Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Plugin Mechanism #94

Open
capitalist opened this issue Jun 9, 2021 · 5 comments
Open

Plugin Mechanism #94

capitalist opened this issue Jun 9, 2021 · 5 comments
Assignees

Comments

@capitalist
Copy link

Is there an existing mechanism for, or plans for a plugin capability for custom Findings similar to credo's Check mechanism?

It looks like sobelow is already well architected to support this, but has the hard-coded @submodules

Forgive me if this is already asked & answered, but I did try to search, so the keywords I use will help others find the conversation if it has already been had.

@GriffinMB
Copy link
Collaborator

Hi! There wasn't (until now) any plan for it, but it's a good suggestion. I'll look into this. I'm working on some other things at the moment, so it might not be a quick turnaround.

I'll update this issue with details once I've worked out the details, and have an ETA.

@GriffinMB GriffinMB self-assigned this Jun 9, 2021
@capitalist
Copy link
Author

Wow, very quick reply. Fortunately, I don't need a quick turn around.

But we're working with a very smart offensive security expert who's suggested some very interesting things and we're looking at what our options are for tool extension.

@GriffinMB
Copy link
Collaborator

Sounds good! Also happy to accept Finding contributions if they're generally applicable :)

@capitalist
Copy link
Author

I think we'd have a mix - some that are generally useful, and some that target specific patterns in our somewhat unorthodox platform.

@houllette
Copy link
Collaborator

Some inspiration could be taken from how Credo integrates plugins

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants