Add privacy violations to the vulnerabilities taxonomy
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 25/100
- Loại issue
- Tính năng
- Độ rõ ràng
- Cần làm rõ
- Mức độ hoạt động
- Đình trệ
- Công nghệ
- typescript
Hướng nghiên cứu
Start by reviewing the existing taxonomy nodes named in the issue: Logging of Sensitive Information (CWE-200) and PII Handling Violations. Run the planned benchmarks against the two prioritized CUJs—data leaks to log files and sensitive flows to third parties—to determine how the taxonomy should expand or split. Done means the relevant privacy violations are represented and benchmark coverage supports the resulting taxonomy.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
The security extension should be able to detect relevant privacy violations.
The current CUJs being prioritized:
P0: CUJ-1: Identify and remove data leaks to log files
A developer is writing code that logs a user's IP address. The Gemini CLI extension acts as a vigilant assistant, instantly flagging such code within the developer's workflow. It provides AI-generated fixes—for example, replacing the IP address with a salted hash or redacting it completely—that can be applied with a single click, ensuring data privacy is maintained without interrupting the developer's flow.
P0: CUJ-2: Identify sensitive flows to 3Ps
The CLI extension proactively identifies and alerts developers when sensitive data types (such as SSNs, telephone numbers, or precise location information) are being transmitted to third-party services.
There are some related nodes in our current taxonomy and we will run benchmarks to decide how to expand/split those nodes to cover specific privacy violations:
Logging of Sensitive Information (CWE-200): Analyze for the logging of sensitive information. Scan the code for logging statements that might write passwords, PII, API keys, or session tokens to application or system logs.
PII Handling Violations: Analyze how the application handles Personally Identifiable Information (PII). Look for improper storage (e.g., unencrypted), insecure transmission, or any use that may violate data privacy regulations.
- Ngôn ngữ chính
- TypeScript
- Star
- 794
- Fork
- 58
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của gemini-cli-extensions/security
-
HelpĐang mở
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 10/100
-
[Feature Request - Codemaps] Deduplicate Structural Graph Edges and Augment with Metadata (Call Sites)Có thể làm lại được @satvikkk đã nhận 225 ngày trước và không có pull request nào đang mở. Đang mởenhancement
gemini-cli-extensions/security#141 · 1 người được giao ·
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 45/100
gemini-cli-extensions/security#133 · 3 bình luận ·
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 35/100
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 20/100
Tất cả issue của gemini-cli-extensions/security
Issue tương tự
-
priority: P2
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 65/100
prime-radiant-inc/evener#3291 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
accessibility bug revealjs
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
quarto-dev/quarto-cli#14961 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 90/100
supabase/agent-skills#614 ·
-
Content
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
RunestoneInteractive/rs#1559 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 2 ngày