Skip to content

Feedback on suspicious comments in Chef scripts #156

@akondasif

Description

@akondasif

Greetings,

I am a security researcher, who is looking for security smells in Chef scripts.
I found instances where certain keywords such as TODO, HACK, FIXME, bug repository IDs, in comments within Chef scripts.
According to the Common Weakness Enumeration organization this is a security weakness
(CWE-546: Suspicious Comment https://cwe.mitre.org/data/definitions/546.html).

I am trying to find out if you agree with the findings. I think it is possible to have a nuanced perspective. Any feedback is appreciated.

Source:

  1. https://github.com/berekuk/questhub/blob/master/cookbooks/apt/providers/repository.rb

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions