Azure / Azure/azure-functions-core-tools

Security: v5 security review and threat model

Open
#5,360 0 comments 0 reactions 0 assignees View on GitHub
design GA v5
Dominant language
C#
Stars
1.5k
Forks
498
Avg merge
4d 20h
Merged PRs (30d)
14

Description

Run a security review of the v5 CLI before GA: token handling,
workload package signature verification, NuGet feed pinning,
supply-chain audit, threat modeling.

## Definition of Done

- [ ] Token handling reviewed
- [ ] Workload package signature verification design
- [ ] NuGet feed pinning policy
- [ ] Supply-chain audit
- [ ] Threat model documented
- [ ] Follow-up issues opened for any findings

Contributor guide

Open the contributing guide

Research direction

Start by mapping the v5 CLI components involved in token handling, workload package verification, and NuGet feeds; the issue names no files or tests. Review the existing security controls and supply-chain assumptions, then document the threat model and policies, and open follow-up issues for findings as specified in the definition of done.

Written by the indexing model from the issue text.

Assessment

Tech stack
csharp
Domain
cli, documentation, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.