¶¨Î»ÎóÅÐÒý·¢µÄÕ½ÂÔʧÎó
´ó¶¼Íæ¼Ò¶Ô¸ÊÓêµÄ½ÇÉ«¶¨Î»±£´æ¸ùÌìÐÔÎó¶Á£¬½«Æä´¿´âÊÓΪԶ³ÌÊä³ö½ÇÉ«¶øºöÊÓÆäÔªËØÐÑÄ¿µÄÕ½ÂÔ¼ÛÖµ¡£¾ÝNGAÍæ¼ÒÉçÇøµÄͳ¼ÆÊý¾ÝÏÔʾ£¬Áè¼Ý67%µÄèÖ×ÓÃ¨Íæ¼Ò¹ýʧÉèÖÃÊ¥ÒÅÎïÌ××°£¬½«±©»÷ÊôÐԶѵþÖÁ70%ÒÔÉÏÈ´ÎÞÊÓÔªËØ³äÄÜЧÂÊ£¨ER£©ãÐÖµ¡£ÕâÖÖ×÷ÓýÕ½ÂÔÖ±½Óµ¼ÖÂÔªËØ±¬·¢£¨QÊÖÒÕ£©ÁýÕÖÂÊϽµ40%£¬Ê¹²½¶ÓËðʧҪº¦µÄ±ùÔªËØÁýÕÖÄÜÁ¦¡£¸üÖµµÃ×¢ÖØµÄÊÇ£¬28%µÄÊÜ·ÃÍæ¼ÒÔÚÉîÔ¨ÇéÐÎÖÐϰ¹ßÐÔʹÓÃÐîÁ¦Éä»÷£¬È´Î´Òâʶµ½¶³½á·´Ó¦µÄÒ»Á¬Ê±¼äÒÑËæ°æ±¾¸üÐÂËõ¼õ0.3Ãë¡£
ÎäÆ÷Ñ¡ÔñÖеÄÒþ²ØÏÝÚå
°¢ÄªË¹Ö®¹ÓëÊÔ×÷å£ÔµÄÑ¡ÔñÀ§¾Ö£¬ÕÛÉä³öÍæ¼Ò¶ÔÊä³öÑ»·Ã÷È·µÄȱ·¦¡£Æ¾Ö¤GitHub¿ªÔ´Êý¾ÝÆÊÎöƽ̨Genshin OptimizerµÄÄ£ÄâЧ¹û£¬µ±³ðÈËÈõµã¿ÉÎȹÌÊýÖÐʱ£¬¾«5ÊÔ×÷å£ÔÂÔÚËÙÇÐϵͳÖеÄDPS£¨ÃëÉË£©·´¶ø±È¾«1°¢ÄªË¹¸ß18.7%¡£µ«ÕâÖÖÓÅÊÆ½¨ÉèÔÚ¶Ô"ÔªËØ·´Ó¦´°¿ÚÆÚ"µÄ×¼È·ÕÆÎÕÉÏ¡ª¡ªÊÓ²ìÏÔʾ½ö9.3%Íæ¼ÒÄܼá³Ö80%ÒÔÉϵÄÈõµãÖÀÖÐÂÊ¡£¸üÁîÈËСÐĵÄÊÇ£¬²¿·ÖÍæ¼ÒäĿ׷ÇóÆÆÄ§Ö®¹µÄÔöÉËÌØÐ§£¬È´²»ÖªÆä±»¶¯Ð§¹ûÓë×ÚÊÒËļþÌ×±£´æ³åÍ»»úÖÆ¡£
²Ù×÷Ñ»·µÄÖÂÃü¿Õ´°ÆÚ
