forcedotcom / forcedotcom/code-analyzer

[Feedback] How is 'ProtectSensitiveData' flagged?

オープン
#1,989 コメント 3 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
TypeScript
スター
240
フォーク
52
平均マージ
1日 23時間
マージ済み PR(30日)
5

説明

### Feedback

Hi, I would like to understand more on how the 'ProtectSensitiveData' rule is flagged because there seem to be instances where fields that are not an auth token or have no key words that suggest it's a token are flagged for this rule.

Is the rule flagged due to certain keywords being detected in the field name? Or is something detected in the xml file?

Thanks

### Context

_No response_

### Suggestions

_No response_

### Additional Information

_No response_

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

レポートでは、ファイル、テスト、エントリーポイントのいずれも特定されていません。まず ProtectSensitiveData ルールとその現在のドキュメントを見つけ、次に何が検出結果を発生させるのかを明確にし、その説明を関連するルールテストと照合して検証してください。

索引モデルが issue の本文から書いたものです。

評価

領域
security
issue の種類
ドキュメント
難易度
2/5
見積もり時間
1〜3時間
活発さ
停滞
明瞭さ
説明が足りない
初心者へのやさしさ
25/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。