Slide 15
Slide 15 text
TIJGUKTJOGP
(PΛηΩϡΞʹॻ͖ਐΊΔͨΊͷʮΨʔυϨʔϧʯΛඋ͠Α͏
‣ HPܥύοέʔδ
‣ HP(Pඪ४ͷ੩తղੳ༻ͷύοέʔδ܈
‣ HPTFDͰओʹHPBTUʢߏจपΓʣͱHPUZQFTʢܕपΓʣ͕ར༻͞Ε͍ͯΔ
‣ ֤ݕग़ϧʔϧHPͱHPTFDʹΑΔHPͷUIJOXSBQQFSͰॻ͔ΕΔ
HPTFDͷ͘͠Έ
if ident, ok := n.Key.(*ast.Ident); ok {
switch ident.Name {
case "InsecureSkipVerify":
if node, ok := n.Value.(*ast.Ident); ok {
if node.Name != "false" {
return gosec.NewIssue(c, n, t.ID(),
"TLS InsecureSkipVerify set true.",
gosec.High, gosec.High)
}
} // ....
https://github.com/securego/gosec/blob/27a5ffb5c8f6dd3b6dea3b8e6019a2b3d43bf0f9/rules/tls.go#L64-L72