1746 Commits

Author SHA1 Message Date
SonarTech
c716dba1e4 update coverage information 2023-02-23 00:33:04 +00:00
github-actions[bot]
c58572f626
Create rule S6505: Allowing shell scripts execution during package installation is security-sensitive (APPSEC-483) (#1584) 2023-02-22 16:09:29 +00:00
Mary Georgiou
ffd8720ca0
Modify rule S2223: Update description to include also the case of global state (#1583) 2023-02-22 15:19:19 +01:00
github-actions[bot]
13174db6cd
Create rule S6504: Having executables not owned by root is security-sensitive (#1581) 2023-02-22 14:35:19 +01:00
SonarTech
28cb47c898 update coverage information 2023-02-22 13:16:55 +00:00
Mary Georgiou
369a47bb71
Modify rule S1444(C#): Add info on decision to not implement this rule for C# (#1578) 2023-02-21 16:34:52 +00:00
SonarTech
9b5475af23 update coverage information 2023-02-21 00:32:51 +00:00
Loïc Joly
af33fce1b9
Modify rule S6191 CPP-3876 Update the RSPEC with un-deprecation of these uses in C++23
And make the description more beginner-friendly.
2023-02-20 17:50:29 +00:00
SonarTech
5acb8a684a update coverage information 2023-02-18 00:33:42 +00:00
Marco Borgeaud
dbc0a4e295
Modify rule S6181: Fix typos (CPP-4112) (#1577) 2023-02-17 12:35:10 +01:00
Arseniy Zaostrovnykh
4a54cf1b62
Modify S4433: fix the broken link (#1582) 2023-02-17 12:15:56 +01:00
maksim-grebeniuk-sonarsource
2ab90fb789
Modify rule S5890: Add a message in case of None value assignment (SONARPY-790) (#1573) 2023-02-17 08:55:51 +01:00
github-actions[bot]
a44203e93d
Modify rule S6437: Add Docker (APPSEC-462) (#1574) 2023-02-17 08:33:20 +01:00
Andrea Guarino
cbd4a1bc85
Remove link in french (#1580) 2023-02-16 16:43:19 +01:00
Antonio Aversa
6a81c5e8bb
Add missing semicolon (#1579) 2023-02-16 13:23:33 +00:00
Gregory Paidis
972f4dc5fb
S2198: Add C# (#1534)
* Change description and add some comments

* Update the description of what the C# implementation actually does for now

* Fix a typo

* Small formatting change on S2198

* Small formatting changes on S2198

* Small formatting change on S2198
2023-02-15 15:00:19 +01:00
github-actions[bot]
a8b5a83add
Create rule S3063: Add vbnet language (#1524)
* Add vbnet to rule S3063

* Add adoc for CS/VB

* Add exceptions

* Add invocations exceptions

* Addressed PR comments

* Semplifications, better wording on the descriptions

* Small description fix

* Add indexer and .Length expression exceptions and fix description

* sub-list to inline

* Fix typos

---------

Co-authored-by: cristian-ambrosini-sonarsource <cristian-ambrosini-sonarsource@users.noreply.github.com>
Co-authored-by: Cristian Ambrosini <cristian.ambrosini@sonarsource.com>
2023-02-15 13:07:42 +01:00
SonarTech
eb541d7fbe update coverage information 2023-02-15 00:33:19 +00:00
github-actions[bot]
42c626fe79
Modify rule S4830: Add Docker (APPSEC-457) (#1566)
* Add docker to rule S4830

* Update Docker rule

* Fix compilation error

* Fix compilation error but for real this time

---------

Co-authored-by: egon-okerman-sonarsource <egon-okerman-sonarsource@users.noreply.github.com>
Co-authored-by: Egon Okerman <egon.okerman@sonarsource.com>
2023-02-14 15:21:16 +01:00
github-actions[bot]
202faf5086
Modify rule S4790: Add Docker (APPSEC-459) (#1562)
* Add docker to rule S4790

