Ця сторінка ще не перекладена українською. Показано англійську версію. Переглянути англійською
OpenSSF Scorecard SLSA Build L2 OWASP ASVS CWE Top 25

Security & Compliance

How RAPS protects your builds, your credentials, and your supply chain.

Reporting a Vulnerability

If you discover a security vulnerability, please do not open a public issue. Use one of the following methods:

1.
GitHub Security Advisories (preferred)

Go to the Security tab and click "Report a vulnerability."

2.
Email

security@autodesk.com — subject: [APS CLI Security]

48h
Initial Response
7 days
Status Update
v4.x
Supported

Standards & Frameworks

RAPS security practices are aligned with industry-recognized frameworks.

SLSA v1.0

Supply-chain Levels for Software Artifacts

RAPS meets SLSA Build Level 2 requirements: builds run on GitHub-hosted runners, provenance is generated automatically via actions/attest-build-provenance, and all artifacts are verifiably linked to source commits.

Build L2 Hosted build platform Signed provenance
OWASP

OWASP ASVS Alignment

While RAPS is a CLI tool (not a web application), its security controls map to relevant OWASP ASVS v4.0 categories:

✓ V1 Architecture — Minimal dependencies, least-privilege permissions in CI
✓ V2 Authentication — OAuth 2.0 with PKCE, secure token storage via OS keychain
✓ V3 Session — Token expiry enforcement, no persistent plaintext credentials
✓ V5 Validation — Input fuzzing, URL validation, config parsing hardening
✓ V6 Cryptography — TLS-only via rustls, no custom crypto implementations
✓ V10 Malicious Code — SAST scanning, dependency auditing, secret detection
✓ V14 Configuration — Secure defaults, no hardcoded secrets, env-based config
CWE

CWE Top 25 Coverage

RAPS CI includes CodeQL (security-extended queries) and Semgrep (p/security-audit) which scan for CWE Top 25 weakness categories including injection flaws, buffer errors, improper input validation, and authentication issues. Rust's memory safety model additionally eliminates entire classes of CWEs by design (buffer overflow, use-after-free, data races).

Memory-safe by default No unsafe blocks in application code Automated CWE scanning
OpenSSF

OpenSSF Scorecard

Weekly OpenSSF Scorecard assessments evaluate the project across security dimensions including branch protection, dependency updates, CI tests, code review, pinned dependencies, SAST, token permissions, and vulnerability disclosure. Results are published to GitHub Security tab as SARIF.

Data Privacy & GDPR

RAPS is designed with privacy by default.

✓
No telemetry or analytics
RAPS does not collect, transmit, or store any usage data. Zero phone-home behavior.
✓
No personal data collection
RAPS does not store PII. OAuth tokens are the only sensitive data, held locally in your OS keychain or platform-specific secure storage.
✓
Local-first architecture
All processing happens on your machine. RAPS communicates only with Autodesk Platform Services APIs that you explicitly invoke.
✓
GDPR-compatible by design
Since RAPS collects no personal data and stores no data on external servers, there are no GDPR data processing concerns from the CLI itself. Any data exchanged with APS APIs is governed by your Autodesk agreement.

Supply Chain Security

Every release includes verifiable provenance and a full software bill of materials.

📦

CycloneDX SBOM

Every release ships with a CycloneDX JSON SBOM attached to the GitHub Release, listing all direct and transitive dependencies.

🔏

SLSA Build L2 Provenance

Builds generate SLSA provenance attestations via GitHub Actions, proving artifacts were built from the claimed source.

📌

Pinned Actions

All GitHub Actions are pinned by full commit SHA, preventing supply-chain attacks via tag mutation.

🔑

OIDC Publishing

PyPI packages use OIDC trusted publishing — no long-lived API tokens, only ephemeral OIDC identity tokens from GitHub Actions.

Static Analysis & Scanning

Multiple layers of automated analysis catch vulnerabilities before they reach users.

Tool Purpose Frequency
CodeQL Semantic SAST with security-extended + security-and-quality queries Every push/PR + weekly
Semgrep Rust-specific and security-audit rule packs plus custom rules Every PR + weekly
cargo clippy Lint-level analysis with -D warnings Every push/PR
cargo-audit RustSec advisory database checks for known vulnerabilities Every push/PR
cargo-deny License compliance, advisory checks, and duplicate detection Every push/PR
Gitleaks Secret detection across full commit history Every push/PR
FOSSA License scanning and open-source compliance Every push/PR
OpenSSF Scorecard Holistic project security health assessment Weekly + on push to main

Continuous Fuzzing

Nightly fuzz testing with cargo-fuzz probes edge cases that unit tests miss.

fuzz_url_validation
Input URL parsing
fuzz_config_parsing
Configuration files
fuzz_json_parsing
API response handling

Each target runs for 5 minutes nightly. Crash artifacts are automatically uploaded for triage.

Testing & Quality

Cross-Platform CI

Tests run on Ubuntu, macOS, and Windows on every push and PR via cargo-nextest.

Code Coverage

Coverage tracked via cargo-llvm-cov and reported to Codecov with patch-level thresholds.

Branch Protection

Merges require all CI checks to pass: check, test, fmt, clippy, docs, license-scan, audit, deny, secrets, and typos.

Install Verification

Post-release CI verifies install scripts on all platforms, ensuring downloads aren't corrupted or tampered with.

Credential Security

RAPS handles APS credentials with care. Follow these best practices:

✓
Never commit credentials
Keep APS_CLIENT_ID and APS_CLIENT_SECRET out of version control.
✓
Use environment variables or .env files
Prefer environment variables or .env files over hardcoding secrets.
✓
Rotate credentials regularly
Periodically rotate your APS application credentials.
✓
Review OAuth scopes
Only grant necessary scopes and permissions to your APS application.
✓
Secure token storage
RAPS stores tokens in platform-specific secure directories. Be aware of file permissions on shared systems.

License Compliance

RAPS is licensed under Apache-2.0. All dependencies must use one of these approved licenses, enforced by cargo-deny:

Apache-2.0 MIT BSD-2-Clause BSD-3-Clause BSL-1.0 ISC MPL-2.0 OpenSSL Zlib Unicode-3.0 Unicode-DFS-2016

Scope

In Scope

  • ✓ The RAPS CLI codebase
  • ✓ Dependencies managed by this project
  • ✓ GitHub Actions workflows
  • ✓ Install scripts (install.sh, install.ps1)

Out of Scope

  • — Autodesk Platform Services APIs themselves
  • — Social engineering attacks
  • — Denial of service attacks
  • — Issues requiring physical access

Found something?

We appreciate responsible disclosure. Researchers who help keep RAPS secure may be credited in security advisories.