New item for secrets in source code
Nobody has claimed this yet.
- Dominant language
- TeX
- Stars
- 30
- Forks
- 5
- PR merge metrics
- No merged PRs in 30d
Description
We already have TASVS-STORAGE-1.1 for secrets in binaries and configuration files shipped to users, and I think we could add another item for secrets in source code under TASVS-CODE. This is what we have in the ASVS under V6.4 Secret Management:
Verify that a secrets management solution such as a key vault is used to securely create, store, control access to and destroy secrets.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by comparing the existing TASVS-STORAGE-1.1 item with the TASVS-CODE section and the cited ASVS V6.4 Secret Management requirement. The work is complete when a source-code secrets item is added under TASVS-CODE with wording consistent with the standard.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- tex
- Domain
- documentation, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100