 05:43PM UTC coverage: 91.39% (+0.3%) from 91.105%
34384664949

push

github

web-flow
fix: validate the base URL, fail fast on an opaque 403, and tidy the retry path (#18)

* ci: declare read-only permissions on the CI workflow

Every other workflow in this repository and its siblings declares
`permissions: contents: read` at the top and narrows to write only on
the jobs that push. This one declared nothing and inherited the
repository or organisation default for GITHUB_TOKEN, which on older
repositories is read/write across scopes.

No path to abuse it today: release.yml records that the organisation
disables write permissions for workflow tokens, and both publishing
steps authenticate with PACKAGES_TOKEN instead. That is an organisation
setting read from a code comment rather than verified, and if it were
ever relaxed this is the workflow that would inherit the looser default.

* fix: validate the base URL, fail fast on an opaque 403, drop the jitter lock

Three findings from the September review, all in UnityRestSharp.

**The base URL was never checked (F13).** Uri.TryCreate was called only
to derive the Host header and its result gated nothing, so a file://,
ftp:// or plain http:// base was accepted and used to build every
request URL. That is what let the bundled example ship an API key over
cleartext without anything in this library objecting. The constructor
now throws unless the result is absolute and HTTPS. Local development
against a site with no certificate opts in with allowInsecureBaseUrl,
which logs a warning and still refuses any scheme but http; the example
CLI exposes it as INTEGRITY_ALLOW_PLAINTEXT=1.

**A 403 with no Content-Type was retried (F9).** IsLikelyWafHtml
returned true for a missing Content-Type, deliberately, as "treat as
suspicious" - so a genuine permission failure served without one was
classified as a WAF page, retried five times with backoff, and had its
body written to the log on every attempt. It now fails fast. Logged
error bodies are also truncated to 1KB; header redaction already keeps
credential... (continued)

41 of 42 new or added lines in 1 file covered. (97.62%)

743 of 813 relevant lines covered (91.39%)

19.79 hits per line

Relevant lines Covered
Build:
Build:
813 RELEVANT LINES 743 COVERED LINES
19.79 HITS PER LINE
Source Files on main
  • Tree
  • List 25
  • Changed 1
  • Source Changed 1
  • Coverage Changed 1
Coverage ∆ File Lines Relevant Covered Missed Hits/Line

Recent builds

Builds Branch Commit Type Ran Committer Via Coverage
34384664949 main fix: validate the base URL, fail fast on an opaque 403, and tidy the retry path (#18) * ci: declare read-only permissions on the CI workflow Every other workflow in this repository and its siblings declares `permissions: contents: read` at the t... push 09 Sep 2026 05:45PM UTC web-flow github
91.39
34380898004 main fix: take the API key out of the example and stop pinning Host on a shared HttpClient (#17) * fix: read the example CLI's credentials from the environment The base URL and API key were literals in a tracked file in a public repository, so two di... push 09 Sep 2026 05:08PM UTC web-flow github
91.11
34259603616 main feat: carry the member landline and preferred contact push 08 Sep 2026 05:53PM UTC web-flow github
91.09
33975480206 main chore(deps): Bump the dependencies group with 3 updates (#15) Bumps Meziantou.Analyzer from 3.0.123 to 3.0.177 Bumps Microsoft.Extensions.Logging.Abstractions from 9.0.0 to 10.0.11 Bumps System.Text.Json from 9.0.0 to 10.0.11 --- updated-depende... push 05 Sep 2026 03:41PM UTC web-flow github
91.03
33975365408 main chore(ci): bump the actions group across 1 directory with 2 updates (#12) Bumps the actions group with 2 updates in the / directory: [actions/checkout](https://github.com/actions/checkout) and [actions/setup-dotnet](https://github.com/actions/set... push 05 Sep 2026 03:39PM UTC web-flow github
91.03
32907234070 main chore(ci): add Semgrep PR gate, scheduled full scan and badge (#14) Brings this repo up to the same standard as the 18 PHP plugins, which have had both since today. Until now this repo was covered only by Semgrep Managed Scans, running on Semgrep... push 25 Aug 2026 10:41PM UTC web-flow github
91.03
32875735473 main chore(ci): add Dependabot for actions and NuGet (#11) The workflows here were just pinned to commit SHAs, which closes the mutable-tag findings but introduces the opposite problem: a pinned SHA never picks up an upstream fix on its own, so withou... push 25 Aug 2026 05:05PM UTC web-flow github
91.03
32874471551 main chore(ci): pin GitHub Actions to commit SHAs (#10) Closes this repo's five github-actions-mutable-action-tag findings. Tags and branch names can be silently repointed by the action owner, which is how the trivy-action and kics-github-action compr... push 25 Aug 2026 04:53PM UTC web-flow github
91.03
31257399192 main Merge pull request #9 from bleedingdeacons/ci/credential-probe ci: probe the registry in the publishing credential check push 08 Aug 2026 12:32PM UTC web-flow github
91.03
31236459735 main Merge pull request #8 from bleedingdeacons/ci/release-script ci: add scripts/release.ps1 to cut a release in one command push 08 Aug 2026 03:07AM UTC web-flow github
91.03
See All Builds (36)
  • Repo on GitHub
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc