Skip to content

fix(rules): add post-match filters for eval, weak-hash, ssl-verify - #493

Merged
ajianaz merged 1 commit into
developfrom
fix/security-filters-remaining-487
Aug 5, 2026
Merged

ajianaz merged 1 commit into
developfrom
fix/security-filters-remaining-487

Conversation

@ajianaz

@ajianaz ajianaz commented Aug 5, 2026

Copy link
Copy Markdown
Collaborator

What

Add post-match false-positive filters for the 3 remaining security scanner rules that lacked them: injection/eval, crypto/weak-hash, and crypto/ssl-verify-disabled.

Why

Epic #487 tracks defense-in-depth coverage for all 11 security patterns. After #491 (cors) and #492 (sql-concat, debug-enabled, hardcoded-role), 3 rules remained with regex-only matching — causing false positives on comments, docstrings, imports, and schema definitions.

This PR completes the epic: 11/11 rules now have defense-in-depth (narrow regex + post-match filter + doc-file skip).

How

injection/eval — is_false_positive_eval()

Suppresses:

  • Comment lines (//, #, --, /*, *)
  • Python/Rust docstrings (""", ''')
  • evaluate() / evaluation (not eval)
  • ast.literal_eval (safe parsing utility)

crypto/weak-hash — is_false_positive_weak_hash()

Suppresses:

  • Comment lines + docstrings
  • Import statements (import, use, require(, #include)
  • Type annotations / trait bounds (impl, fn, type)

crypto/ssl-verify-disabled — is_false_positive_ssl_verify()

Suppresses:

  • Comment lines + docstrings
  • Environment variable references (getenv, environ, from_env, process.env)
  • Schema/interface definitions (interface, schema, field(, default:)
  • Negation patterns (verify + true without false)

Testing

  • cargo test --features tree-sitter — 872 pass, 0 fail
  • cargo clippy --all-targets --features tree-sitter -- -D warnings — 0 warnings
  • cargo fmt --all -- --check — clean
  • cora review — passed (test fixture findings expected)
  • 18 new tests: 6 per rule (real detection + suppression cases)

Related Issues

Closes #487

Checklist

  • Tests pass
  • No clippy warnings
  • Formatted
  • PR description follows template
  • Commit messages follow conventional commits
  • Linked to relevant issues

)

Add defense-in-depth post-match false-positive filters for the 3
remaining security scanner rules without them:

- injection/eval: suppress comments, docstrings, 'evaluate' (not eval),
  ast.literal_eval (safe)
- crypto/weak-hash: suppress comments, docstrings, import/use statements,
  type annotations
- crypto/ssl-verify-disabled: suppress comments, docstrings, env var
  references, schema definitions, negation patterns

This completes epic #487 — all 11 security patterns now have
defense-in-depth coverage (narrow regex + post-match filter + doc skip).

18 new tests covering both detection and suppression for each rule.
@ajianaz
ajianaz merged commit 6493daa into develop Aug 5, 2026
13 checks passed
@ajianaz
ajianaz deleted the fix/security-filters-remaining-487 branch August 5, 2026 01:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Epic: Add post-match filters to remaining security scanner rules (defense-in-depth)

1 participant