API Security Analyzer for OpenAPI/Swagger Specs
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 30/100
- Loại issue
- Tính năng
- Độ rõ ràng
- Cần làm rõ
- Mức độ hoạt động
- Đình trệ
- Công nghệ
- openapi, typescript
Hướng nghiên cứu
The issue names no repository files, tests, or entry points. Start by reviewing the OpenAPI/Swagger examples and defining the analyzer scope, supported specification versions, vulnerability taxonomy changes, and how each listed security violation will be reported; done means those decisions and acceptance checks are documented.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
This feature would introduce a specialized vulnerability type in our security taxonomy to analyze API definition files like openapi.yaml or swagger.json for security best-practice violations.
The scanner would check for common issues such as:
- Endpoints missing security scheme definitions (e.g., no authentication).
- Use of insecure protocols (http instead of https).
- Lack of defined rate-limiting properties.
- Sensitive data being passed in query parameters instead of the request body.
- Vague or overly permissive data type definitions (e.g., type: object without defined properties).
Open question: is there an open source tool we could use to help Gemini on the analysis?
Example 1:
{
"swagger": "2.0",
"info": {
"title": "Bad Swagger API",
"version": "1.0.0"
},
"paths": {
"/reports/confidential": {
"get": {
"summary": "Get confidential report",
"parameters": [
{
"name": "apiKey",
"in": "query",
"description": "API Key passed in URL (insecure!)",
"required": true,
"type": "string"
}
],
"responses": {
"200": {
"description": "Report data"
}
}
}
}
}
}
Example 2:
openapi: 3.0.0
info:
title: Insecure Transport API
version: 1.0.0
servers:
- url: http://api.example.com/v1 # <-- Insecure HTTP
paths:
/data:
get:
summary: Get some data
responses:
'200':
description: OK
- Ngôn ngữ chính
- TypeScript
- Star
- 794
- Fork
- 58
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của gemini-cli-extensions/security
-
HelpĐang mở
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 10/100
-
[Feature Request - Codemaps] Deduplicate Structural Graph Edges and Augment with Metadata (Call Sites)Có thể làm lại được @satvikkk đã nhận 225 ngày trước và không có pull request nào đang mở. Đang mởenhancement
gemini-cli-extensions/security#141 · 1 người được giao ·
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 45/100
gemini-cli-extensions/security#133 · 3 bình luận ·
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 35/100
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 20/100
Tất cả issue của gemini-cli-extensions/security
Issue tương tự
-
needs:triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
Maintainer thường phản hồi trong vòng 1 ngày
-
ai-discovered
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 83/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
jessepollak/home#1627 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
agent-canvas bug llm priority:low ready-for-dev
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
OpenHands/OpenHands#17806 · 3 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
radius-project/ai-extensions#923 ·
Maintainer thường phản hồi trong vòng 1 ngày