-
Notifications
You must be signed in to change notification settings - Fork 13
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add homoglyphs rule types #51
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
could we add links that describe what kind of attack this prevents? I don't think they are very well known
Added in the description now, thanks for noting that! |
guidance: > | ||
For every pull request submitted to a repository, this rule will check if the | ||
pull request adds a new dependency with invisible characters. If it does, the rule will | ||
fail and the pull request will be commented on. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The guidance is meant to tell you what to do if the rule fails. This is more appropriate for a description.
guidance: > | ||
For every pull request submitted to a repository, this rule will check if the | ||
pull request adds text with mixed scripts. If it does, the rule will | ||
fail and the pull request will be commented on. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The guidance is meant to tell you what to do if the rule fails. This is more appropriate for a description.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks: updated
The implications of homoglyphs type of attacks are described in mindersec/minder#2121
It also contains additional explicatory links and useful examples.