2015-Middleware-Keynote / demo-ansible

Apache License 2.0
18 stars 24 forks source link

Instance of Suspicious Comments #166

Open rayhanur-rahman opened 5 years ago

rayhanur-rahman commented 5 years ago

Greetings,

I am a security researcher, who is looking for security smells in Ansible scripts. I found instances where certain keywords such as TODO, HACK, FIXME, bug repository IDs, in comments within Chef scripts. According to the Common Weakness Enumeration organization this is a security weakness (CWE-546: Suspicious Comment https://cwe.mitre.org/data/definitions/546.html).

I am trying to find out if you agree with the findings. I think it is possible to have a nuanced perspective. Any feedback is appreciated.

Any feedback is appreciated.

Source: https://github.com/2015-Middleware-Keynote/demo-ansible/blob/master/playbooks/post_setup.yml