erlef / erlef/elixir-secure-coding

CI/CD Tools - Linting

未關閉
#9 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
discussion new content non-elixir content
主要語言
Elixir
星號
731
分支
172
PR 合併指標
30 天內沒有已合併 PR

描述

Linting, code patterns, security anti-patterns, SAST all run in similar circles - I believe there is some things you could implement in your linting practices that could have an effect on code security.

What that is exactly is still to be determined, but I'd love to start collecting thoughts on it and if should be included in the training module for CI/CD Tooling.

For the Elixir specific examples, it would most likely be referencing [Credo](https://github.com/rrrene/credo).

Relevant Resources:
- https://owasp.org/www-project-devsecops-guideline/latest/01b-Linting-Code#:~:text=What%20Is%20Linting%3F,a%20basic%20static%20code%20analyzer.
- https://medium.com/greenwolf-security/linting-for-bugs-vulnerabilities-49bc75a61c6

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。