From ec3119efc2f2056f0338a90296ea084865441e82 Mon Sep 17 00:00:00 2001
From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com>
Date: Thu, 26 Jun 2025 17:32:45 +0000
Subject: [PATCH 1/3] Initial plan
From 64c1d221c48d1e2a53ffaf095a2172841ae61349 Mon Sep 17 00:00:00 2001
From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com>
Date: Thu, 26 Jun 2025 17:36:01 +0000
Subject: [PATCH 2/3] Initial DevSecOps GHAS demo implementation - Fixed .NET
version and packages
Co-authored-by: CalinL <10718943+CalinL@users.noreply.github.com>
---
src/webapp01/Program.cs | 5 ++---
src/webapp01/webapp01.csproj | 4 ++--
2 files changed, 4 insertions(+), 5 deletions(-)
diff --git a/src/webapp01/Program.cs b/src/webapp01/Program.cs
index a04832b..3177bcf 100644
--- a/src/webapp01/Program.cs
+++ b/src/webapp01/Program.cs
@@ -19,8 +19,7 @@
app.UseAuthorization();
-app.MapStaticAssets();
-app.MapRazorPages()
- .WithStaticAssets();
+app.UseStaticFiles();
+app.MapRazorPages();
app.Run();
diff --git a/src/webapp01/webapp01.csproj b/src/webapp01/webapp01.csproj
index 9b11105..97303be 100644
--- a/src/webapp01/webapp01.csproj
+++ b/src/webapp01/webapp01.csproj
@@ -1,7 +1,7 @@
Extended security vulnerability demonstrations for GitHub Advanced Security scanning
+@demo
+ Detected by GHAS Code Scanning +No vulnerability demonstrations available.
+ } +Deep semantic analysis with custom CodeQL queries for complex vulnerability patterns.
+ +Automated detection of SQL injection vulnerabilities in database queries.
+Organization-specific security policies and custom vulnerability detection rules.
+ +Comprehensive dependency vulnerability tracking and remediation guidance.
++ This form demonstrates SQL injection vulnerabilities that should be detected by GHAS. + DO NOT use in production! +
+ + + ++ This form lacks CSRF protection, demonstrating a common security vulnerability. +
+ + + ++ This page contains intentionally vulnerable code designed for GitHub Advanced Security + demonstrations. The vulnerabilities include SQL injection, CSRF, hardcoded credentials, + and insecure data handling patterns. +
++ Never deploy this code to production! Use it only for learning and testing + GHAS capabilities in a secure, isolated environment. +
++ Extended Demo: Visit our Advanced DevSecOps + page for additional security vulnerability demonstrations and extended GHAS capabilities. +