·
5 commits
to master
since this release
Features
Support for skipcq
You can now add // skipcq
directives in your comments to ignore issues raised by Globstar checkers.
Examples:
- Ignore all issues raised in a line:
# skipcq
assert 1 == 1
- Ignore specific issues raised in a line:
# skipcq
def process(request):
form = PostForm(request.POST)
if form.is_valid():
# skipcq: avoid-assert
assert name == request.POST['name']
- You can also ignore multiple issues in a line:
def process(request):
form = PostForm(request.POST)
if form.is_valid():
# skipcq: avoid-assert, post-after-isvalid
assert name == request.POST['name']
New checkers
Python
- Add checkers for miscellaneous Flask
app.run()
vulnerabilities - Add checker to detect user data formatted string return in Flask
- Add checker to detect user data injection vulnerabilities in Flask
- Add checker to detect dangerous subprocess exec in aws-lambda handler functions
- Add checker to detect AWS Lambda SQL injection due to
event
tainted query