PowerShell / PowerShell/PSScriptAnalyzer
Should have a rule that verifies that scripts are securely signed
Open
Nobody has claimed this yet.
Issue - Enhancement
Issue - New Rule
- Dominant language
- C#
- Stars
- 2.2k
- Forks
- 414
- Avg merge
- 13h 1m
- Merged PRs (30d)
- 2
Description
BinSkim has a rule like this and the code is here: https://github.com/Microsoft/binskim/blob/master/src/BinSkim.Rules/SignSecurely.cs
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reading BinSkim's SignSecurely.cs implementation at the linked URL, then compare its rule structure with PSScriptAnalyzer's existing analyzer rules. Done means PSScriptAnalyzer reports whether a PowerShell script is securely signed, with behavior covered by appropriate analyzer tests.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- csharp, powershell
- Domain
- security, tooling
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100