{"id":13542639,"url":"https://github.com/dvershinin/gixy","last_synced_at":"2025-04-02T10:31:14.874Z","repository":{"id":65284394,"uuid":"198842952","full_name":"dvershinin/gixy","owner":"dvershinin","description":"NGINX configuration static analyzer","archived":false,"fork":true,"pushed_at":"2025-03-18T18:22:34.000Z","size":982,"stargazers_count":892,"open_issues_count":10,"forks_count":14,"subscribers_count":8,"default_branch":"master","last_synced_at":"2025-03-29T21:41:22.353Z","etag":null,"topics":["checker","configuration","linter","linting","nginx","nginx-configuration","python","security","server"],"latest_commit_sha":null,"homepage":"https://gixy.getpagespeed.com","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":"yandex/gixy","license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/dvershinin.png","metadata":{"files":{"readme":"README.RU.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null},"funding":{"github":"GetPageSpeed","patreon":"getpagespeed","open_collective":null,"ko_fi":null,"tidelift":null,"community_bridge":null,"liberapay":null,"issuehunt":null,"otechie":null,"lfx_crowdfunding":null,"custom":null}},"created_at":"2019-07-25T14:05:35.000Z","updated_at":"2025-03-29T11:38:11.000Z","dependencies_parsed_at":"2023-02-09T23:00:37.777Z","dependency_job_id":null,"html_url":"https://github.com/dvershinin/gixy","commit_stats":null,"previous_names":[],"tags_count":13,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/dvershinin%2Fgixy","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/dvershinin%2Fgixy/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/dvershinin%2Fgixy/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/dvershinin%2Fgixy/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/dvershinin","download_url":"https://codeload.github.com/dvershinin/gixy/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":246796918,"owners_count":20835467,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["checker","configuration","linter","linting","nginx","nginx-configuration","python","security","server"],"created_at":"2024-08-01T10:01:13.452Z","updated_at":"2025-04-02T10:31:14.860Z","avatar_url":"https://github.com/dvershinin.png","language":"Python","funding_links":["https://github.com/sponsors/GetPageSpeed","https://patreon.com/getpagespeed"],"categories":["Python","others","Tools","Configuration and tooling"],"sub_categories":["Lua Modules"],"readme":"GIXY\n====\n[![Mozilla Public License 2.0](https://img.shields.io/github/license/dvershinin/gixy.svg?style=flat-square)](https://github.com/dvershinin/gixy/blob/master/LICENSE)\n[![Build Status](https://img.shields.io/travis/dvershinin/gixy.svg?style=flat-square)](https://travis-ci.org/dvershinin/gixy)\n[![Your feedback is greatly appreciated](https://img.shields.io/maintenance/yes/2018.svg?style=flat-square)](https://github.com/dvershinin/gixy/issues/new)\n[![GitHub issues](https://img.shields.io/github/issues/dvershinin/gixy.svg?style=flat-square)](https://github.com/dvershinin/gixy/issues)\n[![GitHub pull requests](https://img.shields.io/github/issues-pr/dvershinin/gixy.svg?style=flat-square)](https://github.com/dvershinin/gixy/pulls)\n\n# Overview\n\u003cimg style=\"float: right;\" width=\"192\" height=\"192\" src=\"/docs/gixy.png\" alt=\"Gixy logo\"\u003e\n\nGixy — это утилита для анализа конфигурации Nginx.\nБольшей частью служит для обнаружения проблем безопасности, но может искать и иные ошибки.\n\nОфициально поддерживаются версии Python \u003e= 3.6.\n\n\u0026nbsp;\n# Что умеет\nНа текущий момент Gixy способна обнаружить:\n\n*   [[ssrf] Server Side Request Forgery](https://github.com/dvershinin/gixy/blob/master/docs/ru/plugins/ssrf.md)\n*   [[http_splitting] HTTP Splitting](https://github.com/dvershinin/gixy/blob/master/docs/ru/plugins/httpsplitting.md)\n*   [[origins] Проблемы валидации referrer/origin](https://github.com/dvershinin/gixy/blob/master/docs/ru/plugins/origins.md)\n*   [[add_header_redefinition] Переопределение \"вышестоящих\" заголовков ответа директивой \"add_header\"](https://github.com/dvershinin/gixy/blob/master/docs/ru/plugins/addheaderredefinition.md)\n*   [[host_spoofing] Подделка заголовка запроса Host](https://github.com/dvershinin/gixy/blob/master/docs/ru/plugins/hostspoofing.md)\n*   [[valid_referrers] none in valid_referrers](https://github.com/dvershinin/gixy/blob/master/docs/ru/plugins/validreferers.md)\n*   [[add_header_multiline] Многострочные заголовки ответа](https://github.com/dvershinin/gixy/blob/master/docs/ru/plugins/addheadermultiline.md)\n*   [[alias_traversal] Path traversal при использовании alias](https://github.com/dvershinin/gixy/blob/master/docs/ru/plugins/aliastraversal.md)\n\nПроблемы, которым Gixy только учится, можно найти в [Issues с меткой \"new plugin\"](https://github.com/dvershinin/gixy/issues?q=is%3Aissue+is%3Aopen+label%3A%22new+plugin%22)\n\n# Установка\nНаиболее простой способ установки Gixy — воспользоваться pip для установки из [PyPI](https://pypi.python.org/pypi/gixy):\n```bash\npip install gixy\n```\n\n# Использование\nПосле установки должна стать доступна консольная утилита `gixy`.