{"id":46728701,"url":"https://github.com/xygeni/xygeni-goat","last_synced_at":"2026-03-09T14:29:12.810Z","repository":{"id":82897422,"uuid":"559117087","full_name":"xygeni/xygeni-goat","owner":"xygeni","description":"A deliberately vulnerable repository against software supply chain attacks","archived":false,"fork":false,"pushed_at":"2024-08-15T20:03:38.000Z","size":260,"stargazers_count":3,"open_issues_count":10,"forks_count":5,"subscribers_count":2,"default_branch":"main","last_synced_at":"2024-08-15T21:49:22.794Z","etag":null,"topics":["secdevops","supply-chain-security","xygeni"],"latest_commit_sha":null,"homepage":"","language":"HCL","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/xygeni.png","metadata":{"files":{"readme":"README.adoc","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2022-10-29T05:29:25.000Z","updated_at":"2024-08-15T20:03:41.000Z","dependencies_parsed_at":null,"dependency_job_id":"19bb1b9c-80e8-4486-ae21-c9e6f9d7f303","html_url":"https://github.com/xygeni/xygeni-goat","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/xygeni/xygeni-goat","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/xygeni%2Fxygeni-goat","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/xygeni%2Fxygeni-goat/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/xygeni%2Fxygeni-goat/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/xygeni%2Fxygeni-goat/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/xygeni","download_url":"https://codeload.github.com/xygeni/xygeni-goat/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/xygeni%2Fxygeni-goat/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":30298939,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-03-09T13:46:43.843Z","status":"ssl_error","status_checked_at":"2026-03-09T13:46:42.821Z","response_time":61,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["secdevops","supply-chain-security","xygeni"],"created_at":"2026-03-09T14:29:12.161Z","updated_at":"2026-03-09T14:29:12.788Z","avatar_url":"https://github.com/xygeni.png","language":"HCL","funding_links":[],"categories":[],"sub_categories":[],"readme":"= xygeni-goat - Vulnerable repository against supply chain attacks\n:toc:\n:toc-title: Contents\n:toclevels: 1\n\nimage:https://img.shields.io/badge/maintained%20by-xygeni.io-blueviolet[Maintained by xygeni.io,link=https://xygeni.io/?utm_source=github\u0026utm_medium=organic_oss\u0026utm_campaign=xygeni-goat]\n\nA deliberately vulnerable repository against software supply chain attacks, by Xygeni.\n\n\n== Introduction\n\nimage:xygeni-goat-logo.png[xygeni-goat,220,,float=\"right\", align=\"center\", title=\"Created by Mat fine from Noun Project\"]\n\nXygeni-goat helps to understand DevOps teams the best practices to follow and which issues should be avoided, for having a good security posture, lowering the risk against software supply chain attacks. Looking at the elements reported as security flaws, you may learn about misconfigurations to avoid. IaC templates that contains insecure configurations, hardcoded secrets, unsafe tool configurations, troublesome dependencies and more are covered.\n\nThis repository is based on existing \"Goat\" projects, like OWASP https://github.com/WebGoat/WebGoat[WebGoat]. \n\n**Shear the (nefarious) goat !**\n\n*WARNING*: This repository is for educational purposes only. Do NOT attempt to use the techniques and items shown for unauthorized hacking. Do NOT deploy assets from this repository this in any environment.\n\n*DISCLAIMER*: Xygeni-goat comes with no warranties. By using xygeni-goat, you take full responsibility for any outcomes. Xygeni would not be liable of any misuse of the information and assets contained in this repository. \n\n== Getting Started\n\n=== Clone the repo, or download\n\n----\ngit clone https://github.com/xygeni/xygeni-goat.git\n----\nor\n----\ngh repo clone xygeni/xygeni-goat\n----\n\n=== Install the Xygeni scanner\n\nDownload the scanner zipfile from https://get.xygeni.io/latest/scanner/xygeni_scanner.zip and unzip it, e.g. in your `$HOME` directory (it will create a `xygeni_scanner` directory).\n\nYou may check it against the https://raw.githubusercontent.com/xygeni/xygeni/main/checksum/latest/xygeni-release.zip.sha256[SHA-256 checksum].\n\nYou need a personal or organizational https://in.xygeni.io/dashboard/configuration-panel/profile[Xygeni API token]. Set the `XYGENI_TOKEN` environment variable with the token (`export XYGENI_TOKEN=...` in Linux/macOS, or `set XYGENI_TOKEN ...` plus `setx XYGENI_TOKEN ...` in Windows).\n\nTIP: You may also set an alias to the xygeni script.\n\nFor full details, read https://docs.xygeni.io/getting-started/quick-start-with-xygeni-cli[Quick start with Xygeni CLI].\n\n=== Run the scanner on xygeni-goat\n\nRun the `scan` command over the contents in the `xygeni-goat/source` directory, or any subdirectory beneath for a partial analysis.\n\nUnder Linux / macOS:\n[source,shell]\n----\ncd xygeni-goat/source\n\"$HOME/xygeni_scanner/xygeni\" scan\n----\n\nUnder Windows (Powershell):\n\n[source,powershell]\n----\ncd xygeni-goat/source\n\"$HOME\\xygeni_scanner\\xygeni.ps1\" scan\n----\n\nOpen the referenced link to see the findings in the Xygeni dashboard !\n\nTo use other scan commands, follow the instructions in the https://docs.xygeni.io/xygeni-scanner-cli/xygeni-cli-overview[Xygeni CLI Overview].\n\n== Contributing\n\nYou may add your own vulnerable items to help others learn about additional security issues, and raise awareness on new potential attacks.\nWe recommend you to keep the existing directory structure for better categorizing those security issues. Pull Requests are welcomed !\n\nIn addition, if you want to add a new \"capture the flag\" (CTF) check, you are welcome!\n\n=== Development\n\n. Clone the repository:\n+\n----\ngit clone https://github.com/xygeni/xygeni-goat.git\n----\n+\nor\n+\n----\ngh repo clone xygeni/xygeni-goat\n----\n+\nAlternatively, you may https://docs.github.com/en/get-started/quickstart/fork-a-repo[fork the repo].\n\n. Create your topic branch\n\n. Develop your changes\n+\nWe recommend to follow the existing directory structure for categorizing the security issue. \n\n. Test your changes\n+\nIf you developed a new check, test with [TBD].\n+\nIf you created a new vulnerable element, test it with Xygeni scanner, as shown in the \u003c\u003cGetting Started,Getting Started\u003e\u003e section.\n\n. Push commits to your topic branch.\n\n. Create a pull request, using `gh pr create` command or the GitHub desktop / web UI.\n+\nAfter review, your PR will be merged.\n\n=== Add a new Capture The Flag challenge\n\n#[TBD]#\n\nEach CTF challenge has a separate directory in the `ctf` directory.\nFollow the steps below to add a CTF challenge: \n\n. Write challenge description.\n. Choose category and difficulty level.\n. Write hints for help.\n. Add a flag. Ensure that it is not accesible when solving other CTF challenges.\n. Write tests.\n. Write the solution.\n. Create a README.md in your CTF directory.\n\n== Support\n\n#[TBD]#\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fxygeni%2Fxygeni-goat","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fxygeni%2Fxygeni-goat","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fxygeni%2Fxygeni-goat/lists"}