API Security Analyzer for OpenAPI/Swagger Specs
还没有人认领这个 Issue。
评估
- 难度
- 5/5
- 预计耗时
- 一周以上
- 新手友好度
- 30/100
- Issue 类型
- 功能
- 描述清晰度
- 需要澄清
- 活跃度
- 停滞
- 技术栈
- openapi, typescript
调研方向
The issue names no repository files, tests, or entry points. Start by reviewing the OpenAPI/Swagger examples and defining the analyzer scope, supported specification versions, vulnerability taxonomy changes, and how each listed security violation will be reported; done means those decisions and acceptance checks are documented.
由索引模型根据 Issue 内容生成。
描述
This feature would introduce a specialized vulnerability type in our security taxonomy to analyze API definition files like openapi.yaml or swagger.json for security best-practice violations.
The scanner would check for common issues such as:
- Endpoints missing security scheme definitions (e.g., no authentication).
- Use of insecure protocols (http instead of https).
- Lack of defined rate-limiting properties.
- Sensitive data being passed in query parameters instead of the request body.
- Vague or overly permissive data type definitions (e.g., type: object without defined properties).
Open question: is there an open source tool we could use to help Gemini on the analysis?
Example 1:
{
"swagger": "2.0",
"info": {
"title": "Bad Swagger API",
"version": "1.0.0"
},
"paths": {
"/reports/confidential": {
"get": {
"summary": "Get confidential report",
"parameters": [
{
"name": "apiKey",
"in": "query",
"description": "API Key passed in URL (insecure!)",
"required": true,
"type": "string"
}
],
"responses": {
"200": {
"description": "Report data"
}
}
}
}
}
}
Example 2:
openapi: 3.0.0
info:
title: Insecure Transport API
version: 1.0.0
servers:
- url: http://api.example.com/v1 # <-- Insecure HTTP
paths:
/data:
get:
summary: Get some data
responses:
'200':
description: OK
- 主要语言
- TypeScript
- 星标
- 794
- 派生
- 58
- PR 合并指标
- 30 天内没有已合并 PR
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
gemini-cli-extensions/security 的其他 Issue
-
Help未关闭
难度 1/5 1 小时以内 新手友好度 10/100
-
[Feature Request - Codemaps] Deduplicate Structural Graph Edges and Augment with Metadata (Call Sites)可能重新可做 @satvikkk 于 225 天前认领,目前没有进行中的 PR。 未关闭enhancement
gemini-cli-extensions/security#141 · 已指派 1 人 ·
-
难度 3/5 1-2 天 新手友好度 45/100
gemini-cli-extensions/security#133 · 3 条评论 ·
-
难度 4/5 3-5 天 新手友好度 35/100
-
难度 5/5 一周以上 新手友好度 20/100
查看 gemini-cli-extensions/security 的全部 Issue
相似的 Issue
-
documentation
难度 2/5 1-3 小时 新手友好度 88/100
inu-appcenter/memorIN-frontend#106 ·
维护者通常 1 天内回复
-
kind/bug
难度 1/5 1 小时以内 新手友好度 88/100
维护者通常 7 天内回复
-
[Bug] @deck.gl/arcgis dist import resolves to unpublished @deck.gl/core source path (9.3.11, 9.4.0)未关闭
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 1 天内回复
-
bug
难度 2/5 1-3 小时 新手友好度 82/100
CSCfi/sd-search-ui#145 ·
维护者通常 1 天内回复
-
check:passed streams:add
难度 2/5 1-3 小时 新手友好度 62/100
维护者通常 1 天内回复