Is there any plan to provide Microsoft-backed digital signatures for RulesEngine DLLs and dependencies?

オープン
#747 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
5/5
見積もり時間
1週間以上
初心者へのやさしさ
25/100
issue の種類
機能追加
明瞭さ
おおむね明確
活発さ
静か
技術スタック
csharp
領域
release, security

調査の方向性

ソースファイルもテストも指定されていません。まず RulesEngine NuGet パッケージと列挙されている DLL を確認し、次にパッケージの署名と依存関係の所有権がどのように扱われているかを判断してください。完了とするには、Microsoft が支援する署名についてのチームの正式な決定、または厳格な署名要件を持つ組織向けの文書化されたガイダンスが必要です。

索引モデルが issue の本文から書いたものです。

説明

Hello RulesEngine team,

We are evaluating RulesEngine for use in our future software development projects. Our company extensively uses Microsoft products and technologies, and one of our internal security and software governance requirements is that third-party DLLs used in our products must have a trusted digital signature.

While reviewing the official NuGet package:

https://www.nuget.org/packages/RulesEngine

and the GitHub repository:

https://github.com/microsoft/RulesEngine

we noticed that the generated DLLs do not appear to include a Microsoft digital signature, even though the project is hosted under the official Microsoft GitHub organization.

The DLLs we checked include:

RulesEngine.dll
FastExpressionCompiler.dll
FluentValidation.dll
System.Linq.Dynamic.Core.dll
We also noticed that some dependencies are not owned by Microsoft:

https://www.nuget.org/packages/FastExpressionCompiler/
https://www.nuget.org/packages/FluentValidation/
https://www.nuget.org/packages/System.Linq.Dynamic.Core/
Our question is:

Is there any plan to provide Microsoft digital signatures, or any official Microsoft-backed signature/certificate, for the DLLs produced by this project or for Microsoft-hosted/supported open-source projects such as RulesEngine?

Alternatively, is there any official guidance from the team on how organizations with strict DLL-signing requirements should consume this package and its dependencies?

This clarification would help us determine whether RulesEngine can be adopted in environments with strict security, compliance, and software supply-chain policies.

Thank you for your support and for maintaining this project.

Kind regards,
Ali Rasoulian

主要言語
C#
スター
4.4k
フォーク
616
平均マージ
6分
マージ済み PR(30日)
2

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

microsoft/RulesEngine のほかの issue

microsoft/RulesEngine の issue をすべて見る

似ている issue

C# の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。