Azure / Azure/azure-functions-core-tools
Security: v5 security review and threat model
- Dominant language
- C#
- Stars
- 1.5k
- Forks
- 498
- Avg merge
- 4d 20h
- Merged PRs (30d)
- 14
Description
Run a security review of the v5 CLI before GA: token handling,
workload package signature verification, NuGet feed pinning,
supply-chain audit, threat modeling.
## Definition of Done
- [ ] Token handling reviewed
- [ ] Workload package signature verification design
- [ ] NuGet feed pinning policy
- [ ] Supply-chain audit
- [ ] Threat model documented
- [ ] Follow-up issues opened for any findings
Contributor guide
Research direction
Start by mapping the v5 CLI components involved in token handling, workload package verification, and NuGet feeds; the issue names no files or tests. Review the existing security controls and supply-chain assumptions, then document the threat model and policies, and open follow-up issues for findings as specified in the definition of done.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- csharp
- Domain
- cli, documentation, security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100