Add a Tricium analyzer to help make mojo security reviews easier |
|||||||||
Issue descriptionPer Marc-Antoine, it's now possible to write a Tricium plugin to annotate mojom/manifest files in Gerrit. Security team has long wanted more information displayed about mojom files, i.e. which services they live in, and maybe which processes embed them (not sure if this is possible).
,
Feb 2 2018
Small analyzer example: https://cs.chromium.org/chromium/infra/go/src/infra/tricium/functions/spacey/ There is not yet detailed, tested documentation about creating an analyzer, but this is one of the next major goals for the Tricium project. A simple analyzer will generally be an executable that takes a list of files to process (i.e. files in the CL) as input and produces a list of comments to add into those files. The analyzer could check out other files in the repo and use those as input too.
,
Feb 2 2018
,
Jun 15 2018
,
Jun 15 2018
,
Oct 17
,
Nov 20
,
Nov 20
,
Jan 1
|
|||||||||
►
Sign in to add a comment |
|||||||||
Comment 1 by maruel@google.com
, Feb 2 2018Labels: -OS-Mac Tricium