GitHub 推出 Fuzzing Taskflow 自动化模糊测试
GitHub Security Lab 推出了自动化模糊测试工具 Fuzzing Taskflow,能自动完成从代码分析到漏洞报告的全流程。
GitHub Security Lab 发布 Fuzzing Taskflow,将模糊测试流程自动化。该工具能识别 C/C++ 代码入口点,分析构建过程,生成测试代码,运行 AFL++ 模糊测试工具,监控代码覆盖率,并为每个发现的漏洞生成报告。整个过程无需人工编写测试用例和监控覆盖率。
Continuous fuzzing finds real bugs, but it still needs someone to write harnesses, watch coverage, and triage every crash. The GitHub Security Lab built the Fuzzing Taskflow to give that loop to an agent. You point it at a C or C++ repository, and it identifies entrypoints, analyzes the build, crafts harnesses, runs the AFL++ fuzzer, reads coverage, and creates a vulnerability report for each unique bug. Check out how the pipeline works end to end 🔍 github.blog/security/appli… h 💬 2 🔄 0 ❤️ 4 👀 2503 📊 2 ⚡