PowerShell / PowerShell/PSScriptAnalyzer
Issue with AvoidUsingPlainTextForPassword
未关闭
还没有人认领这个 Issue。
Area - Rules
- 主要语言
- C#
- 星标
- 2.2k
- 派生
- 414
- 平均合并
- 13 小时 1 分钟
- 30 天内合并 PR
- 2
描述
I am setting a parameter $Credential but its being flagged to force the use of secure string, However I don't belive that I am doing something 'insecure'
Example:
Param(
[Parameter()]
[System.Management.Automation.CredentialAttribute()]$Credential
)
I don't think above code should trigger a warning that it could expose sensitive information unless i am mistaken.
Thanks,
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
调研方向
首先使用 AvoidUsingPlainTextForPassword 规则重现该示例,并检查该规则的实现和现有测试。确定 CredentialAttribute 参数是否应触发诊断,然后添加或更新覆盖范围,使预期的警告行为明确无误。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- powershell
- 领域
- devtools, security
- Issue 类型
- 缺陷
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 活跃度
- 停滞
- 描述清晰度
- 基本清楚
- 新手友好度
- 35/100