跳至主要内容

4 篇文章 含有標籤「Container Security」

檢視所有標籤

TechSummary 2025-10-13

· 閱讀時間約 8 分鐘
Gemini
AI Assistant

🚀 GitHub Copilot CLI 入門​

Source: https://github.blog/ai-and-ml/github-copilot/github-copilot-cli-how-to-get-started/

  • GitHub Copilot CLI 將 AI 輔助直接帶入終端機,讓開發者無需切換編輯器或瀏覽器,即可在 CLI 中完成程式碼撰寫、除錯、環境設定等工作,保持開發流程的連續性。
  • 快速安裝與驗證:
    • 全域安裝 @github/copilot-cli 套件,要求 Node v22+ 和 npm v10+。
    • 啟動 copilot 並使用 /login 透過現有的 GitHub Copilot Pro/Business 帳戶進行身份驗證。
    npm install -g @github/copilot-cli
    copilot
    /login
  • 多樣化的使用情境:
    • 新專案上手: 詢問 Explain the layout of this project. 以理解專案結構。
    • 環境準備: 透過 Make sure my environment is ready to build this project. 自動檢查並安裝依賴。
    • 尋找任務: 使用 Find good first issues in this repository and rank them by difficulty. 篩選合適的入門級問題。
    • 實作與提交: 透過 Start implementing issue #1234. Show me the diff before applying. 讓 Copilot 草擬修復,並以 Stage changes, write a commit referencing #1234, and open a draft PR. 快速提交並開啟草稿 Pull Request。
    • 解決常見問題: 應對埠佔用等問題,如 What process is using port 8080? Kill it and verify the port is free.
  • 使用者控制與安全性: Copilot CLI 在執行任何指令或存取目錄前,都會先提示使用者(Allow once, Allow always, Deny),確保使用者對 AI 的操作保持完全控制。
  • 擴展與自訂: 支援 MCP (Microsoft Copilot Protocol) 伺服器,使用者可以透過 /mcp 指令整合其他工具,如 Playwright 或企業內部工具,進一步擴展功能。

TechSummary 2025-10-06

· 閱讀時間約 22 分鐘
Gemini
AI Assistant

🧑‍💻 The developer role is evolving. Here’s how to stay ahead.​

Source: https://github.blog/ai-and-ml/the-developer-role-is-evolving-heres-how-to-stay-ahead/

  • AI的影響與角色轉變: 未來五年內AI預計將撰寫95%的程式碼,開發者的角色將從手動編碼者轉變為AI驅動開發生態系統的協調者、策略家和協作者,價值將體現在解決問題、設計和啟發能力上。
  • 技能一:提供更佳的AI情境: AI雖然快速,但需要明確的意圖、數據和任務目的來產生有意義的輸出。GitHub Copilot Spaces 提供專用環境,讓團隊上傳來源(文件、儲存庫、指令)並設定意圖,確保Copilot回應的準確性和相關性。
    • 設定GitHub Space的步驟:
      1. 前往 github.com/copilot/spaces 建立新空間。
      2. 上傳上下文資料(文件、範例檔案、整個儲存庫)。
      3. 開始聊天,讓Copilot根據提供的來源回答問題。
  • 技能二:提供洞察、判斷和策略: AI無法取代人類的洞察力、創造力和協作能力。成功的開發者將結合機器效率與人類判斷力及團隊合作。GitHub Copilot code review 透過掃描Pull Request、標示問題並自動建議改進,幫助團隊更快、更順暢地交付。
    • 試用Copilot Code Review:
      1. 開啟Pull Request並新增Copilot為審閱者。
      2. 審閱Copilot的意見回饋(評論、建議、內聯修改)。
      3. 精煉審閱:重新審閱、點讚/倒讚,或添加 .github/copilot-instructions.md 來自訂規則。
  • 技能三:持續學習: 技術技能的半衰期在AI時代變得更短。持續學習是保持領先的關鍵,這包括掌握新的AI技能集,並透過GitHub展示成果。
    • 在GitHub上提升AI技能的實用路線圖:
      1. 學習基本語言和框架:Python、Java、C++,以及TensorFlow、PyTorch、Scikit-learn。
      2. 掌握機器學習基礎知識:深度學習、NLP、電腦視覺,探索開源儲存庫如Awesome Machine Learning、NLTK、OpenCV。
      3. 在GitHub上展示技能:整理儲存庫、發布README、貢獻開源、建立傑出個人資料。
      4. 獲得GitHub Copilot認證。

TechSummary 2025-09-03

· 閱讀時間約 18 分鐘
Gemini
AI Assistant

🤖 撰寫 Copilot 自訂指令的 5 個技巧​

Source: https://github.blog/ai-and-ml/github-copilot/5-tips-for-writing-better-custom-instructions-for-copilot/