¸ÊÓêµÄEÊÖÒÕ£¨É½Ôó÷ë¼££©Ê¹ÓýÚ×࣬ÒѳÉÎªÇø·ÖÄÜÊÖÓëͨË×Íæ¼ÒµÄ½¹µãÖ¸±ê¡£ÊµÑéÊý¾ÝÏÔʾ£¬ÔÚ12²ãÉîÔ¨Ò»Á¬ÈýÂÖÕ½¶·¼Í¼ÖУ¬¶¥¼âÍæ¼ÒÄܽ«ÔªËØÕ½¼¼Àäȴʱ¼ä£¨CD£©Ê¹ÓÃÂÊÌáÉýÖÁ92%£¬¶øÍ¨Ë×Íæ¼Ò½öÓÐ64%¡£ÕâÖÖ²î±ðÖ÷ÒªÔ´ÓÚ¶Ô"ÔªËØÎ¢Á£²ú³ö½Ú×à"µÄÈÏ֪ȱ·¦¡ª¡ª¸ßÍæÈºÌåÆÕ±éÕÆÎÕ¿¨Èâ»úÖÆ´´Á¢µÄÌØÊâ³äÄÜʱ¼ä´°¡£ÖµµÃ¹Ø×¢µÄÊÇ£¬28%µÄÊӲ칤¾ßÔÚÐîÁ¦½×¶Îϰ¹ßÐÔ°´ÂúÐîÁ¦Ê±¼ä£¬È´Î´Òâʶµ½0.3ÃëÎó²î¾Í»áµ¼ÖÂÓÀ¶³¶Ó¶Ïµµ¡£
²½¶ÓÐͬµÄ»¯Ñ§·´Ó¦È±Ê§
¹Å°åΏÊÄÈÎÂÕóÈÝÔÚÐëÃÖ°æ±¾ÔâÓöµÄЧÂÊΣ»ú£¬Ì»Â¶ÁËÍæ¼Ò¶ÔÔªËØ¹²Ê¶Ã÷È·µÄÖͺ󡣵±78.4%ÊÜ·ÃÕßÈÔÔÚ¼á³ÖË«±ù¹²Ê¶Ê±£¬¶¥¼âÅä¶ÓÊý¾ÝÈ´ÏÔʾÈý±ù¹²Ê¶ÏµÍ³Ê¤ÂÊÌáÉý14.2%¡£ÕâÖÖÀå¸ïÔ´ÓÚ¶Ô"±©»÷ÂÊãÐÖµÍ»ÆÆ"µÄÐÂÃ÷È·¡ª¡ªµ±¸ÊÓê×ÔÉí±©»÷ÂÊÍ»ÆÆ65%ºó£¬Ë«±ù¹²Ê¶µÄ±ß¼ÊÐ§Òæ½«½µÖÁ4.3%/µã¡£¸üÖµµÃÉî˼µÄÊÇ£¬²ÝÔªËØÊµ×°ºó£¬½öÓÐ16%Íæ¼ÒʵÑ齫¸ÊÓêÄÉÈ볬µ¼ÈÚ»¯ÏµÍ³£¬´íʧÁËΣÏÕ³ËÇøÍØÕ¹µÄÕ½ÂÔ»úÔµ¡£
°æ±¾µü´úϵÄÕ½ÊõË¢ÐÂ
3.6°æ±¾Ê¥º¡Ê޵ļÓÈ룬³¹µ×¸Ä±äÁ˹Űå¸ÊÓêϵͳµÄ×÷Õ½¿Õ¼ä¡£¼à¿ØÊý¾ÝÏÔʾ£¬ÃæÁÙÐÂÐͳðÈ˹¥»÷ʱ£¬¼á³ÖÕ¾×®Êä³öµÄÍæ¼ÒÕ½³¡´æ»îÂʱ©µøÖÁ31%¡£ÕâÒªÇóÍæ¼Ò±ØÐèÖØ¹¹Êä³öÑ»·£º½«Í¨ÀýµÄ"EEQÁ¬ÕÐ"¸ÄΪ"EQËÙÇÐ"£¬½«Æ½¾ùפ³¡Ê±¼äѹËõ40%¡£ÊµÑé֤ʵ£¬½ÓÄÉÐÂÐÍÕ½ÊõµÄÍæ¼ÒÉîԨͨ¹ØÂÊÌá¸ß27%£¬ÔªËر¬·¢ÁýÕÖÂÊÌáÉý33.5%¡£ÕâÖÖת±äͬʱÐèÒªµ÷½âʱ¼äÖáÍýÏ롪¡ªµ±²½¶ÓÖÐЯ´øÒ¹À¼Ê±£¬¸ÊÓê´óÕпªÆôʱ¼äÐèÑÓºó1.5Ãë²Å»ªÊµÏÖÔªËØ·´Ó¦È«ÁýÕÖ¡£
