audit-labs/audit-tools

A collection of scripts, queries, and other goodies you can use in an audit. audit automation compliance evidence scripts

Commit 4867af4f3d

4867af4f3d6bc555da3464b9e9b9bfdff9a4416b

parent: 699513a1a7

Unsigned

cmc <hello@cleberg.net> · 2026-08-07 02:32 UTC

Harden CLI path handling and sample.html default RNG

SonarCloud security findings:
- load_config / load_json resolve and validate that the input path is a
  regular file before opening (pythonsecurity:S8707)
- sample.html seeds its default draw from crypto.getRandomValues instead of
  Math.random, and writes the seed back so the sample stays reproducible
  (javascript:S2245)

Layout: unified · split

applications/aws/aws_password_policy/evaluate_policy.py +4 −1
@@ -109,8 +109,11 @@ def evaluate(expect: Any | None, actual: Any, field_type: str) -> str:
109109
110110def load_json(path: Path) -> dict[str, Any]:
111111 """Read the JSON file generated by the Bash script."""
112 resolved = path.resolve()
113 if not resolved.is_file():
114 sys.exit(f"Could not read JSON file {path}: not a regular file")
112115 try:
113 with path.open("r", encoding="utf-8") as fh:
116 with resolved.open("r", encoding="utf-8") as fh:
114117 return json.load(fh)
115118 except Exception as exc:
116119 sys.exit(f"Could not read JSON file {path}: {exc}")
sampling/sample.html +8 −1
@@ -77,7 +77,14 @@ function seededRandom(seed) {
7777function handleFormSubmit(event) {
7878 event.preventDefault(); // Prevent the default form submission behavior
7979 const customSeedInput = document.getElementById('customSeed').value;
80 const seed = customSeedInput ? parseInt(customSeedInput) : Math.floor(Math.random() * 1000000); // Use custom seed if provided
80 // Use the custom seed if provided; otherwise draw a strong random seed and
81 // write it back so the (reproducible) sample can always be tied to a seed.
82 const seed = customSeedInput
83 ? parseInt(customSeedInput)
84 : crypto.getRandomValues(new Uint32Array(1))[0] % 1000000;
85 if (!customSeedInput) {
86 document.getElementById('customSeed').value = seed;
87 }
8188 generateSamples(seed); // Call the function with the seed
8289}
8390
sampling/sampling_tool/cli.py +3 −1
@@ -54,7 +54,9 @@ def load_config(path: str | None) -> dict[str, object]:
5454 "YAML config support requires PyYAML. Install requirements.txt."
5555 ) from exc
5656
57 config_path = Path(path)
57 config_path = Path(path).resolve()
58 if not config_path.is_file():
59 raise AuditSamplingError(f"Config file not found: {path}")
5860 with config_path.open("r", encoding="utf-8") as handle:
5961 data = yaml.safe_load(handle) or {}
6062 if not isinstance(data, dict):