{"id":44349921,"url":"https://github.com/timothywarner-org/globomantics-ghas-dashboard","last_synced_at":"2026-02-11T14:36:37.828Z","repository":{"id":334730708,"uuid":"1142500469","full_name":"timothywarner-org/globomantics-ghas-dashboard","owner":"timothywarner-org","description":"GitHub Advanced Security Dashboard - Teaching artifact for GH-500 certification prep | Pluralsight | Real GHAS data visualization","archived":false,"fork":false,"pushed_at":"2026-01-26T17:30:41.000Z","size":1074,"stargazers_count":0,"open_issues_count":12,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-01-27T03:34:02.743Z","etag":null,"topics":["certification","codeql","dashboard","dependabot","education","ghas","github-advanced-security","nodejs","pluralsight","react","security","training"],"latest_commit_sha":null,"homepage":"https://techtrainertim.com","language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/timothywarner-org.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":"AGENTS.md","dco":null,"cla":null},"funding":{"github":["your_github_username"],"patreon":["your_patreon_username"],"open_collective":["your_open_collective_username"],"ko_fi":["your_ko_fi_username"],"tidelift":["package_name"],"community_bridge":["your_community_bridge_project_name"],"liberapay":["your_liberapay_username"],"issuehunt":["your_issuehunt_username"],"otechie":["your_otechie_username"],"custom":["https://www.example.com/donate"]}},"created_at":"2026-01-26T13:50:36.000Z","updated_at":"2026-01-26T17:29:28.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/timothywarner-org/globomantics-ghas-dashboard","commit_stats":null,"previous_names":["timothywarner-org/globomantics-ghas-dashboard"],"tags_count":null,"template":false,"template_full_name":null,"purl":"pkg:github/timothywarner-org/globomantics-ghas-dashboard","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/timothywarner-org%2Fglobomantics-ghas-dashboard","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/timothywarner-org%2Fglobomantics-ghas-dashboard/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/timothywarner-org%2Fglobomantics-ghas-dashboard/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/timothywarner-org%2Fglobomantics-ghas-dashboard/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/timothywarner-org","download_url":"https://codeload.github.com/timothywarner-org/globomantics-ghas-dashboard/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/timothywarner-org%2Fglobomantics-ghas-dashboard/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":29335275,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-02-11T14:34:07.188Z","status":"ssl_error","status_checked_at":"2026-02-11T14:34:06.809Z","response_time":97,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["certification","codeql","dashboard","dependabot","education","ghas","github-advanced-security","nodejs","pluralsight","react","security","training"],"created_at":"2026-02-11T14:36:36.973Z","updated_at":"2026-02-11T14:36:37.819Z","avatar_url":"https://github.com/timothywarner-org.png","language":"JavaScript","funding_links":["https://github.com/sponsors/your_github_username","https://patreon.com/[\"your_patreon_username\"]","https://opencollective.com/[\"your_open_collective_username\"]","https://ko-fi.com/[\"your_ko_fi_username\"]","https://tidelift.com/funding/github/[\"package_name\"]","https://funding.communitybridge.org/projects/[\"your_community_bridge_project_name\"]","https://liberapay.com/[\"your_liberapay_username\"]","https://issuehunt.io/r/[\"your_issuehunt_username\"]","https://otechie.com/[\"your_otechie_username\"]","https://www.example.com/donate"],"categories":[],"sub_categories":[],"readme":"\u003c!