practicalli / practicalli/clojure
Security of Clojure libraries
Nobody has claimed this yet.
- Dominant language
- Makefile
- Stars
- 117
- Forks
- 36
- PR merge metrics
- No merged PRs in 30d
Description
Create a section on understanding how security concerns are addressed on the Clojure world
To review:
- https://github.com/nubank/clj-owasp
- https://github.com/bpringe/auth-template
- https://purelyfunctional.tv/article/clojure-web-security/
- https://jemurai.com/2019/11/27/clojure-signal/
- https://clojureverse.org/t/a-template-for-web-apps-with-user-auth-using-owasp-best-practices-and-pedestal/6104
- https://owasp.org/www-chapter-vancouver/assets/presentations/2020-05_Exploiting_and_Preventing_Deserialization_Vulnerabilities.pdf
Tools
- https://github.com/BareSquare/deps-nvd
- https://github.com/bpringe/auth-template
- https://dependencytrack.org/ - CI tool
"software bill of materials" can be generated for Clojure projects - See for example https://cyclonedx.org/tool-center/.
GitHub / Leiningen specific tool
https://go.atomist.com/catalog/skills/atomist/owasp-dependency-check-skill?stability=unstable
OWASP dependency track scanner for leiningen projects on GitHub. It's free to use, enable it by installing a GitHub app in your org. After that, it creates GitHub CheckRuns with the results of the scan (only on Pushes to leiningen repos of course).
Add this as an alias to practicalli/clojure-deps-edn
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the linked Clojure security articles, libraries, scanners, OWASP resources, and dependency tools listed in the issue. Determine where this security section belongs and which recommendations are relevant to Clojure projects; done means the section covers the agreed scope and cites the selected resources and tools.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- clojure
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100