Commit 41d4f5879a
Unsigned
Layout: unified · split
README.org +11
| @@ -7,6 +7,12 @@ automating common audit procedures and analyses. | |||
| 7 | This repository includes practical examples that can be used as-is or adapted to | 7 | This repository includes practical examples that can be used as-is or adapted to |
| 8 | specific audit environments. | 8 | specific audit environments. |
| 9 | 9 | ||
| 10 | It also ships an interactive terminal UI (=audit_tui.py=) that walks you through | ||
| 11 | running an audit against GitHub, GitLab, or AWS — pick a platform, enter | ||
| 12 | connection details, choose which checks to run, and watch live progress. | ||
| 13 | |||
| 14 | [[./docs/screenshots/menu.png]] | ||
| 15 | |||
| 10 | ** Contents | 16 | ** Contents |
| 11 | 17 | ||
| 12 | | Directory | Description | | 18 | | Directory | Description | |
| @@ -66,6 +72,11 @@ To pick a platform and be walked through an audit interactively: | |||
| 66 | python audit_tui.py | 72 | python audit_tui.py |
| 67 | #+end_src | 73 | #+end_src |
| 68 | 74 | ||
| 75 | Each run writes the same package the platform's =audit.py= produces — one CSV per | ||
| 76 | check plus a summary — with a progress bar and per-check results: | ||
| 77 | |||
| 78 | [[./docs/screenshots/run.png]] | ||
| 79 | |||
| 69 | See =tui/README.md= for details. GitHub, GitLab, and AWS are supported. | 80 | See =tui/README.md= for details. GitHub, GitLab, and AWS are supported. |
| 70 | 81 | ||
| 71 | ** Contributing | 82 | ** Contributing |
docs/screenshots/checks.png added
Binary file not shown.
docs/screenshots/menu.png added
Binary file not shown.
docs/screenshots/run.png added
Binary file not shown.
sonar-project.properties deleted −15
| @@ -1,15 +0,0 @@ | |||
| 1 | # SonarCloud configuration (Automatic Analysis / Autoscan). | ||
| 2 | # | ||
| 3 | # projectKey and organization are intentionally omitted — they are bound | ||
| 4 | # automatically by the GitHub integration, and setting them here can disable | ||
| 5 | # Automatic Analysis. | ||
| 6 | |||
| 7 | # Suppress python:S1172 (unused function parameter) on the collector packages. | ||
| 8 | # Collectors share a uniform (id, cfg, cache) signature so the audit runner can | ||
| 9 | # dispatch every check the same way. Some collectors legitimately use only part | ||
| 10 | # of that signature — per-project collectors don't need the org/group, and the | ||
| 11 | # pure formatter needs only the cache. This mirrors the existing GitHub | ||
| 12 | # collectors (e.g. privileged_access, permission_matrix). | ||
| 13 | sonar.issue.ignore.multicriteria=e1 | ||
| 14 | sonar.issue.ignore.multicriteria.e1.ruleKey=python:S1172 | ||
| 15 | sonar.issue.ignore.multicriteria.e1.resourcePath=applications/**/collectors/**/*.py | ||
tui/README.md +4
| @@ -8,6 +8,10 @@ GitHub, GitLab, and AWS are supported. Adding a platform is a matter of writing | |||
| 8 | a runner and a `Platform` descriptor in `tui/platforms.py` — the screens are | 8 | a runner and a `Platform` descriptor in `tui/platforms.py` — the screens are |
| 9 | platform-agnostic. | 9 | platform-agnostic. |
| 10 | 10 | ||
| 11 | | Pick a platform | Choose checks | Watch it run | | ||
| 12 | |---|---|---| | ||
| 13 | |  |  |  | | ||
| 14 | |||
| 11 | ## Run it | 15 | ## Run it |
| 12 | 16 | ||
| 13 | ```bash | 17 | ```bash |