falcosecurity / rules

Falco rule repository
https://falcosecurity.github.io/rules/
Apache License 2.0
93 stars 68 forks source link

[Feedback] Collect feedback and identify areas for improvement for Falco 0.37 wrt to new rules maturity framework and rules style guide #176

Closed incertum closed 7 months ago

incertum commented 1 year ago

Motivation

Collect feedback and identify areas for improvement for Falco 0.37 wrt the new rules maturity framework and rules style guide to drive future improvements, as the first version of something new typically has great potential for improvement.

References:

@falcosecurity/falco-maintainers @falcosecurity/rules-maintainers

incertum commented 1 year ago

Instead of exe_flags=%evt.arg.flags change to flags=%evt.arg.flags @loresuso called this out. We keep adding findings and then address them together.

poiana commented 9 months ago

Issues go stale after 90d of inactivity.

Mark the issue as fresh with /remove-lifecycle stale.

Stale issues rot after an additional 30d of inactivity and eventually close.

If this issue is safe to close now please do so with /close.

Provide feedback via https://github.com/falcosecurity/community.

/lifecycle stale

incertum commented 9 months ago

Cross-linking this issue https://github.com/falcosecurity/rules/issues/214

incertum commented 9 months ago

And https://github.com/falcosecurity/rules/issues/213

poiana commented 7 months ago

Stale issues rot after 30d of inactivity.

Mark the issue as fresh with /remove-lifecycle rotten.

Rotten issues close after an additional 30d of inactivity.

If this issue is safe to close now please do so with /close.

Provide feedback via https://github.com/falcosecurity/community.

/lifecycle rotten

leogr commented 7 months ago

Should target this for 0.39? Or can we close?

incertum commented 7 months ago

Mark as completed. Adopters could open regular issues in the future.