NodeSecure / NodeSecure/scanner
Scanning Github organization and repository
Nobody has claimed this yet.
- Dominant language
- TypeScript
- Stars
- 40
- Forks
- 23
- Avg merge
- 23h 23m
- Merged PRs (30d)
- 2
Description
My long-term idea is to expand Tree-walker and possibly Scanner to handle GitHub repositories and organizations. The first version of NodeSecure was originally capable of this: Dependency-Analyser.
This expansion would also allow us to replace or improve code in the report, such as in this example: fetch.ts.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the Tree-walker and Scanner entry points, then compare the original Dependency-Analyser linked in the issue. Read report/src/analysis/fetch.ts to understand the report code that may be replaced or improved. Done would mean a defined first version that scans GitHub repositories and organizations, but the issue does not yet specify its scope or acceptance criteria.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github, typescript
- Domain
- security, tooling
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100