From de839a29009e4d09be45e51c9c03e9570f06b5fe Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?AI=E4=B8=8D=E6=AD=A2=E8=AF=AD?= <12096460+jnMetaCode@users.noreply.github.com> Date: Tue, 29 Sep 2026 07:40:49 +0800 Subject: [PATCH] =?UTF-8?q?docs(security):=20=E8=87=AA=E6=9F=A5=E6=8F=90?= =?UTF-8?q?=E7=A4=BA=E8=AF=8D=E6=9B=B4=E6=96=B0=E4=B8=BA=20OWASP=20Top=201?= =?UTF-8?q?0:2025?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- common/security.en.md | 22 +++++++++++----------- common/security.md | 22 +++++++++++----------- 2 files changed, 22 insertions(+), 22 deletions(-) diff --git a/common/security.en.md b/common/security.en.md index 07583db..57bbd92 100644 --- a/common/security.en.md +++ b/common/security.en.md @@ -103,17 +103,17 @@ Add these rules to your project config file: Periodically have AI self-audit for security issues: ``` -Scan the entire src/ directory against the OWASP Top 10: -1. Injection (SQL, NoSQL, command injection) -2. Broken Authentication -3. Sensitive Data Exposure -4. XML External Entities (XXE) -5. Broken Access Control -6. Security Misconfiguration -7. Cross-Site Scripting (XSS) -8. Insecure Deserialization -9. Using Components with Known Vulnerabilities -10. Insufficient Logging & Monitoring +Scan the entire src/ directory against the OWASP Top 10:2025: +1. Broken Access Control (incl. SSRF) +2. Security Misconfiguration +3. Software Supply Chain Failures (vulnerable / unpinned dependencies) +4. Cryptographic Failures (plaintext secrets, weak algorithms) +5. Injection (SQL, NoSQL, command injection, XSS) +6. Insecure Design +7. Authentication Failures +8. Software or Data Integrity Failures (incl. insecure deserialization) +9. Security Logging and Alerting Failures +10. Mishandling of Exceptional Conditions (swallowed errors, fail-open) For each finding, provide: file location, risk level, and remediation. ``` diff --git a/common/security.md b/common/security.md index 1e53cbf..4d59bdf 100644 --- a/common/security.md +++ b/common/security.md @@ -101,17 +101,17 @@ console.log('Payment response:', { id: response.id, status: response.status }) 定期让 AI 自查安全问题: ``` -扫描整个 src/ 目录,按 OWASP Top 10 检查: -1. 注入(SQL、NoSQL、命令注入) -2. 失效的身份认证 -3. 敏感数据暴露 -4. XML 外部实体 -5. 失效的访问控制 -6. 安全配置错误 -7. 跨站脚本(XSS) -8. 不安全的反序列化 -9. 使用含已知漏洞的组件 -10. 不足的日志和监控 +扫描整个 src/ 目录,按 OWASP Top 10:2025 检查: +1. 失效的访问控制(含 SSRF) +2. 安全配置错误 +3. 软件供应链失效(含已知漏洞依赖、未锁版本) +4. 加密失效(明文敏感数据、弱算法) +5. 注入(SQL、NoSQL、命令注入、XSS) +6. 不安全的设计 +7. 身份认证失效 +8. 软件或数据完整性失效(含不安全的反序列化) +9. 安全日志与告警失效 +10. 异常情况处理不当(吞异常、失败时放行) 每个问题给出:文件位置、风险等级、修复建议。 ```