loopbackio / loopbackio/security

Replace Secvisogram with `csaf-validator-lib`

オープン
#35 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

主要言語
TypeScript
スター
4
フォーク
1
PR マージ指標
30日以内にマージされた PR はありません

説明

Overview

Secvisogram is a project for a React-powered, web-based Common Security Advisory Framework Version 2.0 (CSAF 2.0) validator.

https://github.com/loopbackio/security/pull/5 / https://github.com/loopbackio/security/commit/17f860ad6f885177033f809bc4fefb14782e0c53 added CSAF 2.0 validation with Secvisogram. When that change was merged, Secvisogram was bundled as a single solution, and the validation code was not distributed separately. Hence, we implemented a hacky solution to import the entire project and then to call only the validation logic. Notably, this includes:

  • Installing all of Secvisogram's depenencies
  • Re-constructing and executing relevant parts of Secvisogram's custom build pipeline

Since then, this validation code has been decoupled and Secvisogram has been updated to use the csaf-validator-lib Node.js module (https://github.com/BSI-Bund/secvisogram/pull/39 / https://github.com/BSI-Bund/secvisogram/commit/4487b6b0032348b487fe05e881da8f654b2f78ec).

Benefits of making the switch include:

  • A more stable interface for us to bootstrap and use the dependency.
  • Reduced build pipeline complexity
  • Removed need for frontend build pipeline knowledge
  • Reduced attack surface from unneeded web frontend packages.

Implementation remarks

The current approach involves:

  • git submodule-ing https://github.com/BSI-Bund/secvisogram.git
  • Installing Secvisogram's dependencies and calling Babel as part of the build pipeline
  • Manually copying some non-JavaScript resources to the distibution directory
  • Importing validation logic from dist/shared/Core

In contrast, the new approach would involve:

  • git submodule-ing https://github.com/secvisogram/csaf-validator-lib.git
    Although the csaf-validator-lib README indicates to use git subtree, git submodule is better for explicitly linking two Git repositories together. In contrast, git subtree copies the Git history without any coupling to the source Git repository.
  • Installing csaf-validator-lib's production dependencies

This switch would also bring in the latest features and validation tests such Test 6.3.8 ("Spell check", powered by the Hunspell spell checking library), of which the BSI-Bund Git repository is currently lacking.

Mitigating against NPM dependency confusion attacks

At time of writing, csaf-validator-lib is not published as an NPM package, hence the need to install this as a "local dependency". To mitigate against NPM dependency confusion attacks, it is important that the package.json dependency entry explicitly points to the local copy.

We can achieve this "explicit pointer" requirement by leveraging package aliases, which was introduced in

This issue is to track switching over to csaf-validator-lib

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

調査の方向性

まず、現在のSecvisogramサブモジュール、package.jsonの依存関係設定、ビルドパイプライン、そしてdist/shared/Coreからのインポートを追跡します。その統合をcsaf-validator-libサブモジュールとその本番用依存関係に置き換え、CSAFの検証と既存のビルドが引き続き動作することを確認します。これには、issueで説明されている新しい検証カバレッジも含まれます。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
node.js, typescript
領域
build-system, security
issue の種類
リファクタリング
難易度
4/5
見積もり時間
3〜5日
活発さ
停滞
明瞭さ
おおむね明確
初心者へのやさしさ
42/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。