Security of Clojure libraries
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 35/100
- Issue type
- Documentation
- Clarity
- Needs clarification
- Activity status
- Stale
- Tech stack
- clojure
- Domain
- documentation, security
Research direction
Start by reviewing the linked Clojure security articles, libraries, scanners, OWASP resources, and dependency tools listed in the issue. Determine where this security section belongs and which recommendations are relevant to Clojure projects; done means the section covers the agreed scope and cites the selected resources and tools.
Written by the indexing model from the issue text.
Description
Create a section on understanding how security concerns are addressed on the Clojure world
To review:
- https://github.com/nubank/clj-owasp
- https://github.com/bpringe/auth-template
- https://purelyfunctional.tv/article/clojure-web-security/
- https://jemurai.com/2019/11/27/clojure-signal/
- https://clojureverse.org/t/a-template-for-web-apps-with-user-auth-using-owasp-best-practices-and-pedestal/6104
- https://owasp.org/www-chapter-vancouver/assets/presentations/2020-05_Exploiting_and_Preventing_Deserialization_Vulnerabilities.pdf
Tools
- https://github.com/BareSquare/deps-nvd
- https://github.com/bpringe/auth-template
- https://dependencytrack.org/ - CI tool
"software bill of materials" can be generated for Clojure projects - See for example https://cyclonedx.org/tool-center/.
GitHub / Leiningen specific tool
https://go.atomist.com/catalog/skills/atomist/owasp-dependency-check-skill?stability=unstable
OWASP dependency track scanner for leiningen projects on GitHub. It's free to use, enable it by installing a GitHub app in your org. After that, it creates GitHub CheckRuns with the results of the scan (only on Pushes to leiningen repos of course).
Add this as an alias to practicalli/clojure-deps-edn
- Dominant language
- Makefile
- Stars
- 117
- Forks
- 36
- PR merge metrics
- No merged PRs in 30d
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from practicalli/clojure
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
practicalli/clojure#381 ·
-
Clojure on windows Open
Difficulty 1/5 Under an hour Newbie friendliness 75/100
practicalli/clojure#298 ·
-
video
practicalli/clojure#478 · 1 assignee ·
-
practicalli/clojure#477 · 1 assignee ·
-
practicalli/clojure#476 · 1 assignee ·
All issues in practicalli/clojure
Similar issues
-
sync-en
Difficulty 1/5 1-3 hours Newbie friendliness 88/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
agilepathway/label-checker#640 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
BasedHardware/omi#15662 · 1 comment ·
-
documentation help wanted
Difficulty 2/5 1-3 hours Newbie friendliness 90/100
-
Difficulty 1/5 1-3 hours Newbie friendliness 88/100