From 0f08e1e49c180535169198522fcd8b608c8403eb Mon Sep 17 00:00:00 2001 From: Chad Bentz <1760475+felickz@users.noreply.github.com> Date: Thu, 15 Sep 2022 09:28:01 -0400 Subject: [PATCH 1/2] Update README.md --- README.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/README.md b/README.md index f36a510..ac018d2 100644 --- a/README.md +++ b/README.md @@ -1,6 +1,6 @@ # Code Scanning C# Tutorial -Welcome to the Code Scanning C# Tutorial! This tutorial will take you through how to set up Github Advanced Security: Code Scanning as well as interpret results that it may find. The following repository contains cross-site scripting vulnerability for demonstration purpose. +Welcome to the Code Scanning C# Tutorial! This tutorial will take you through how to set up Github Advanced Security: Code Scanning as well as interpret results that it may find. The following repository contains a cross-site scripting vulnerability for demonstration purpose. ## Introduction @@ -39,7 +39,7 @@ Click `Set up code scanning`. #### Setup Workflow -Click the `Setup this workflow` button by CodeQL Analysis. +Click the `Configure CodeQL alerts` button. @@ -163,7 +163,7 @@ Click `show paths` in order to see the dataflow path that resulted in this alert Fix the Security Alert -In order to fix this specific alert, we will need to ensure the content being write to the `HttpContext`'s response is validated and sanitized. +In order to fix this specific alert, we will need to ensure the content being written to the `HttpContext`'s response is both validated and sanitized. Click on the `Code` tab and [Edit](https://docs.github.com/en/free-pro-team@latest/github/managing-files-in-a-repository/editing-files-in-your-repository) the file [`Autocomplete.ashx.cs`](./WebGoat/WebGoatCoins/Autocomplete.ashx.cs) in the `WebGoat/WebGoatCoins` folder. For this demonstration purpose, we will simply write some hardcoded value to the `HttpContext` instance, this granatees the parameter is sanitized and safe. From fbcaf7b5273a851e285df7363a005eddc2840833 Mon Sep 17 00:00:00 2001 From: Mike Date: Mon, 14 Nov 2022 08:59:14 +0100 Subject: [PATCH 2/2] Correct programming language java -> C# --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index ac018d2..3cbf952 100644 --- a/README.md +++ b/README.md @@ -43,7 +43,7 @@ Click the `Configure CodeQL alerts` button. -This will create a GitHub Actions Workflow file with CodeQL already set up. Since Java is a compiled language you will need to setup the build in later steps. See the [documentation](https://docs.github.com/en/free-pro-team@latest/github/finding-security-vulnerabilities-and-errors-in-your-code/running-codeql-code-scanning-in-your-ci-system) if you would like to configure CodeQL Analysis with a 3rd party CI system instead of using GitHub Actions. +This will create a GitHub Actions Workflow file with CodeQL already set up. Since C# is a compiled language you will need to setup the build in later steps. See the [documentation](https://docs.github.com/en/free-pro-team@latest/github/finding-security-vulnerabilities-and-errors-in-your-code/running-codeql-code-scanning-in-your-ci-system) if you would like to configure CodeQL Analysis with a 3rd party CI system instead of using GitHub Actions.