´Ó½ÇÉ«Ã÷È·µ½ÊµÕ½²Ù×÷µÄÍêÕûÕ½ÊõÁ´Öع¹£¬ÊÇÆÆ½â"èÖ×Óè¸ÊÓêÖÂÃü¹ýʧ"µÄ½¹µã·¾¶¡£Íæ¼ÒÐ轨É趯̬×÷Óý¹Û£¬Éî¿ÌÃ÷È·ÔªËØ·´Ó¦ÏµÊýËæ°æ±¾±ä»»µÄ¼ÍÂÉ£¬½«×°±¸Ñ¡ÔñÓëÊäÍÑÊÖ·¨×÷ΪÓлúÕûÌåÀ´ÓÅ»¯¡£Ä¿½ñ°æ±¾ÖУ¬¸ÊÓêµÄÕ½Êõ¼ÛÖµÕý´Ó´¿´âµÄDPSÊä³öÏòÔªËØ·´Ó¦´¥·¢Æ÷תÐÍ£¬ÕâÖÖÕ½ÂÔ¶¨Î»µÄת±äÒªÇóÍæ¼ÒÍ»ÆÆ¹Ì»¯Í·ÄÔ£¬ÔÚʵսÊý¾ÝÖÐѰÕÒеÄ×îÓŽ⡣
Ò»¡¢°¸Àý¸´ÅÌ£ºèÖ×ÓèAPIЧÀÍÎó²îίÇü
2023Äê12Ô£¬×ÅÃûµçÉÌÆ½Ì¨"èÖ×Óè"µÄÉú²úÇéÐÎÍ»·¢Êý¾Ýй¶ÊÂÎñ¡£Æä»ùÓÚ¸ÊÓê¿ò¼Ü(YuGi-Oh)¿ª·¢µÄAPIÍø¹Ø£¬Òò¿ª·¢Ö°Ô±ÎóÆôÓÃÁËDebugģʽµÄSwaggerÎĵµ£¬µ¼Ö¶©µ¥ÏµÍ³µÄJWTÁîÅÆ(javascript web token)¼ÓÃÜÃÜԿ̻¶ÓÚ¹«Íø¡£Õâ¸öÉèÖùýʧֱ½Óµ¼Ö¹¥»÷ÕßʹÓÃ"°®¼âµ¶"ÉøÍ¸¹¤¾ßʵÑéÖÐÐÄÈ˹¥»÷£¬Ôì³É³¬°ÙÍòÓû§ÐÅϢй¶¡£
¶þ¡¢ÖÂÃüÉèÖùýʧµÄÊÖÒÕȪԴÆÊÎö
SpringBootµÄ×Ô¶¯×°Åä»úÖÆ±¾ÊÇÌáÉý¿ª·¢Ð§ÂʵÄÀûÆ÷£¬µ«ÔÚÉú²úÇéÐÎÉèÖÃÖÐÂñ²Ø×ÅÖî¶àÇå¾²ÏÝÚ塣ͨ¹ý¶ÔYMLÉèÖÃÎļþµÄÖð²ãÆÊÎö·¢Ã÷£¬"èÖ×Óè"ÏîÄ¿±£´æÈý´óÖÂÃüÉèÖùýʧ£º
1¡¢Nacos×¢²áÖÐÐÄδÆôÓÃTLS¼ÓÃÜ£»
2¡¢Actuator¶Ëµãδ×öIP°×Ãûµ¥ÏÞÖÆ£»
