Conversation
PR Summary
|
|
I love this, thank you for opening it! |
| - Test your code – follow safe practices (like sanitising errors) and ensure you audit features and functionality before pushing to prod. | ||
| - Set up multi-factor authentication and avoid re-using passwords by implementing something like a password manager to avoid credential stuffing attacks. |
There was a problem hiding this comment.
I don't love these 2 points in a frequently-reused command, as advice they're not super actionable on their own — it would be great to see these link out to other resources that are somewhat comprehensive/canonical as to what threats exist and what mitigations are recommended. I don't have great recommendations handy immediately, though
There was a problem hiding this comment.
That's completely fair - I'll do some digging and see what i can find. I did try to bring it back to the simple stuff but also wanted to ensure it captured the essence of "its not just packages and lets be sensible."
After the react2shell incident there was a discussion to proactively add a security command.
The command adopted
!securityreturns the following response:Managing security in a web application requires a proactive approach.
Some points to consider:
The command was tested successfully prior to the PR being raised.