Microsoft Application Inspector
github.com
github.com
If you're running this across your own project output, especially for a big code base, it's definitely not going to be as useful as across each dependency. For example your app having "analytics services" and "outbound http connections" might be totally normal, but if a library you're using for encryption adds those, that would be a concern.
Most likely people aren't going bother to run this on dependencies themselves (not to mention every version update), so having the info surfaced at the point of decision would be very useful and reach a ton more folks.
I've tracked a feature request on GitHub here attempting to represent what was suggested here:
https://github.com/NuGet/NuGetGallery/issues/7824
Add additional comments if you have thoughts on how it should work or anything else. Our backlog is pretty full right now but we'll update this GitHub issue if there is movement.
https://github.com/NuGet/Home/issues/new
If you have some ideas in the space of how specifically it could work, maybe mention where/how (e.g. what file) you'd like to declare these "rules".
https://www.fuget.org/packages/System.Net.Http for example doesn't show me all of that.
It looks like they are repurposing Audible's logo to mean "Dynamic Command Execution" [2]
[0] https://user-images.githubusercontent.com/47648296/72893326-...
[1] https://m.media-amazon.com/images/G/01/audibleweb/arya/navig...
[2] https://user-images.githubusercontent.com/47648296/71859554-...
EDIT: Thanks to xroot's comment above, it is indeed Adobe Flash.
"displayName": "Dynamic command execution",
"detectedIcon": "fab fa-audible"
It's probably unintentionally used by an engineer unfamiliar with the product as audible is more common as a descriptive word than as a brand.https://github.com/microsoft/ApplicationInspector/blob/08c91...
It quite confidently pointed out an "App container" category, on grounds of the repo containing a circleci/config.yml, which is... technically correct, I guess, but less than useful.
[1]: https://github.com/nathell/skyscraper/ [2]: http://pliki.danieljanus.pl/appinspector-skyscraper/
Is Rudy meant to be Ruby?
If you look at languages.json in RulesEngine/Resources, files with the extension .html (and some others) are recognized as "html", with type "code":
{
"name": "html",
"extensions": [ ".html", ".htm", ".cshtml", ".tmpl" ],
"type": "code"
},
This sets the scope for the patterns in AppInspector/rules/default; e.g., {
"name": "Content Management Framework: Wordpress",
"id": "AI021200",
"description": "Development Framework: Wordpress",
"applies_to": [ "javascript", "html" ],
"tags": [ "Framework.CMS.Wordpress" ],
"severity": "moderate",
"patterns": [
{
"pattern": "wordpress",
"type": "string",
"scopes": [ "code", "comment" ],
"modifiers": [ "i" ],
"confidence": "high"
}
]
},
This seems like it would be prone to a lot of false positives, but I haven't tried the tool.> The tool supports scanning various programming languages including C, C++, C#, Java, JavaScript, HTML, Python, Objective-C, Go, Rudy, Powershell and more
The tool supports scanning various programming languages including C, C++, C#, Java, JavaScript, HTML, Python, Objective-C, Go, Rudy, Powershell and more and includes html, json and text output formats with the default being an html report
I ended up having to put in 50 exceptions one by one over the course of half an hour. Just about the worst.
IDEs like Visual Studio and Rider can download the code on demand and debug step-through.
Tons of popular .NET libs (including the Microsoft ones) already support this.
[1] https://docs.microsoft.com/en-us/dotnet/standard/library-gui...