Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

API Security Analyzer for OpenAPI/Swagger Specs

未关闭
#61 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
5/5
预计耗时
一周以上
新手友好度
30/100
Issue 类型
功能
描述清晰度
需要澄清
活跃度
停滞
技术栈
openapi, typescript
领域
api, security

调研方向

The issue names no repository files, tests, or entry points. Start by reviewing the OpenAPI/Swagger examples and defining the analyzer scope, supported specification versions, vulnerability taxonomy changes, and how each listed security violation will be reported; done means those decisions and acceptance checks are documented.

由索引模型根据 Issue 内容生成。

描述

This feature would introduce a specialized vulnerability type in our security taxonomy to analyze API definition files like openapi.yaml or swagger.json for security best-practice violations.

The scanner would check for common issues such as:

  • Endpoints missing security scheme definitions (e.g., no authentication).
  • Use of insecure protocols (http instead of https).
  • Lack of defined rate-limiting properties.
  • Sensitive data being passed in query parameters instead of the request body.
  • Vague or overly permissive data type definitions (e.g., type: object without defined properties).

Open question: is there an open source tool we could use to help Gemini on the analysis?

Example 1:

{
  "swagger": "2.0",
  "info": {
    "title": "Bad Swagger API",
    "version": "1.0.0"
  },
  "paths": {
    "/reports/confidential": {
      "get": {
        "summary": "Get confidential report",
        "parameters": [
          {
            "name": "apiKey",
            "in": "query",
            "description": "API Key passed in URL (insecure!)",
            "required": true,
            "type": "string"
          }
        ],
        "responses": {
          "200": {
            "description": "Report data"
          }
        }
      }
    }
  }
}

Example 2:

openapi: 3.0.0
info:
  title: Insecure Transport API
  version: 1.0.0
servers:
  - url: http://api.example.com/v1 # <-- Insecure HTTP
paths:
  /data:
    get:
      summary: Get some data
      responses:
        '200':
          description: OK
主要语言
TypeScript
星标
794
派生
58
PR 合并指标
30 天内没有已合并 PR

环境准备

  • 没有 Dockerfile 或 Docker Compose 文件
  • 没有 Pull Request 模板
  • 阅读贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

gemini-cli-extensions/security 的其他 Issue

查看 gemini-cli-extensions/security 的全部 Issue

相似的 Issue

更多 TypeScript Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。