Skip to main content

ywh2bt - YesWeHack to Bug Tracker

Project description

ywh2bt

ywh2bt synchronizes your vulnerability reports from the Yes We Hack platform with issues of your bug tracker(s). It automatically retrieves reports you want to copy in your bug tracker, creates the related issue, and syncs further updates between issues and reports.
It comes with a handy GUI to set up and test the integration, while completely controlling the information you allow to be synchronized from both side.

Screenshot of GUI with loaded example file

Table of contents

User Guide

A User Guide is available in PDF and HTML formats.

Architecture

YWH2BT embeds both the GUI to set up the integration, and the application to be scheduled on your server to periodically poll and synchronize new reports.
You can either run both on a single machine, or prepare the configuration file on a computer (with the GUI) and transfer it on the server and use it through a scheduled command.

Since data is pulled from YWH platform to your server, only regular outbound web connections need to be authorized on your server.

Requirements

  • python >= 3.7,<=3.9
  • pip

Supported trackers

  • github
  • gitlab
  • jira / jiracloud
  • servicenow

Changelog

  • v2.7:
    • added synchronization of "fix verification" logs when "Upload status updates" is checked
    • fixed an issue with jira when scope contains special markdown characters
    • fixed an issue when "Download bug trackers comments" feedback option is activated and bug tracker attachments do not meet platform attachments requirements (unacceptable mime-type, maximum allowed size exceeded)
  • v2.6:
    • added work around bug trackers maximum size allowed for the text of the issues/comments (content put in Markdown file attachment when necessary)
  • v2.5:
    • added Personal Access Token (PAT) authentication
    • removed OAuth authentication
  • v2.4:
    • added option to prevent recreation of issues that were created by a previous synchronization but are not found into the bug tracker anymore
  • v2.3:
    • added support for ServiceNow
  • v2.2:
    • added GitLab option for confidential issues
  • v2.1:
  • v0.* to v2.0.0:
    • behavior changes:
      • reports logs can selectively be synchronized with the trackers:
        • public comments
        • private comments
        • report details changes
        • report status changes
        • rewards
      • a program can now only be synchronized with 1 tracker
    • added support for JSON configuration files
    • removed ywh-bugtracker command (use ywh2bt synchronize)
    • added ywh2bt command:
      • added ywh2bt synchronize:
        • note: ywh2bt synchronize --config-file FILE --config-format FORMAT is the equivalent of ywh-bugtracker -n -f FILE in v0.*
      • added ywh2bt validate
      • added ywh2bt test
      • added ywh2bt convert
      • added ywh2bt schema
    • removed command line interactive mode
    • added GUI via ywh2bt-gui command

Local development

Requirements

Installation

  • make install (or poetry install): creates a virtualenv and install dependencies

Usage

Instead of ywh2bt [command], run commands using poetry run ywh2bt [command].

Same goes for ywh2bt-gui, run poetry run ywh2bt-gui instead.

Updating User Guide

PDF and HTML versions of the User Guide are generated via Pandoc using docs/User-Guide.md as an input file.
Any changes made to docs/User-Guide.md must be followed by the execution of the command make user-guide in order to regenerate the PDF and HTML files, otherwise the CI will fail.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

ywh2bt-2.7.4.tar.gz (245.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

ywh2bt-2.7.4-py3-none-any.whl (315.8 kB view details)

Uploaded Python 3

File details

Details for the file ywh2bt-2.7.4.tar.gz.

File metadata

  • Download URL: ywh2bt-2.7.4.tar.gz
  • Upload date:
  • Size: 245.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: poetry/1.4.2 CPython/3.9.16 Linux/4.19.0-23-cloud-amd64

File hashes

Hashes for ywh2bt-2.7.4.tar.gz
Algorithm Hash digest
SHA256 a63a2c43477f79f840fc51ad098e569c34bc227f8ed1ed3a34bf2ea2bc225792
MD5 983a9bdc7437436f861e4cf8045a4786
BLAKE2b-256 83b3912671776666af9eac73cff14344a7293f8a4ecdcef2d63d688246a174ab

See more details on using hashes here.

File details

Details for the file ywh2bt-2.7.4-py3-none-any.whl.

File metadata

  • Download URL: ywh2bt-2.7.4-py3-none-any.whl
  • Upload date:
  • Size: 315.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: poetry/1.4.2 CPython/3.9.16 Linux/4.19.0-23-cloud-amd64

File hashes

Hashes for ywh2bt-2.7.4-py3-none-any.whl
Algorithm Hash digest
SHA256 3afc9c5c35628931fc43a53b58ef4476ff2e06c159c54861d7b65612f6cf1d62
MD5 064cd0b0c002000ad945afd4262250b9
BLAKE2b-256 fb8a5ec3036144e38a8b0c7624a0483ea6afc5cd4e739206815b9a11c333ecf3

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page