Post #4151378
2026-07-28 01:03 UTC
Replies (1)
-
@still@infosec.exchange 2026-07-28 01:07
I've had so much friction in general when trying to PR for new rules this time around. https://github.com/mandiant/capa-rules/pull/1171 https://github.com/mandiant/capa-rules/pull/1172 https://github.com/mandiant/capa-rules/pull/1173 In #1171, my proposal for discussion was ignored. In #1172, I explicitly stated `I can PR the sample into testfiles before or after the discussion.` This was seemingly ignored, as I was told to "address the linter" which pointed to the sample being missing - it was *intentionally* missing as I wanted discussion to go through first. In #1173, I was told to add a `description` field, which I did, which then led to the discovery of the `description` / `namespace` bug, and also I had to explain why the rules sat in nursery instead of the corresponding folders when capa's stance on rules have always been nursery-first. I love capa but man whenever I want to submit new rules it's a stupid hassle.