-- Shields.io Badges --\u003e\n\u003cp align=\"center\"\u003e\n  \u003ca href=\"https://github.com/timothywarner-org/globomantics-ghas-dashboard/actions/workflows/ci.yml\"\u003e\u003cimg src=\"https://github.com/timothywarner-org/globomantics-ghas-dashboard/actions/workflows/ci.yml/badge.svg\" alt=\"CI Status\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://github.com/timothywarner-org/globomantics-ghas-dashboard/blob/main/LICENSE\"\u003e\u003cimg src=\"https://img.shields.io/badge/License-MIT-blue.svg\" alt=\"License: MIT\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://nodejs.org/\"\u003e\u003cimg src=\"https://img.shields.io/badge/Node.js-20%2B-339933?logo=node.js\u0026logoColor=white\" alt=\"Node.js 20+\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://github.com/timothywarner-org/globomantics-ghas-dashboard/stargazers\"\u003e\u003cimg src=\"https://img.shields.io/github/stars/timothywarner-org/globomantics-ghas-dashboard?style=social\" alt=\"GitHub Stars\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://github.com/timothywarner-org/globomantics-ghas-dashboard/network/members\"\u003e\u003cimg src=\"https://img.shields.io/github/forks/timothywarner-org/globomantics-ghas-dashboard?style=social\" alt=\"GitHub Forks\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://github.com/timothywarner-org/globomantics-ghas-dashboard/commits/main\"\u003e\u003cimg src=\"https://img.shields.io/github/last-commit/timothywarner-org/globomantics-ghas-dashboard\" alt=\"Last Commit\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://github.com/timothywarner-org/globomantics-ghas-dashboard/pulls\"\u003e\u003cimg src=\"https://img.shields.io/badge/PRs-welcome-brightgreen.svg\" alt=\"PRs Welcome\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://www.pluralsight.com/\"\u003e\u003cimg src=\"https://img.shields.io/badge/Made%20for-Pluralsight-F15B2A?logo=pluralsight\u0026logoColor=white\" alt=\"Made for Pluralsight\"\u003e\u003c/a\u003e\n\u003c/p\u003e\n\n---\n\n\u003ch1 align=\"center\"\u003e\n  :robot: Globomantics GHAS Dashboard\n\u003c/h1\u003e\n\n\u003ch3 align=\"center\"\u003e\n  \u003cem\u003eA Real-World Training Repository for GitHub Advanced Security (GH-500) Certification\u003c/em\u003e\n\u003c/h3\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003cstrong\u003eGlobomantics Robotics - Platform Engineering Division\u003c/strong\u003e\n\u003c/p\u003e\n\n---\n\n## :dart: What Is This?\n\nA **real, non-toy web application** that visualizes GitHub Advanced Security data for its own repository. Built as a **teaching artifact** for **GH-500: GitHub Advanced Security** certification preparation on Pluralsight.\n\nThis is not a simple demo - it's a full-stack React + Express application that *practices what it preaches* by monitoring **its own security posture**.\n\n---\n\n## :brain: The \"Dogfooding\" Architecture\n\nThis dashboard demonstrates a **self-referential security monitoring pattern** - it intentionally contains vulnerable dependencies so learners can observe *real* GHAS features in action:\n\n```\n+=====================================================================+\n|                    SELF-REFERENTIAL DEMO ARCHITECTURE               |\n+=====================================================================+\n|                                                                     |\n|  +---------------------------------------------------------------+  |\n|  |                     package.json                               |  |\n|  |  Contains INTENTIONALLY VULNERABLE dependencies:               |  |\n|  |  - lodash@4.17.20, axios@0.21.1, node-fetch@2.6.1             |  |\n|  |  - minimist@1.2.5, tar@4.4.13, glob-parent@5.1.1              |  |\n|  +---------------------------------------------------------------+  |\n|                              |                                      |\n|                              v                                      |\n|  +---------------------------------------------------------------+  |\n|  |              GitHub Advanced Security (GHAS)                   |  |\n|  |  - Dependency Graph parses manifest                            |  |\n|  |  - Advisory Database matches CVEs                              |  |\n|  |  - Dependabot creates alerts                                   |  |\n|  +---------------------------------------------------------------+  |\n|                              |                                      |\n|                              v                                      |\n|  +---------------------------------------------------------------+  |\n|  |                 Dashboard Express API                          |  |\n|  |  GET /api/alerts      -\u003e Fetches Dependabot alerts via Octokit |  |\n|  |  GET /api/dependencies -\u003e Parses package.json + correlates CVEs|  |\n|  +---------------------------------------------------------------+  |\n|                              |                                      |\n|                              v                                      |\n|  +---------------------------------------------------------------+  |\n|  |                   React Frontend (Vite)                        |  |\n|  |  Displays: Real CVEs | Real Alerts | Real Security Data       |  |\n|  |  Learners see LIVE GHAS data from THIS repository              |  |\n|  +---------------------------------------------------------------+  |\n|                                                                     |\n+=====================================================================+\n            Learners observe the COMPLETE supply chain security loop\n```\n\n---\n\n## :mortar_board: GH-500 Exam Domain Alignment\n\nThe GH-500 certification covers five domains. This dashboard is optimized for **Domain 3**, which carries the highest exam weight:\n\n| Domain | Weight | Topic | Dashboard Coverage |\n|:------:|:------:|-------|-------------------|\n| 1 | 15% | **GHAS Features Overview** | :white_check_mark: Full visibility into all GHAS features |\n| 2 | 15% | **Secret Scanning** | :construction: Planned for future release |\n| **3** | **35%** | **Dependencies, Alerts, Dependency Review** | :star: **PRIMARY FOCUS** - Full coverage with live demos |\n| 4 | 25% | **CodeQL Analysis** | :white_check_mark: CodeQL workflow with security-extended queries |\n| 5 | 10% | **Best Practices** | :white_check_mark: Workflow best practices demonstrated |\n\n\u003e :bulb: **Exam Tip:** Domain 3 is the largest portion of the exam at 35%. This dashboard provides hands-on experience with every concept in that domain.\n\n---\n\n## :rocket: Quick Start\n\n### Prerequisites\n\n| Requirement | Details |\n|-------------|---------|\n| **Node.js** | Version 20.0.0 or higher |\n| **GitHub PAT** | Personal Access Token with `repo` and `security_events` scopes |\n| **Git** | For cloning the repository |\n\n### Installation\n\n```bash\n# Clone the repository\ngit clone https://github.com/timothywarner-org/globomantics-ghas-dashboard.git\ncd globomantics-ghas-dashboard\n\n# Install dependencies\nnpm install\n\n# Configure environment variables\ncp .env.example .env\n# Edit .env and add your GITHUB_TOKEN\n\n# Start development servers\nnpm run dev\n```\n\n### Access the Application\n\n| Service | URL | Description |\n|---------|-----|-------------|\n| **Frontend** | http://localhost:5173 | React dashboard UI |\n| **Backend API** | http://localhost:3001 | Express REST API |\n\n---\n\n## :warning: Intentional Vulnerabilities\n\n\u003e **EDUCATIONAL PURPOSE ONLY** - This repository contains **pinned vulnerable dependencies** to trigger GHAS features. **Do NOT use these versions in production!**\n\n| Package | Version | CVE | Severity | Vulnerability Type |\n|---------|:-------:|-----|:--------:|-------------------|\n| `lodash` | 4.17.20 | CVE-2021-23337 | :red_circle: **Critical** | Command Injection |\n| `lodash` | 4.17.20 | CVE-2020-28500 | :orange_circle: High | ReDoS |\n| `minimist` | 1.2.5 | CVE-2021-44906 | :red_circle: **Critical** | Prototype Pollution |\n| `axios` | 0.21.1 | CVE-2021-3749 | :orange_circle: High | ReDoS |\n| `node-fetch` | 2.6.1 | CVE-2022-0235 | :orange_circle: High | Information Exposure |\n| `tar` | 4.4.13 | CVE-2021-32803 | :orange_circle: High | Arbitrary File Write |\n| `tar` | 4.4.13 | CVE-2021-32804 | :orange_circle: High | Arbitrary File Write |\n| `glob-parent` | 5.1.1 | CVE-2020-28469 | :orange_circle: High | ReDoS |\n| `trim-newlines` | 3.0.0 | CVE-2021-33623 | :orange_circle: High | ReDoS |\n| `path-parse` | 1.0.6 | CVE-2021-23343 | :orange_circle: High | ReDoS |\n\nThese packages exist **solely** to generate Dependabot alerts and demonstrate the dependency review action.