id: circleci-config
info:
name: circleci config.yml exposure
author: geeknik
severity: low
reference: https://circleci.com/docs/2.0/sample-config/
tags: config,exposure,circleci
requests:
- method: GET
redirects: true
max-redirects: 3
path:
- "{{BaseURL}}/.circleci/config.yml"
matchers-condition: and
matchers:
- type: dsl
dsl:
- 'regex("^version: ", body) && contains(body, "jobs:")'
- type: status
status:
- 200