erlef / erlef/elixir-secure-coding

CI/CD Tools - Linting

未关闭
#9 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
discussion new content non-elixir content
主要语言
Elixir
星标
731
派生
172
PR 合并指标
30 天内没有已合并 PR

描述

Linting, code patterns, security anti-patterns, SAST all run in similar circles - I believe there is some things you could implement in your linting practices that could have an effect on code security.

What that is exactly is still to be determined, but I'd love to start collecting thoughts on it and if should be included in the training module for CI/CD Tooling.

For the Elixir specific examples, it would most likely be referencing [Credo](https://github.com/rrrene/credo).

Relevant Resources:
- https://owasp.org/www-project-devsecops-guideline/latest/01b-Linting-Code#:~:text=What%20Is%20Linting%3F,a%20basic%20static%20code%20analyzer.
- https://medium.com/greenwolf-security/linting-for-bugs-vulnerabilities-49bc75a61c6

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。