\n\n---\n\n## :building_construction: Architecture Overview\n\n### Tech Stack\n\n```\n+---------------------------+     +---------------------------+\n|      FRONTEND             |     |       BACKEND             |\n+---------------------------+     +---------------------------+\n| React 18                  |     | Express 4.18              |\n| Vite 5 (dev server)       |     | Octokit REST Client       |\n| TanStack Query            |     | CORS + Helmet middleware  |\n| Tailwind CSS 3.4          |     | Rate limiting             |\n| Recharts (visualizations) |     | In-memory caching         |\n| Lucide React (icons)      |     |                           |\n+---------------------------+     +---------------------------+\n       Port 5173                        Port 3001\n```\n\n### Project Structure\n\n```\nglobomantics-ghas-dashboard/\n├── .github/\n│   ├── workflows/\n│   │   ├── ci.yml                 # Build/test pipeline\n│   │   ├── dependency-review.yml  # Blocks PRs with new vulns\n│   │   └── codeql.yml             # JavaScript security scanning\n│   └── dependabot.yml             # Automated updates config\n├── src/\n│   ├── client/                    # React frontend (Vite)\n│   │   ├── components/            # UI components\n│   │   ├── pages/                 # Route pages\n│   │   ├── hooks/                 # Custom React hooks\n│   │   └── api/                   # API client functions\n│   └── server/                    # Express backend\n│       ├── routes/                # API route handlers\n│       ├── github/                # Octokit client setup\n│       └── middleware/            # Express middleware\n├── docs/\n│   ├── DEMO-RUNBOOK-M5.md         # Module 5 demo script\n│   └── DEMO-RUNBOOK-M6.md         # Module 6 demo script\n├── package.json                   # Includes intentional vulns\n└── README.md                      # You are here!\n```\n\n### API Endpoints\n\n| Endpoint | Method | Description |\n|----------|:------:|-------------|\n| `/api/repo` | GET | Repository metadata and GHAS feature status |\n| `/api/alerts` | GET | Dependabot alerts with severity breakdown |\n| `/api/dependencies` | GET | Parsed dependencies with CVE correlation |\n| `/api/pull-requests` | GET | PRs with dependency changes and review status |\n\n---\n\n## :gear: GitHub Actions Workflows\n\nThis repository includes three workflows that demonstrate GHAS concepts:\n\n### 1. CI Pipeline (`ci.yml`)\n\n**Purpose:** Standard build and test validation\n\n```yaml\n- Runs on: push and pull_request to main\n- Steps: Checkout → Setup Node 20 → Install → Lint → Test → Build\n```\n\n**Teaching Value:** Shows baseline CI that integrates with security workflows.\n\n---\n\n### 2. Dependency Review (`dependency-review.yml`)\n\n**Purpose:** :shield: **Proactive PR-time security gate** (Domain 3)\n\n```yaml\n- uses: actions/dependency-review-action@v4\n  with:\n    fail-on-severity: high           # Block high/critical CVEs\n    deny-licenses: GPL-3.0, AGPL-3.0 # Block copyleft licenses\n    comment-summary-in-pr: always    # Post findings on PR\n    fail-on-scopes: runtime, development\n```\n\n**Teaching Value:** Demonstrates shift-left security by blocking vulnerable dependencies *before* they merge.\n\n\u003e :bulb: **Exam Tip:** The dependency review action is **proactive** (blocks at PR time), while Dependabot alerts are **reactive** (notify after merge).\n\n---\n\n### 3. CodeQL Analysis (`codeql.yml`)\n\n**Purpose:** :mag: Semantic code scanning for security vulnerabilities (Domain 4)\n\n```yaml\n- uses: github/codeql-action/init@v3\n  with:\n    languages: javascript-typescript\n    queries: security-extended       # Enhanced query suite\n```\n\n**Teaching Value:** Shows how CodeQL builds a database from source code and runs security queries.\n\n\u003e :bulb: **Exam Tip:** CodeQL runs on push, PR, and schedule (weekly) to catch newly discovered vulnerability patterns.\n\n---\n\n## :book: Demo Runbooks\n\nDetailed step-by-step demo scripts for Pluralsight recordings:\n\n| Module | Document | Duration | Topics |\n|:------:|----------|:--------:|--------|\n| **5** | [DEMO-RUNBOOK-M5.md](docs/DEMO-RUNBOOK-M5.md) | 10-13 min | Dependency Graph, SBOM Export, Alert Mechanics |\n| **6** | [DEMO-RUNBOOK-M6.md](docs/DEMO-RUNBOOK-M6.md) | 10-13 min | Dependabot Config, Grouped Updates, Dependency Review Action |\n\nEach runbook includes:\n- Prerequisites checklist\n- Click-by-click navigation\n- Talking points and exam tips\n- PowerShell/CLI commands\n- Troubleshooting guides\n\n---\n\n## :key: Environment Variables\n\n| Variable | Required | Default | Description |\n|----------|:--------:|---------|-------------|\n| `GITHUB_TOKEN` | :white_check_mark: Yes | - | GitHub PAT with `repo` and `security_events` scopes |\n| `GITHUB_OWNER` | No | `timothywarner-org` | Repository owner/organization |\n| `GITHUB_REPO` | No | `globomantics-ghas-dashboard` | Repository name |\n| `PORT` | No | `3001` | Backend server port |\n| `CACHE_TTL` | No | `300000` | API cache TTL in milliseconds (5 min) |\n\n### Creating a GitHub Personal Access Token\n\n1. Go to **GitHub Settings** \u003e **Developer settings** \u003e **Personal access tokens** \u003e **Tokens (classic)**\n2. Click **Generate new token (classic)**\n3. Select scopes:\n   - :white_check_mark: `repo` (Full control of private repositories)\n   - :white_check_mark: `security_events` (Read and write security events)\n4. Copy the token to your `.env` file\n\n---\n\n## :busts_in_silhouette: Contributing\n\nThis is a **teaching artifact** for Pluralsight courses. Contributions that enhance the educational value are welcome!\n\n### Contribution Guidelines\n\n| Category | Welcome? | Examples |\n|----------|:--------:|----------|\n| Bug fixes | :white_check_mark: Yes | API errors, UI issues |\n| Documentation | :white_check_mark: Yes | Typos, clarifications, exam tips |\n| New GHAS demos | :white_check_mark: Yes | Secret scanning, code scanning rules |\n| Production hardening | :x: No | Updating vulnerable packages defeats the purpose! |\n\n### How to Contribute\n\n1. Fork the repository\n2. Create a feature branch (`git checkout -b feature/amazing-demo`)\n3. Commit your changes (`git commit -m 'Add amazing demo'`)\n4. Push to the branch (`git push origin feature/amazing-demo`)\n5. Open a Pull Request\n\n\u003e :warning: **Important:** Do not submit PRs that update the intentionally vulnerable packages. The Dependency Review Action will block them anyway!\n\n---\n\n## :teacher: Author\n\n\u003ctable\u003e\n  \u003ctr\u003e\n    \u003ctd align=\"center\"\u003e\n      \u003cstrong\u003eTim Warner\u003c/strong\u003e\u003cbr\u003e\n      \u003cem\u003eMicrosoft MVP | Pluralsight Author | Cloud Security Trainer\u003c/em\u003e\u003cbr\u003e\u003cbr\u003e\n      :email: \u003ca href=\"mailto:tim@techtrainertim.com\"\u003etim@techtrainertim.com\u003c/a\u003e\u003cbr\u003e\n      :globe_with_meridians: \u003ca href=\"https://techtrainertim.com\"\u003etechtrainertim.com\u003c/a\u003e\u003cbr\u003e\n      :briefcase: \u003ca href=\"https://www.linkedin.com/in/intpro/\"\u003eLinkedIn\u003c/a\u003e\u003cbr\u003e\n      :bird: \u003ca href=\"https://twitter.com/TechTrainerTim\"\u003e@TechTrainerTim\u003c/a\u003e\n    \u003c/td\u003e\n  \u003c/tr\u003e\n\u003c/table\u003e\n\n---\n\n## :page_facing_up: License\n\nThis project is licensed under the **MIT License** - see the [LICENSE](LICENSE) file for details.\n\n```\nMIT License\n\nCopyright (c) 2026 Timothy Warner Organization\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction...\n```\n\n---\n\n## :link: Resources\n\n### Official Documentation\n- [GitHub Advanced Security Documentation](https://docs.github.com/en/get-started/learning-about-github/about-github-advanced-security)\n- [Dependabot Documentation](https://docs.github.com/en/code-security/dependabot)\n- [CodeQL Documentation](https://codeql.github.com/docs/)\n- [GitHub Advisory Database](https://github.com/advisories)\n\n### Certification\n- [GitHub Certifications Overview](https://resources.github.com/learn/certifications/)\n- [GH-500: GitHub Advanced Security Exam](https://resources.github.com/learn/certifications/)\n\n### Pluralsight\n- [Pluralsight GitHub Learning Paths](https://www.pluralsight.com/)\n\n---\n\n\u003cp align=\"center\"\u003e\n  \u003cstrong\u003eBuilt for \u003ca href=\"https://resources.github.com/learn/certifications/\"\u003eGH-500: GitHub Advanced Security Certification\u003c/a\u003e Preparation\u003c/strong\u003e\u003cbr\u003e\n  \u003cem\u003eGlobomantics Robotics - Platform Engineering Division\u003c/em\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  :star: Star this repo if it helped your certification journey! :star:\n\u003c/p\u003e\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftimothywarner-org%2Fglobomantics-ghas-dashboard","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ftimothywarner-org%2Fglobomantics-ghas-dashboard","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftimothywarner-org%2Fglobomantics-ghas-dashboard/lists"}