\nПо умолчанию Gixy ищет конфигурацию по стандартному пути `/etc/nginx/nginx.conf`, однако вы можете указать специфичное расположение:\n```\n$ gixy /etc/nginx/nginx.conf\n\n==================== Results ===================\n\nProblem: [http_splitting] Possible HTTP-Splitting vulnerability.\nDescription: Using variables that can contain \"\\n\" may lead to http injection.\nAdditional info: https://github.com/dvershinin/gixy/wiki/ru/httpsplitting\nReason: At least variable \"$action\" can contain \"\\n\"\nPseudo config:\ninclude /etc/nginx/sites/default.conf;\n\n\tserver {\n\n\t\tlocation ~ /v1/((?\u003caction\u003e[^.]*)\\.json)?$ {\n\t\t\tadd_header X-Action $action;\n\t\t}\n\t}\n\n\n==================== Summary ===================\nTotal issues:\n    Unspecified: 0\n    Low: 0\n    Medium: 0\n    High: 1\n```\n\nGixy умеет обрабатывать директиву `include` и попробует максимально корректно обработать все зависимости, если что-то пошло не так, можно попробовать запустить `gixy` с флагом `-d` для вывода дополнительной информации.\nВсе доступные опции:\n```\n$ gixy -h\nusage: gixy [-h] [-c CONFIG_FILE] [--write-config CONFIG_OUTPUT_PATH]\n            [-v] [-l] [-f {console,text,json}] [-o OUTPUT_FILE] [-d]\n            [--tests TESTS] [--skips SKIPS] [--disable-includes]\n            [--origins-domains domains]\n            [--origins-https-only https_only]\n            [--add-header-redefinition-headers headers]\n            [nginx.conf]\n\nGixy - a Nginx configuration [sec]analyzer\n\npositional arguments:\n  nginx.conf            Path to nginx.conf, e.g. /etc/nginx/nginx.conf\n\noptional arguments:\n  -h, --help            show this help message and exit\n  -c CONFIG_FILE, --config CONFIG_FILE\n                        config file path\n  --write-config CONFIG_OUTPUT_PATH\n                        takes the current command line args and writes them\n                        out to a config file at the given path, then exits\n  -v, --version         show program's version number and exit\n  -l, --level           Report issues of a given severity level or higher (-l\n                        for LOW, -ll for MEDIUM, -lll for HIGH)\n  -f {console,text,json}, --format {console,text,json}\n                        Specify output format\n  -o OUTPUT_FILE, --output OUTPUT_FILE\n                        Write report to file\n  -d, --debug           Turn on debug mode\n  --tests TESTS         Comma-separated list of tests to run\n  --skips SKIPS         Comma-separated list of tests to skip\n  --disable-includes    Disable \"include\" directive processing\n\nplugins options:\n  --origins-domains domains\n                        Default: *\n  --origins-https-only https_only\n                        Default: False\n  --add-header-redefinition-headers headers\n                        Default: content-security-policy,x-xss-\n                        protection,x-frame-options,x-content-type-\n                        options,strict-transport-security,cache-control\n\n\navailable plugins:\n\thost_spoofing\n\tadd_header_multiline\n\thttp_splitting\n\tvalid_referers\n\torigins\n\tadd_header_redefinition\n\tssrf\n```\n\n# Contributing\nContributions to Gixy are always welcome! You can help us in different ways:\n  * Open an issue with suggestions for improvements and errors you're facing;\n  * Fork this repository and submit a pull request;\n  * Improve the documentation.\n\nCode guidelines:\n  * Python code style should follow [pep8](https://www.python.org/dev/peps/pep-0008/) standards whenever possible;\n  * Pull requests with new plugins must have unit tests for them.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fdvershinin%2Fgixy","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fdvershinin%2Fgixy","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fdvershinin%2Fgixy/lists"}