Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

1 Commit
 
 
 
 
 
 
 
 
 
 

Repository files navigation

launchproof-e2e-fixture

Test fixture for LaunchProof end-to-end scanner verification.

This repository is deliberately vulnerable and misconfigured. It is not a real project. Everything in it is fabricated:

  • package-lock.json pins npm packages with known OSV advisories.
  • Dockerfile contains deliberate misconfigurations for trivy.
  • config/service.env contains a fake, randomly generated credential string that matches gitleaks' generic-api-key rule. It is not a real credential and grants access to nothing.

Branches:

  • main — full fixture (lockfile + Dockerfile + planted fake secret).
  • bare — orphan branch with only this README: no lockfile, no config files.
  • unrelated-depmain plus one unrelated, non-vulnerable dependency.
  • bump-vulnmain with lodash bumped 4.17.15 -> 4.17.20 (both versions are affected by the same advisories; the bump does not fix them).

About

Deliberately vulnerable/misconfigured test fixture for LaunchProof end-to-end scanner verification. Not a real project; all credentials in it are fabricated.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages