PowerShell / PowerShell/PSScriptAnalyzer

PSAvoidUsingConvertToSecureStringWithPlainText makes unreasonable claims at high severity

未关闭
#2,187 2 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

主要语言
C#
星标
2.2k
派生
414
平均合并
13 小时 1 分钟
30 天内合并 PR
2

描述

Internal MS situation:

PSAvoidUsingConvertToSecureStringWithPlainText is now generating SFI/s360 work based on unsupported claims with neither Guardian nor TSA teams able to offer repo-wide suppression options.

This will expose secure information. Encrypted standard strings should be used instead.

Will it? Why is it an error?
I challenge you to create Credential instance from a token or another credential following this guidance.

There are workarounds of course and line-by-line suppressions, but they don't scale or make security story any stronger and we can't provide our own rules/settings for the linter.

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

调研方向

首先定位 PSAvoidUsingConvertToSecureStringWithPlainText 规则的入口点,并检查其消息和严重性是如何定义的。将这些说法与 issue 中描述的凭据和令牌场景进行比较;完成的标准是,该规则的严重性和指导不再对整个仓库提出无依据的安全性主张。

由索引模型根据 Issue 内容生成。

评估

技术栈
csharp, powershell
领域
security, tooling
Issue 类型
缺陷
难度
4/5
预计耗时
3-5 天
活跃度
冷清
描述清晰度
需要澄清
新手友好度
35/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。