microsoft / microsoft/AttackSurfaceAnalyzer
Allow More Robust Rule Descriptions
Nobody has claimed this yet.
- Dominant language
- C#
- Stars
- 3k
- Forks
- 294
- PR merge metrics
- No merged PRs in 30d
Description
Is your feature request related to a problem? Please describe.
You should be able to format rule descriptions in something like markdown, and have a link available for that rule. All default rules should be annotated. These are optional fields.
Describe the solution you'd like
Add additional optional fields to Rule.
- URL
- Extended description
- ID
Surface those fields in the GUI. For example the extended description could be in Markdown and displayed inline when loaded in the GUI, either as some drop down or as a URL. The URL could be to the source code with additional guidance in some cases like we do with DevSkim.
Add an optional flag to the CLI to include those fields in the output.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by locating the Rule model and tracing how rules are represented in the GUI and CLI output. Review how existing default rules and DevSkim guidance are surfaced. Done means optional URL, extended description, and ID fields are supported, visible in the GUI, and available through an opt-in CLI output option.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- csharp
- Domain
- security, tooling
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100