Is there any plan to provide Microsoft-backed digital signatures for RulesEngine DLLs and dependencies?
まだ誰も着手していません。
評価
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 初心者へのやさしさ
- 25/100
調査の方向性
ソースファイルもテストも指定されていません。まず RulesEngine NuGet パッケージと列挙されている DLL を確認し、次にパッケージの署名と依存関係の所有権がどのように扱われているかを判断してください。完了とするには、Microsoft が支援する署名についてのチームの正式な決定、または厳格な署名要件を持つ組織向けの文書化されたガイダンスが必要です。
索引モデルが issue の本文から書いたものです。
説明
Hello RulesEngine team,
We are evaluating RulesEngine for use in our future software development projects. Our company extensively uses Microsoft products and technologies, and one of our internal security and software governance requirements is that third-party DLLs used in our products must have a trusted digital signature.
While reviewing the official NuGet package:
https://www.nuget.org/packages/RulesEngine
and the GitHub repository:
https://github.com/microsoft/RulesEngine
we noticed that the generated DLLs do not appear to include a Microsoft digital signature, even though the project is hosted under the official Microsoft GitHub organization.
The DLLs we checked include:
RulesEngine.dll
FastExpressionCompiler.dll
FluentValidation.dll
System.Linq.Dynamic.Core.dll
We also noticed that some dependencies are not owned by Microsoft:
https://www.nuget.org/packages/FastExpressionCompiler/
https://www.nuget.org/packages/FluentValidation/
https://www.nuget.org/packages/System.Linq.Dynamic.Core/
Our question is:
Is there any plan to provide Microsoft digital signatures, or any official Microsoft-backed signature/certificate, for the DLLs produced by this project or for Microsoft-hosted/supported open-source projects such as RulesEngine?
Alternatively, is there any official guidance from the team on how organizations with strict DLL-signing requirements should consume this package and its dependencies?
This clarification would help us determine whether RulesEngine can be adopted in environments with strict security, compliance, and software supply-chain policies.
Thank you for your support and for maintaining this project.
Kind regards,
Ali Rasoulian
- 主要言語
- C#
- スター
- 4.4k
- フォーク
- 616
- 平均マージ
- 6分
- マージ済み PR(30日)
- 2
コントリビューションガイド
このリポジトリのコントリビューションガイドは索引されていません
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
microsoft/RulesEngine のほかの issue
-
難易度 4/5 3〜5日 初心者へのやさしさ 30/100
microsoft/RulesEngine#702 ·
-
難易度 3/5 1〜2日 初心者へのやさしさ 25/100
microsoft/RulesEngine#701 · コメント 1 件 ·
-
難易度 5/5 1週間以上 初心者へのやさしさ 25/100
microsoft/RulesEngine#700 ·
-
難易度 5/5 1週間以上 初心者へのやさしさ 25/100
microsoft/RulesEngine#699 ·
-
難易度 5/5 1週間以上 初心者へのやさしさ 25/100
microsoft/RulesEngine#691 ·
microsoft/RulesEngine の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 86/100
-
:watch: Not Triaged 11.0 fundamentals/subsvc
難易度 2/5 1〜3時間 初心者へのやさしさ 92/100
dotnet/AspNetCore.Docs#37699 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
SubtitleEdit/subtitleedit#15108 · コメント 1 件 ·
-
area/docs-content Bug pulumi/docs
難易度 1/5 1〜3時間 初心者へのやさしさ 94/100
-
agentic-workflows untriaged
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100