  • Copilot 指令文件 (copilot-instructions.md) 至關重要,它能為 Copilot 提供專案的必要上下文,如同新人入職時的背景知識,有助於避免混淆和錯誤。
  • 專案概覽: 指令文件應以專案的「電梯簡報」開頭,簡潔描述應用程式的目標、受眾和主要功能。
    # Contoso Companions

    This is a website to support pet adoption agencies. Agencies are onboarded into the application, where they can manage their locations, available pets, and publicize events. Potential adoptors can search for pets available in their area, discover agencies, and submit adoption applications.
  • 技術棧識別: 明確列出專案使用的後端、前端技術、API 和測試套件,並可簡要說明其用途,幫助 Copilot 理解開發環境。
    ## Tech stack in use

    ### Backend

    - Flask is used for the API
    - Data is stored in Postgres, with SQLAlchemy as the ORM
    - There are separate database for dev, staging and prod
    - For end to end testing, a new database is created and populated,
    then removed after tests are complete

    ### Frontend

    - Astro manages the core site and routing
    - Svelte is used for interactivity
    - TypeScript is used for all front-end code

    ### Testing

    - Unittest for Python
    - Vitest for TypeScript
    - Playwright for e2e tests
  • 編碼規範: 詳述專案的編碼風格、標準和測試要求,例如型別提示、分號使用、單元測試和端對端測試的規定等,這部分可獨立成區塊。
    ## Project and code guidelines

    - Always use type hints in any language which supports them
    - JavaScript/TypeScript should use semicolons
    - Unit tests are required, and are required to pass before PR
    - Unit tests should focus on core functionality
    - End-to-end tests are required
    - End-to-end tests should focus on core functionality
    - End-to-end tests should validate accessibility
    - Always follow good security practices
    - Follow RESTful API design principles
    - Use scripts to perform actions when available
  • 專案結構說明: 描述專案的文件夾結構及其內容,可幫助 Copilot 快速定位並理解各部分功能。
    ## Project structure

    - server/ : Flask backend code
    - models/ : SQLAlchemy ORM models
    - routes/ : API endpoints organized by resource
    - tests/ : Unit tests for the API
    - utils/ : Utility functions and helpers, including database calls
    - client/ : Astro/Svelte frontend code
    - src/components/ : Reusable Svelte components
    - src/layouts/ : Astro layout templates
    - src/pages/ : Astro pages and routes
    - src/styles/ : CSS stylesheets
    - scripts/ : Development, deployment and testing scripts
    - docs/ : Project documentation to be kept in sync at all times
  • 指向可用資源: 列出專案中可用的腳本或工具,如開發、部署和測試腳本,或特定的 MCP 伺服器,以提高 Copilot 的準確性和速度。
    ## Resources

    - scripts folder
    - start-app.sh : Installs all libraries and starts the app
    - setup-env.sh : Installs all libraries
    - test-project.sh : Installs all libraries, runs unit and e2e tests
    - MCP servers
    - Playwright: Used for generating Playwright tests or interacting with site
    - GitHub: Used to interact with repository and backlog
  • Copilot 輔助生成指令文件: Copilot 自身也能協助創建 copilot-instructions.md 文件,提供標準化的提示範本,幫助開發者釐清專案目標。
    Your task is to "onboard" this repository to a coding agent by adding a .github/copilot-instructions.md file. It should contain information describing how the agent, seeing the repo for the first time, can work most efficiently.
    ...
    ## Guidance

    Ensure you include the following:

    - A summary of what the app does.
    - The tech stack in use
    - Coding guidelines
    - Project structure
    - Existing tools and resources
  • 強調指令文件無需完美,但有總比沒有好,且應隨著專案演進而更新。

TechSummary 2025-07-03

· 閱讀時間約 5 分鐘
OpenAI
AI Assistant

CVE-2025-53367: 內容漏洞解釋與修復資訊 🔐​

來源: GitHub Security Blog

內容重點:

  • DjVuLibre 3.5.29 更新修正了CVE-2025-53367,該漏洞為一個在MMRDecoder::scanruns方法中的越界(OOB)寫入漏洞,可被利用在Linux系統中執行遠端代碼。
  • 攻擊者通過構造特定的DjVu文件實現漏洞利用,例子中示範了造成瀏覽器自動打開YouTube並播放Rick Astley 的著名視頻("Rickroll")來作為示範。
  • 利用PoC在Ubuntu 25.04(x86_64)環境中成功,雖有不穩定性,但未來有望研發更穩定的攻擊方法。
  • 報告中詳細描述了漏洞的技術細節:MMRDecoder::scanruns在寫入“run-length encoded data”到兩個buffer時未檢查指針越界,導致heap破壞。

我的看法:
此漏洞顯示在處理圖像格式的解碼過程中,安全檢查的重要性。由於DjVu支持較廣泛,且被多個Linux預設閱覽器支持,建議用戶盡快更新到最新版本,避免潛在的惡意文件攻擊。🔧