practicalli / practicalli/clojure

Security of Clojure libraries

Open
#387 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Makefile
Stars
117
Forks
36
PR merge metrics
No merged PRs in 30d

Description

Create a section on understanding how security concerns are addressed on the Clojure world

To review:

Tools

"software bill of materials" can be generated for Clojure projects - See for example https://cyclonedx.org/tool-center/.

GitHub / Leiningen specific tool
https://go.atomist.com/catalog/skills/atomist/owasp-dependency-check-skill?stability=unstable
OWASP dependency track scanner for leiningen projects on GitHub. It's free to use, enable it by installing a GitHub app in your org. After that, it creates GitHub CheckRuns with the results of the scan (only on Pushes to leiningen repos of course).

Add this as an alias to practicalli/clojure-deps-edn

https://github.com/rm-hull/lein-nvd#clojure-cli

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the linked Clojure security articles, libraries, scanners, OWASP resources, and dependency tools listed in the issue. Determine where this security section belongs and which recommendations are relevant to Clojure projects; done means the section covers the agreed scope and cites the selected resources and tools.

Written by the indexing model from the issue text.

Assessment

Tech stack
clojure
Domain
documentation, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.