security
æè¿ããªã¼ãã³ã½ã¼ã¹ã½ããã¦ã§ã¢ãå©ç¨ãããµãã©ã¤ãã§ã¤ã³æ»æãå¢å ãã¦ãã¾ãããã®ãããããã¸ã§ã¯ãã®ä¾åé¢ä¿ç®¡çã¨èå¼±æ§å¯¾çã®éè¦æ§ãé«ã¾ã£ã¦ãã¾ããåã¯éçºããã¸ã§ã¯ãã§å¤ãã®ä¾åããã±ã¼ã¸ãå©ç¨ãã¦ãã¾ããããã®ä¾åé¢ä¿ã®å¯è¦åã¨â¦
Cookieã«ããæ å ±åå¾ã«é¢ãã¦åæãæ±ãããããã¢ããããå¤ãã®ãã¼ã¸ã§å®è£ ãããããã«ãªãã¾ããã ï¼GDPRã§ã¯ãªãï¼æ¹æ£å人æ å ±ä¿è·æ³ã®è¦³ç¹ã§ãCookieã®æ±ãã«é¢ãã¦èª¿ã¹ããã¨ãã¾ã¨ãã¾ããæ£ããã®ãã¯ç¢ºä¿¡ããªãããã©ã ç§ã®ä¸ã®çµè«ã¨ãã¦ã¯â¦
npm auditã«ã¯audit-levelãªãã·ã§ã³ãããã¾ããããã®ãªãã·ã§ã³ã§æ¸¡ããSeverityã¨CVSSã«ã¯ã©ã®ãããªé¢ä¿ãããã®ã§ããããã ãã®èå³ãæ¹§ããã®ã¯ãéç¨è¨è¨ã«ããã¦ã©ã®ç¨åº¦ã®CVSSå¤ãæã¤èå¼±æ§ããçå£ã«å¯¾å¿ããããå®ãããã¨ãã¦ããããã§ããâ¦
ã»ãã¥ãªãã£ã«é¢ããã¬ã¤ããæ¸ãã¦ãã¾ãã ã»ãã¥ãªãã£ã¨ããã°OWASPã§ã¨ãã©ãåç §ããã¦ããã ãã¦ãã¾ãããããã®éç¨ã§åãã¦ã®ããã¸ã§ã¯ãã«åºä¼ã£ã¦ãã¾ãã¾ããã OWASP Cheet Sheet Seriesã§ãã ãã¡ããæ§ã ãªã»ãã¥ãªãã£åéã®ãã¼ãã·ã¼â¦
ã»ãã¥ãªãã£ã®ã¬ã¤ããæ¸ãã¨ãã話ããããæ¥æ¬ã§æãåºæ¬çãªã¨ããã§ãããIPAã®ãå®å ¨ãªã¦ã§ããµã¤ãã®ä½ãæ¹ãã®1ç« ãå確èªãã¾ãã 対çã®ç¨®é¡ èå¼±æ§å¯¾çã«ã¯2種é¡ããããæ ¹æ¬ç対çã¨ä¿éºç対çã§ãã æ ¹æ¬ç対çã¯ããããã¨ãã¦ãèå¼±æ§ãä½ãâ¦
ä»ä¼æ¥æ§ã®ãµã¼ãã¹ãå©ç¨ããå ´åãISMSèªè¨¼ãæ±ãããããã¨ãå¤ãã§ãã ISMSã¯Information Security Management Systemã®ç¥ã§ããã wikipedia:æ å ±ã»ãã¥ãªãã£ããã¸ã¡ã³ãã·ã¹ãã ã«ããã¨ä»¥ä¸ã®ããã«è¿°ã¹ããã¦ãã¾ãã ISMSã®ç®æ¨ã¯ããªã¹ã¯ããã¸â¦