fix(rules): add post-match filters for eval, weak-hash, ssl-verify - #493
Merged
Merged
Conversation
) Add defense-in-depth post-match false-positive filters for the 3 remaining security scanner rules without them: - injection/eval: suppress comments, docstrings, 'evaluate' (not eval), ast.literal_eval (safe) - crypto/weak-hash: suppress comments, docstrings, import/use statements, type annotations - crypto/ssl-verify-disabled: suppress comments, docstrings, env var references, schema definitions, negation patterns This completes epic #487 — all 11 security patterns now have defense-in-depth coverage (narrow regex + post-match filter + doc skip). 18 new tests covering both detection and suppression for each rule.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Add post-match false-positive filters for the 3 remaining security scanner rules that lacked them:
injection/eval,crypto/weak-hash, andcrypto/ssl-verify-disabled.Why
Epic #487 tracks defense-in-depth coverage for all 11 security patterns. After #491 (cors) and #492 (sql-concat, debug-enabled, hardcoded-role), 3 rules remained with regex-only matching — causing false positives on comments, docstrings, imports, and schema definitions.
This PR completes the epic: 11/11 rules now have defense-in-depth (narrow regex + post-match filter + doc-file skip).
How
injection/eval—is_false_positive_eval()Suppresses:
//,#,--,/*,*)""",''')evaluate()/evaluation(noteval)ast.literal_eval(safe parsing utility)crypto/weak-hash—is_false_positive_weak_hash()Suppresses:
import,use,require(,#include)impl,fn,type)crypto/ssl-verify-disabled—is_false_positive_ssl_verify()Suppresses:
getenv,environ,from_env,process.env)interface,schema,field(,default:)verify+truewithoutfalse)Testing
cargo test --features tree-sitter— 872 pass, 0 failcargo clippy --all-targets --features tree-sitter -- -D warnings— 0 warningscargo fmt --all -- --check— cleancora review— passed (test fixture findings expected)Related Issues
Closes #487
Checklist