9 Commits

Author SHA1 Message Date
Pierre-Loup
e769e586c9
Update security rules: add OWASP Mobile Top 10 2024 security standard (APPSEC-2383) (#4660) 2025-02-19 17:19:00 +01:00
Jamie Anderson
9ee16daa47
Modify rules: Add STIG AS&D 2023-06-08 mappings (#3914)
* Update JSON schema to include STIG ASD 2023-06-08 mapping

* Update rules to add STIG metadata mappings

---------

Co-authored-by: Loris Sierra <loris.sierra@sonarsource.com>
2024-05-06 08:56:31 +02:00
Pierre-Loup
770348d041
Avoid OWASP Top 10 security-standard mismatch between metadata and description links (RULEAPI-798) (#3537)
* Add check for security standard mismatch

* Fix security standard mismatches

* Fix Resources/Standards links for secrets rules

* Fix check

* Fix links and update security standard mapping

* Fix maintanability issue

* Apply review suggestions

* Apply suggestions from code review

Co-authored-by: Egon Okerman <egon.okerman@sonarsource.com>

* Fix typo

Co-authored-by: Egon Okerman <egon.okerman@sonarsource.com>

---------

Co-authored-by: Egon Okerman <egon.okerman@sonarsource.com>
2024-01-17 17:20:28 +01:00
Egon Okerman
d1417e82f8
Modify CWE and OWASP Top 10 links to follow standard link format (APPSEC-1134) (#3529)
* Fix all CWE references

* Fix all OWASP references

* Fix missing CWE prefixes
2024-01-15 17:15:56 +01:00
Loris S
62788cdfcc Modify rule S2083(mult. lang): Add absolute path joining pitfall (APPSEC-213) (#1370) 2023-03-02 18:48:41 +01:00
Loris S
f8e412528e Modify S2083(multiple languages): Update to the education framework (APPSEC-188) (#1328) 2023-03-02 18:22:24 +01:00
Loris S
16919a7fc1 Modify S2083&S6096(Education): Add Partial Path Traversal to pitfalls (#1243) 2023-03-02 18:22:24 +01:00
Pierre-Loup
dbca6ec12c Modify rule S2083[C#]: Educational content (APPSEC-49) (#1121) 2023-03-02 18:07:54 +01:00
Pierre-Loup
9d944403b4 [APPSEC-48] Modify rule S2083[java]: Educational content (#1112) 2023-03-02 18:07:54 +01:00