PowerShell / PowerShell/PSScriptAnalyzer
Integrate Injection Hunter with PSSA
未关闭
还没有人认领这个 Issue。
Area - Rules
Consider - 2.0
Issue - Enhancement
- 主要语言
- C#
- 星标
- 2.2k
- 派生
- 414
- 平均合并
- 13 小时 1 分钟
- 30 天内合并 PR
- 2
描述
Injection Hunter is a module that has rules to detect coding practices leading to injection attacks. We should integrate this module with PSSA.
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
调研方向
首先审查 Injection Hunter 模块和 PSScriptAnalyzer 项目,以确定如何集成该模块的 injection 检测规则。确定所需的集成边界和验证方法;当 Injection Hunter 的规则可通过 PSScriptAnalyzer 使用,并且其行为已得到验证时,工作即告完成。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- powershell
- 领域
- security, tooling
- Issue 类型
- 功能
- 难度
- 5/5
- 预计耗时
- 一周以上
- 活跃度
- 停滞
- 描述清晰度
- 需要澄清
- 新手友好度
- 25/100