Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

publish-gate: scan a normalized copy of the page for escaped secrets and paths

オープン
#6,432 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
3/5
見積もり時間
半日
初心者へのやさしさ
62/100
issue の種類
機能追加
明瞭さ
おおむね明確
活発さ
活発
技術スタック
javascript
領域
security, tooling

調査の方向性

Start in lib/publish-gate.mjs, which currently scans raw upload bytes only. Mirror the pages Worker normalization from melodic-software/provisioning#705 so HTML-escaped, tag-split, and JSON-escaped credential, path, and hostname shapes are scanned the same way. Add regression tests for those three sample forms, then regenerate the shared copies. Done when the client gate refuses those shapes before upload instead of after a 409/422.

索引モデルが issue の本文から書いたものです。

説明

needs-human needs-triage

The pages Worker (melodic-software/provisioning#705) now also scans a normalized copy of each upload, so HTML-escaped, tag-split and JSON-escaped credential, path and hostname shapes are caught. lib/publish-gate.mjs scans only the raw bytes, so its early check misses those forms. The Worker remains the enforcing layer; this aligns the client gate so it routes or refuses before upload instead of after a 409/422. Add the same normalization and regression tests (escaped entity, tag-split, JSON-escaped samples), then regenerate the shared copies.

主要言語
Shell
スター
22
フォーク
2
平均マージ
5時間 11分
マージ済み PR(30日)
838

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

melodic-software/claude-code-plugins のほかの issue

melodic-software/claude-code-plugins の issue をすべて見る

似ている issue

Shell/Bash の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。