microsoft / microsoft/AttackSurfaceAnalyzer

Allow More Robust Rule Descriptions

Open
#386 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement gui
Dominant language
C#
Stars
3k
Forks
294
PR merge metrics
No merged PRs in 30d

Description

Is your feature request related to a problem? Please describe.
You should be able to format rule descriptions in something like markdown, and have a link available for that rule. All default rules should be annotated. These are optional fields.

Describe the solution you'd like
Add additional optional fields to Rule.

  1. URL
  2. Extended description
  3. ID

Surface those fields in the GUI. For example the extended description could be in Markdown and displayed inline when loaded in the GUI, either as some drop down or as a URL. The URL could be to the source code with additional guidance in some cases like we do with DevSkim.

Add an optional flag to the CLI to include those fields in the output.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating the Rule model and tracing how rules are represented in the GUI and CLI output. Review how existing default rules and DevSkim guidance are surfaced. Done means optional URL, extended description, and ID fields are supported, visible in the GUI, and available through an opt-in CLI output option.

Written by the indexing model from the issue text.

Assessment

Tech stack
csharp
Domain
security, tooling
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.