github / github/codeql

Add rules for Vert.X

未关闭
#12,844 5 条评论 4 个 reaction 已指派 0 人 在 GitHub 查看
question
主要语言
CodeQL
星标
10.1k
派生
2.1k
平均合并
2 天 15 小时
30 天内合并 PR
141

描述

# Task Description

We would like to see specialized rules for the [Vert.x](https://vertx.io/) Java framework. This is a popular Eclipse framework [hosted on Github](https://github.com/vert-x3/) with over 13000 followers (as of now).

Based on our research, it appears Checkmarx is the only SAST tool that has rules for Vert.X, targetting Kotlin.

Our codebase is written in Java and heavily dependent on Vert.X. We are already using GHAS for scanning our private repositories (in GHES). We would like to not need to use several different tools such as Fortify, Checkmarx, Mend, etc for the job.

It would be great, it we could see the same support in CodeQL.

# Task List

The following tasks will have to be carried out:
* [ ] Collect a list of common security issues in Vert.X
* [ ] Implement rules for them
* [ ] Add tests
* [ ] Update the documentation

# Useful Links

* [Vert.X: Github Org](https://github.com/vert-x3/)
* [Vert.X: Website](https://vertx.io/)
* [Vert.X: Writing Secure Vert.X webapps](https://vertx.io/blog/writing-secure-vert-x-web-apps/)
* [Vert.X: Things to keep in mind concerning CSRF attacks"](https://vertx.io/blog/eclipse-vert-x-CSRF-concerns/)
* [Vert.X: #security chat channel on Discord](https://discord.com/channels/751380286071242794/751398225105125376)
* [Checkmarx: Supported Code Languages And Frameworks](https://checkmarx.com/resource/documents/en/34965-46283-supported-code-languages-and-frameworks-for-9-5-0.html)

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。