Posted by solotandem on April 8, 2011 at 4:44pm
The goals of my project are:
- to develop additional reviews in the Secure Code Review module
- to improve the reporting of results from the module
- to provide Drush commands to invoke the reviews
The goals of my project are:
Comments
link to gsoc application
http://www.google-melange.com/gsoc/proposal/review/google/gsoc2011/solot...
This content of those links
Who: Jim Berry, solotandem in IRC.
Overview:
The goals of my project are: 1) to develop additional reviews in the Secure Code Review module, an automated tool to assist with security reviews of Drupal module code, 2) to improve the reporting of results from the module, and 3) to provide Drush commands to invoke the reviews. The review tools will be built atop the grammar parser library and its code manipulation API (CMAPI). The project may also involve extending and enhancing the CMAPI to support the security review tools. CMAPI provides tools for traversing, searching and modifying a code snippet.
Description:
As with automated testing and upgrading of code, the use of an automated tool to analyze (and possibly modify) code for security vulnerabilities has the potential to be more productive than the repetition of manual security reviews. The new reviews will target the contributed module vulnerabilities announced by the Drupal Security Team in the last two years. It would be helpful to have input from members of the Drupal Security Team who have experience in finding and fixing vulnerabilities in code.
Schedules:
1.
2.
3.
4.
5.
6.
7.
Mentors: Greg Knaddison, others interested in this topic
free 10000 real visitor http://khubah.com
From sun
From sun (http://drupal.org/node/1139168#comment-4421164) ... The Secure Code Review project should have a look at my initial prototype patch for Drupal core in #786856 (XSS attacks and security scan via testbot)
SumitK
www.sumitk.net