PowerShell / PowerShell/PSScriptAnalyzer
PSAvoidUsingConvertToSecureStringWithPlainText makes unreasonable claims at high severity
还没有人认领这个 Issue。
- 主要语言
- C#
- 星标
- 2.2k
- 派生
- 414
- 平均合并
- 13 小时 1 分钟
- 30 天内合并 PR
- 2
描述
Internal MS situation:
PSAvoidUsingConvertToSecureStringWithPlainText is now generating SFI/s360 work based on unsupported claims with neither Guardian nor TSA teams able to offer repo-wide suppression options.
This will expose secure information. Encrypted standard strings should be used instead.
Will it? Why is it an error?
I challenge you to create Credential instance from a token or another credential following this guidance.
There are workarounds of course and line-by-line suppressions, but they don't scale or make security story any stronger and we can't provide our own rules/settings for the linter.
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
调研方向
首先定位 PSAvoidUsingConvertToSecureStringWithPlainText 规则的入口点,并检查其消息和严重性是如何定义的。将这些说法与 issue 中描述的凭据和令牌场景进行比较;完成的标准是,该规则的严重性和指导不再对整个仓库提出无依据的安全性主张。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- csharp, powershell
- 领域
- security, tooling
- Issue 类型
- 缺陷
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 活跃度
- 冷清
- 描述清晰度
- 需要澄清
- 新手友好度
- 35/100