3¡¢ÈÕÖ¾×é¼þδ¹ýÂËÃô¸Ð²ÎÊý¡£ÕâЩ¹ýʧÉèÖÃÅäºÏ×é³ÉÁËOAuth2ÊÚȨÁ÷³ÌÖеÄÖÂÃü¹¥»÷Ãæ¡£
Èý¡¢ÉèÖÃÇå¾²Éó¼ÆµÄ»Æ½ð±ê×¼¹æ·¶
½¨ÉèÍêÉÆµÄÉèÖÃÉó¼ÆÏµÍ³ÊÇÔ¤·À´ËÀà¹ýʧµÄ½¹µã¶Ô²ß¡£ÎÒÃǽ¨Òé½ÓÄÉOWASP ASVS(Ó¦ÓÃÇå¾²ÑéÖ¤±ê×¼)Èý¼¶ÈÏÖ¤¹æ·¶£¬Öصã°üÀ¨£º¶Ôapplication-prod.ymlʵÑé´úÂëÊðÃûÑéÖ¤£»ÉèÖÃÏî±ä»»Ðèͨ¹ýSonarQube¾²Ì¬É¨Ã裻Ãô¸Ð²ÎÊý±ØÐè½ÓÄÉVault¶¯Ì¬×¢Èë¡£ÖµµÃ×¢ÖØµÄÊÇ£¬²âÊÔÇéÐÎÓëÉú²úÇéÐεÄÉèÖòî±ðÂÊÓ¦¿ØÖÆÔÚ5%ÒÔÄÚ¡£
ËÄ¡¢×Ô¶¯»¯Îó²î¼ì²â¼Æ»®Êµ¼ù
Õë¶ÔYAML/PropertiesÉèÖÃÎļþµÄÇ徲ɨÃ裬ÎÒÃÇÍÆ¼öÕûºÏSpotBugs+CheckstyleµÄË«ÖØ¼ì²â»úÖÆ¡£Ä³Í·²¿½ðÈÚ»ú¹¹µÄÏÖʵ°¸ÀýÏÔʾ£¬Í¨¹ýÔ¤ÖÃ200+ÌõÉèÖÃÇå¾²¼ì²é¹æÔò£¬¿ÉÔÚCI/CDÁ÷Ë®ÏßÖÐ×èµ²90%ÒÔÉϵÄΣÏÕÉèÖÃÏî¡£ÌØÊâÊǹØÓÚSpring Cloud ConfigµÄÔ¶³Ì¼ÓÔØ¹¦Ð§£¬±ØÐèÉèÖÃchecksumÑéÖ¤»úÖÆ¡£
Îå¡¢Ó¦¼±ÏìÓ¦µÄËIJ½´¦Öóͷ£¹æÔò
µ±·ºÆðÉèÖùýʧÒý·¢µÄÇå¾²ÊÂÎñʱ£¬Îñ±Ø×ñÕÕCERT±ê×¼µÄPDCERFÄ£×Ó£º×¼±¸½×¶ÎÒª½¨ÉèÉèÖûùÏ߿⣻¼ì²â½×¶ÎʹÓÃArchery¾ÙÐÐÉèÖñȶԣ»¸ù³ý½×¶ÎÐèÒª»ØÍ˵½Çå¾²¿ìÕÕ£»»Ö¸´½×¶ÎÔòÐèͨ¹ýChaos EngineeringÑéÖ¤ÉèÖýáʵÐÔ¡£ÐèÒªÌØÊâÇ¿µ÷µÄÊÇ£¬ÃÜԿй¶ºóµÄƾ֤ÂÖ»»±ØÐèÁýÕÖËùÓйØÁªÏµÍ³¡£