dotnet / dotnet/extensions

Compliance/Redaction analyzers?

Open
#7,490 0 comments 1 reaction 0 assignees View on GitHub
area-telemetry untriaged
Dominant language
C#
Stars
3.2k
Forks
894
Avg merge
1d 12h
Merged PRs (30d)
23

Description

The Microsoft.Extensions.Compliance.Abstractions and Microsoft.Extensions.Compliance.Redaction package make it easy for a developer to log structured data in a compliant manner. LoggerMessage, TagProvider, etc.

This still leaves a great many gaps that are easy for a developer to trip over:
* A legacy codebase might still rely on interpolated strings for logging.
* Someone used Don't Repeat Yourself to allocate a string containing sensitive data so they can write to both an audit trail but also to a telemetry stream.
* A service logs HTTP requests/responses. Most of these may be safely logged; some contain sensitive data.

Is there an appetite for a Redaction.Analyzer package to help catch these sorts of issues?

I've played around with a local implementation using a form of taint analysis, and while _I_ have much use for such a thing, I'm wondering if this is a thing suitable for dotnet/extensions.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.