Do not log sensitive data such as user id, email or other personal data (first name, last name, etc).
Non-Compliant Code Examples
console.log("email from user"+user.email);console.log(`email from user ${user.email}`);logger.info(`email from user ${user.email}`);logger.info(`email from user ${username}: ${user.email}`);logger.warn(email);logger.error(`email from user ${email}`);foobar.error(`email from user ${email}`);logger.foobar(`email from user ${email}`);
Compliant Code Examples
console.log("email from user"+user.id);console.log(`email from user ${user.uuid}`);
원활한 통합. Datadog Code Security를 경험해 보세요
Datadog Code Security
이 규칙을 사용해 Datadog Code Security로 코드를 분석하세요
규칙 사용 방법
1
2
rulesets:- javascript-node-security # Rules to enforce JavaScript node security.
리포지토리 루트에 위의 내용을 포함하는 static-analysis.datadog.yml을 만듭니다
무료 IDE 플러그인을 사용하거나 CI 파이프라인에 Code Security 검사를 추가합니다