diff --git a/common/security.en.md b/common/security.en.md index 07583db..57bbd92 100644 --- a/common/security.en.md +++ b/common/security.en.md @@ -103,17 +103,17 @@ Add these rules to your project config file: Periodically have AI self-audit for security issues: ``` -Scan the entire src/ directory against the OWASP Top 10: -1. Injection (SQL, NoSQL, command injection) -2. Broken Authentication -3. Sensitive Data Exposure -4. XML External Entities (XXE) -5. Broken Access Control -6. Security Misconfiguration -7. Cross-Site Scripting (XSS) -8. Insecure Deserialization -9. Using Components with Known Vulnerabilities -10. Insufficient Logging & Monitoring +Scan the entire src/ directory against the OWASP Top 10:2025: +1. Broken Access Control (incl. SSRF) +2. Security Misconfiguration +3. Software Supply Chain Failures (vulnerable / unpinned dependencies) +4. Cryptographic Failures (plaintext secrets, weak algorithms) +5. Injection (SQL, NoSQL, command injection, XSS) +6. Insecure Design +7. Authentication Failures +8. Software or Data Integrity Failures (incl. insecure deserialization) +9. Security Logging and Alerting Failures +10. Mishandling of Exceptional Conditions (swallowed errors, fail-open) For each finding, provide: file location, risk level, and remediation. ``` diff --git a/common/security.md b/common/security.md index 1e53cbf..4d59bdf 100644 --- a/common/security.md +++ b/common/security.md @@ -101,17 +101,17 @@ console.log('Payment response:', { id: response.id, status: response.status }) 定期让 AI 自查安全问题: ``` -扫描整个 src/ 目录,按 OWASP Top 10 检查: -1. 注入(SQL、NoSQL、命令注入) -2. 失效的身份认证 -3. 敏感数据暴露 -4. XML 外部实体 -5. 失效的访问控制 -6. 安全配置错误 -7. 跨站脚本(XSS) -8. 不安全的反序列化 -9. 使用含已知漏洞的组件 -10. 不足的日志和监控 +扫描整个 src/ 目录,按 OWASP Top 10:2025 检查: +1. 失效的访问控制(含 SSRF) +2. 安全配置错误 +3. 软件供应链失效(含已知漏洞依赖、未锁版本) +4. 加密失效(明文敏感数据、弱算法) +5. 注入(SQL、NoSQL、命令注入、XSS) +6. 不安全的设计 +7. 身份认证失效 +8. 软件或数据完整性失效(含不安全的反序列化) +9. 安全日志与告警失效 +10. 异常情况处理不当(吞异常、失败时放行) 每个问题给出:文件位置、风险等级、修复建议。 ```