forked from surrealdb/surrealdb
-
Notifications
You must be signed in to change notification settings - Fork 0
80 lines (70 loc) · 3.07 KB
/
Copy pathautomoderator.yaml
File metadata and controls
80 lines (70 loc) · 3.07 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
name: Automatically Moderate Github Comments
on:
issue_comment:
types: [created, edited]
permissions: read-all
jobs:
automoderator:
permissions:
issues: write
runs-on: ["ubuntu-latest"]
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 # v2.16.0
with:
egress-policy: audit
- name: Redact Suspicious Links
# This step contains code from "Comment-Filter", licensed under MIT by Martin Leduc
# Source: https://github.com/DecimalTurn/Comment-Filter/blob/v0.1.0/LICENSE
uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8 (Actions must be pinned by commit hash)
with:
script: |
const comment = context.payload.comment
const { owner, repo } = context.repo
console.log('Repository owner:', owner)
console.log('Repository name:', repo)
console.log('Comment body:', comment.body)
// Array of regex patterns and their replacements
const regexReplacements = [
// File Sharing
{
pattern: /(www\.)?(box|dropbox|mediafire|sugarsync|tresorit|hightail|opentext|sharefile|citrixsharefile|icloud|onedrive|1drv|mega)(\.com|\.co\.nz)\/[^\s\)]+/g,
replacement: '[REDACTED]'
},
// Google Drive
{
pattern: /drive\.google\.com\/[^\s\)]+/g,
replacement: '[REDACTED]'
},
// Link Shorteners
{
pattern: /(www\.)?(bit\.ly|t\.co|tinyurl\.com|goo\.gl|ow\.ly|buff\.ly|is\.gd|soo\.gd|t2mio|bl\.ink|clck\.ru|shorte\.st|cutt\.ly|v\.gd|qr\.ae|rb\.gy|rebrand\.ly|tr\.im|shorturl\.at|lnkd\.in)\/[^\s\)]+/g,
replacement: '[REDACTED]'
},
];
// Iterate through each regex and replace matches in the comment body
let updatedBody = comment.body;
regexReplacements.forEach(({ pattern, replacement }) => {
if (pattern.test(updatedBody)) {
console.log(`Pattern found: ${pattern}`);
updatedBody = updatedBody.replace(pattern, replacement);
}
});
// If the comment body was updated, edit the comment
if (updatedBody !== comment.body) {
console.log('Updated comment body:', updatedBody);
// Append edition notice to the body
updatedBody = updatedBody + '\n\n' +
'**NOTICE**: This comment has been automatically edited by a bot ' +
'to redact some links in order to protect users from potentially malicious content. ' +
'Please, let us know if you believe this action may have been a mistake.'
// Edit the comment with the updated body
await github.rest.issues.updateComment({
owner: owner,
repo: repo,
comment_id: comment.id,
body: updatedBody
});
} else {
console.log('No suspicious links found.')
}