Security & Compliance
How RAPS protects your builds, your credentials, and your supply chain.
Reporting a Vulnerability
If you discover a security vulnerability, please do not open a public issue. Use one of the following methods:
Go to the Security tab and click "Report a vulnerability."
security@autodesk.com
— subject: [APS CLI Security]
Standards & Frameworks
RAPS security practices are aligned with industry-recognized frameworks.
Supply-chain Levels for Software Artifacts
RAPS meets SLSA Build Level 2 requirements:
builds run on GitHub-hosted runners, provenance is generated automatically via
actions/attest-build-provenance,
and all artifacts are verifiably linked to source commits.
OWASP ASVS Alignment
While RAPS is a CLI tool (not a web application), its security controls map to relevant OWASP ASVS v4.0 categories:
CWE Top 25 Coverage
RAPS CI includes CodeQL (security-extended queries) and Semgrep (p/security-audit) which scan for
CWE Top 25 weakness categories
including injection flaws, buffer errors, improper input validation, and authentication issues.
Rust's memory safety model additionally eliminates entire classes of CWEs by design (buffer overflow, use-after-free, data races).
OpenSSF Scorecard
Weekly OpenSSF Scorecard assessments evaluate the project across security dimensions including branch protection, dependency updates, CI tests, code review, pinned dependencies, SAST, token permissions, and vulnerability disclosure. Results are published to GitHub Security tab as SARIF.
Data Privacy & GDPR
RAPS is designed with privacy by default.
Supply Chain Security
Every release includes verifiable provenance and a full software bill of materials.
CycloneDX SBOM
Every release ships with a CycloneDX JSON SBOM attached to the GitHub Release, listing all direct and transitive dependencies.
SLSA Build L2 Provenance
Builds generate SLSA provenance attestations via GitHub Actions, proving artifacts were built from the claimed source.
Pinned Actions
All GitHub Actions are pinned by full commit SHA, preventing supply-chain attacks via tag mutation.
OIDC Publishing
PyPI packages use OIDC trusted publishing — no long-lived API tokens, only ephemeral OIDC identity tokens from GitHub Actions.
Static Analysis & Scanning
Multiple layers of automated analysis catch vulnerabilities before they reach users.
| Tool | Purpose | Frequency |
|---|---|---|
| CodeQL | Semantic SAST with security-extended + security-and-quality queries | Every push/PR + weekly |
| Semgrep | Rust-specific and security-audit rule packs plus custom rules | Every PR + weekly |
| cargo clippy | Lint-level analysis with -D warnings | Every push/PR |
| cargo-audit | RustSec advisory database checks for known vulnerabilities | Every push/PR |
| cargo-deny | License compliance, advisory checks, and duplicate detection | Every push/PR |
| Gitleaks | Secret detection across full commit history | Every push/PR |
| FOSSA | License scanning and open-source compliance | Every push/PR |
| OpenSSF Scorecard | Holistic project security health assessment | Weekly + on push to main |
Continuous Fuzzing
Nightly fuzz testing with cargo-fuzz probes edge cases that unit tests miss.
Each target runs for 5 minutes nightly. Crash artifacts are automatically uploaded for triage.
Testing & Quality
Cross-Platform CI
Tests run on Ubuntu, macOS, and Windows on every push and PR via cargo-nextest.
Code Coverage
Coverage tracked via cargo-llvm-cov and reported to Codecov with patch-level thresholds.
Branch Protection
Merges require all CI checks to pass: check, test, fmt, clippy, docs, license-scan, audit, deny, secrets, and typos.
Install Verification
Post-release CI verifies install scripts on all platforms, ensuring downloads aren't corrupted or tampered with.
Credential Security
RAPS handles APS credentials with care. Follow these best practices:
APS_CLIENT_ID and APS_CLIENT_SECRET out of version control..env files over hardcoding secrets.License Compliance
RAPS is licensed under Apache-2.0. All dependencies must use one of these approved licenses, enforced by cargo-deny:
Scope
In Scope
- ✓ The RAPS CLI codebase
- ✓ Dependencies managed by this project
- ✓ GitHub Actions workflows
- ✓ Install scripts (install.sh, install.ps1)
Out of Scope
- — Autodesk Platform Services APIs themselves
- — Social engineering attacks
- — Denial of service attacks
- — Issues requiring physical access
Found something?
We appreciate responsible disclosure. Researchers who help keep RAPS secure may be credited in security advisories.