* Add rule

* Add "sensitive" comment

* Fix compilation error

---------

Co-authored-by: egon-okerman-sonarsource <egon-okerman-sonarsource@users.noreply.github.com>
Co-authored-by: Egon Okerman <egon.okerman@sonarsource.com>
2023-02-14 14:29:19 +01:00
pedro-oliveira-sonarsource
1b5fe36f3f
Modify Rule S6472: Add Docker (APPSEC-277) (#1569) 2023-02-14 10:43:24 +01:00
SonarTech
8a5ec882f1 update coverage information 2023-02-11 00:32:09 +00:00
pedro-oliveira-sonarsource
86c7a71144
Modify Rule S2612: Add Docker (APPSEC-440) (#1560) 2023-02-10 09:35:50 +01:00
Alban Auzeill
2d779725a5
Modify rule S3400: Clarify the exceptions (#1568) 2023-02-10 09:05:57 +01:00
SonarTech
74e8cdb98f update coverage information 2023-02-10 00:32:59 +00:00
nicolas-gauthier-sonarsource
8e81480093
Modify rule S5496: Fix typo and update message (#1567) 2023-02-09 17:31:36 +01:00
Zsolt Kolbay
c3a629adcb
Add rule description files for C# and VB.NET (#1561) 2023-02-09 14:20:43 +01:00
github-actions[bot]
0c88ad07a4
Create rule S6497[Docker]: Using a container image based on its digest is security-sensitive (APPSEC-443) (#1515) 2023-02-09 12:16:47 +01:00
Yassin Kammoun
8656528c00
Modify rule S4423: Update issue message (#1558) 2023-02-09 11:34:23 +01:00
Zsolt Kolbay
5c16542452
Update rule message and VB.NET sample code (#1565) 2023-02-09 08:37:20 +01:00
pedro-oliveira-sonarsource
457586d53c
Modify Rule S6431: Add Docker (APPSEC-437) (#1540) 2023-02-08 15:58:26 +01:00
github-actions[bot]
7fecd63449
Create rule S4507: add Docker support (APPSEC-441) (#1542) 2023-02-07 15:04:20 +01:00
dorian-burihabwa-sonarsource
048101e017 Modify rule S1066: mark quick fix as "covered" 2023-02-07 14:55:09 +01:00
Irina Batinic
bdc2dd32c6
Modify S1656: Update quickfix status (SONARJAVA-3959) (#1551) 2023-02-07 11:46:20 +01:00
chrislain-razafimahefa-sonarsource
d96dbe3076
Modify S1217: update 'quickfix' status (SONARJAVA-4311) (#1543) 2023-02-07 11:40:59 +01:00
github-actions[bot]
4bfb86149f
Create rule S6500: Installing unnecessary packages is security-sensitive (APPSEC-439) (#1525) 2023-02-07 11:30:23 +01:00
Johann Beleites
54d84f9260
SONARJAVA-4403 Add exception to S3553 (#1536) 2023-02-07 10:49:54 +01:00
github-actions[bot]
50e655601b
Create rule S6502: Disabling builder sandboxes is security-sensitive (#1547) 2023-02-07 10:32:16 +01:00
dorian-burihabwa-sonarsource
058a07036c Modify rule S1450: mark quick fix as "partial" 2023-02-07 10:17:21 +01:00
github-actions[bot]
376687dcba
Modify rule S2147: mark quick fix as "covered" (#1554) 2023-02-07 09:56:39 +01:00
github-actions[bot]
a49526ac39
Modify rule S2129: mark quick fix as "covered" (#1555) 2023-02-07 09:56:27 +01:00
github-actions[bot]
dbe76ea560
Modify rule S2225: mark quick fix as "covered" (#1556) 2023-02-07 09:56:13 +01:00
github-actions[bot]
3566bef2fd
Modify rule S1132: mark quick fix as "covered" (#1557) 2023-02-07 09:55:57 +01:00
Loïc Joly
62a82ec8f0
Modify rule S1699 Rewrite the RSPEC to use C++ vocabulary 2023-02-06 18:57:08 +01:00
Irina Batinic
d206ef3f61
Modify S2116: Update quickfix status (SONARJAVA-4319) (#1550) 2023-02-06 18:05:31 +01:00
Zsolt Kolbay
cc46195759
Fix HTML link (#1549)
Fix links to include rule description
2023-02-06 16:01:57 +01:00
Zsolt Kolbay
f3480df4d9
S2166: Add C# and VB.NET (#1548)
* Add rule description for C#

* Add rule description for VB.NET

---------

Co-authored-by: Andrei Epure <38876598+andrei-epure-sonarsource@users.noreply.github.com>
2023-02-06 14:10:38 +01:00
Johann Beleites
ff343a582b
SONARJAVA-4327 Improve rule description, add Java exception (#1533) 2023-02-06 14:00:13 +01:00
chrislain-razafimahefa-sonarsource
d0ea589f48
Modify S4719: update quickfix status (SONARJAVA-3938) (#1544) 2023-02-06 10:57:28 +01:00
Yassin Kammoun
7a72747c45
Modify rule S5860: Improve documentation (#1546) 2023-02-06 09:50:52 +01:00