You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
<h5class="card-title">About this HTML report generated by Gitxray</h5>
102
102
<pclass="card-text">The report was generated as a result of using the HTML output format of Gitxray. Other output formats are available and documented at <ahref='https://github.com/kulkansecurity/gitxray/'>https://github.com/kulkansecurity/gitxray</a> and <ahref='https://www.gitxray.com'>www.gitxray.com</a>.</p>
103
-
<pclass="card-text">The information contained in this HTML report is exactly the same information displayed in other formats (eg. text and json). Additional processing was implemented to create the "By Category" option on the sidemenu, which merges all Contributor result categories, making it easier to navigate through specific categories across a given repository.</p>
104
103
105
-
<h5class="card-title">About Gitxray</h5>
106
-
<pclass="card-text">Gitxray (short for Git X-Ray) is a multifaceted security tool designed for use on GitHub repositories. It can serve many purposes, including OSINT and Forensics. gitxray leverages public GitHub REST APIs to gather information that would otherwise be very time-consuming to obtain manually. Additionally, it seeks out information in unconventional places.</p>
104
+
<h5class="card-title">Use-cases and potential scenarios</h5>
105
+
<pclass="card-text">Gitxray extracts so much data from a repository and its contributors that it can be overwhelming. You may already be looking into a specific contributor or scenario, but if you need ideas, here are some sample use cases Gitxray covers by default:</p>
106
+
<ul>
107
+
<li><ahref='https://gitxray.com/features/#unintended-disclosures-in-contributor-profiles' target='_blank'>Unintended disclosures in contributor profiles</a></li>
108
+
<li><ahref='https://gitxray.com/features/#spotting-shared-co-owned-or-fake-contributors' target='_blank'>Spotting shared, co-owned or fake contributors</a></li>
109
+
<li><ahref='https://gitxray.com/features/#duplicate-repository-name-check' target='_blank'>Duplicate repository name checks</a></li>
110
+
<li><ahref='https://gitxray.com/features/#the-pr-rejection-awards' target='_blank'>Top 3 of Users with rejected Pull Requests</a></li>
111
+
<li><ahref='https://gitxray.com/features/#looking-out-for-malicious-releases-and-assets' target='_blank'>Finding Releases and Assets updated post-release</a></li>
<divclass="col-md-12"><strong>IMPORTANT:</strong> This section groups all findings flagged with "WARNING" by Gitxray to help you focus and prioritize your investigation. Please remember that Gitxray is an information-extraction tool, not a security scanner. Do not rely solely on these highlighted entries—take the time to review all of the data thoroughly.</div>
126
+
{{highlights_section}}
127
+
</div>
128
+
</div>
129
+
<br/>
130
+
116
131
<divclass="card">
117
132
<h5class="card-header">Findings specific to the repository</h5>
0 commit comments