daemon-sec-lotl

DÆMONBins: GTFOBins × LOLBAS × WADComs × LOOBins in one filterable catalog
git clone https://git.daemon-sec.xyz/daemon-sec-lotl.git
Log | Files | Refs | Submodules | README | LICENSE

upstream-drift.yml (2740B)


      1 # Weekly freshness check. The dataset is regenerated by hand (`npm run data`
      2 # needs the vendored upstreams), so nothing would otherwise tell us that
      3 # GTFOBins / LOLBAS / WADComs moved on. This compares each upstream's current
      4 # HEAD against the short hash recorded in src/data/facets.json and opens (or
      5 # updates) a single tracking issue when any of them drifted.
      6 name: Upstream drift
      7 
      8 on:
      9   schedule:
     10     - cron: '17 6 * * 1' # Mondays 06:17 UTC
     11   workflow_dispatch:
     12 
     13 permissions:
     14   contents: read
     15   issues: write
     16 
     17 jobs:
     18   drift:
     19     runs-on: ubuntu-latest
     20     steps:
     21       - uses: actions/checkout@v4
     22       - name: Compare upstream HEADs with facets.json
     23         id: cmp
     24         shell: bash
     25         run: |
     26           set -euo pipefail
     27           declare -A REPO=(
     28             [gtfobins]=https://github.com/GTFOBins/GTFOBins.github.io
     29             [lolbas]=https://github.com/LOLBAS-Project/LOLBAS
     30             [wadcoms]=https://github.com/WADComs/WADComs.github.io
     31           )
     32           drift=0; body=""
     33           for name in gtfobins lolbas wadcoms; do
     34             pinned=$(node -p "require('./src/data/facets.json').commits.$name || ''")
     35             head=$(git ls-remote "${REPO[$name]}" HEAD | cut -c1-7)
     36             if [ -z "$pinned" ]; then
     37               body+="- **$name**: no pinned commit recorded (upstream HEAD \`$head\`)"$'\n'; drift=1
     38             elif [ "$pinned" != "$head" ]; then
     39               body+="- **$name**: pinned \`$pinned\`, upstream HEAD \`$head\` — ${REPO[$name]}/compare/$pinned...$head"$'\n'; drift=1
     40             else
     41               body+="- $name: up to date (\`$pinned\`)"$'\n'
     42             fi
     43           done
     44           echo "drift=$drift" >> "$GITHUB_OUTPUT"
     45           { echo 'body<<EOF'; echo "$body"; echo 'EOF'; } >> "$GITHUB_OUTPUT"
     46       - name: Open or update the tracking issue
     47         if: steps.cmp.outputs.drift == '1'
     48         env:
     49           GH_TOKEN: ${{ github.token }}
     50           BODY: ${{ steps.cmp.outputs.body }}
     51         run: |
     52           title="Upstream drift: dataset is behind GTFOBins / LOLBAS / WADComs"
     53           text="$(printf '%s\n\n%s\n\n%s' "Detected by the weekly drift check on $(date -u +%F)." "$BODY" 'Refresh with `git submodule update --remote vendor/gtfobins vendor/lolbas vendor/wadcoms && npm run data`, then commit `src/data/*.json`.')"
     54           existing=$(gh issue list --label upstream-drift --state open --json number --jq '.[0].number // empty')
     55           if [ -n "$existing" ]; then
     56             gh issue comment "$existing" --body "$text"
     57           else
     58             gh label create upstream-drift --color c4a7e7 --description "Dataset behind an upstream" 2>/dev/null || true
     59             gh issue create --title "$title" --label upstream-drift --body "$text"
     60           fi