Skip to content

fix: Revise README structure, fix formatting, update Docker docs, bum… - #7

Merged
seqradev merged 1 commit into
mainfrom
seqradev/publish
Jan 21, 2026
Merged

fix: Revise README structure, fix formatting, update Docker docs, bum…#7
seqradev merged 1 commit into
mainfrom
seqradev/publish

Conversation

@seqradev

Copy link
Copy Markdown
Member

…p version

@seqradev
seqradev merged commit e8208ae into main Jan 21, 2026
5 checks passed
@seqradev
seqradev deleted the seqradev/publish branch February 1, 2026 16:10
misonijnik pushed a commit that referenced this pull request Mar 19, 2026
misonijnik pushed a commit that referenced this pull request Mar 19, 2026
* Add LICENSE
Saloed added a commit that referenced this pull request Jun 29, 2026
Engine (opentaint-go-dataflow):
- #1 typed field-read source no longer crashes: thread GoFieldSignature.receiverType,
  allow This as a field-source condition base (taint target stays Result-only).
- #2 TypeUtils.matchesType matches interface implementations (method-set check,
  pointer/value rules, graceful fallback).
- #7 GoFunctionSignature.pkgName (declared package clause name) + candidates() branch
  so bare rand.* matches math/rand/v2.
- #11 GoConditionResolver.resolveWithType descends a single-element GoIRTupleType
  (single-return result) before a Field/Element modifier, so a result-field source
  taint action (cookie .Value) resolves and seeds field-sensitively. No whole-value taint.
- #12 GoCallExpr peels the receiver for DIRECT concrete pointer-receiver methods from the
  static target signature (fixes *sql.DB.Query arg indexing); no go-ssa-server change.
- #6 GoTaintConfiguration.matchPackage is exact for slash-qualified matchers.

Querylang (opentaint-go-querylang):
- #3 typed metavar in argument position parses to ParamCondition.TypeIs(Argument).
- #6 new GoImportRewriter pre-pass resolves package qualifiers from in-pattern imports.

Ruleset (rules/ruleset/go):
- #6 import-qualified package names across lib/security rules (bare where a local
  test-stub / ambiguous package / typed-receiver method pattern requires it).
- #7 weak-random drops the v2.* block.
- #11 http-sources cookies source taints [$I].Value.

Tooling: #10 restore scan --entry-point flag; re-point fn_investigate.py to
test rule reachability.

Gates: engine units 1300/1300; GoSampleBasedTest 95 (3 intentional skips);
rules/test/go detection harness 197/197.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
misonijnik added a commit that referenced this pull request Jul 3, 2026
- #7 PreparedStatementCreatorFactory:
newPreparedStatementCreator(String, Object[])
  DOES exist in Spring JDBC 5.3.x (arg0 is the SQL) — the "no String
overload" note
  was about the single-arg form. Added unsafeNewPSC using the 2-arg
overload;
  re-enabled. Suite: OK 979 | Skip 0 | FP 0 | FN 0.

- Removed the three disabled samples whose behavior is now captured by
minimal
  engine repros on misonijnik/core-engine-repros, leaving a NOTE that
points to
  each repro:
    - #2 staticResource(new URL("..."+resource))  ->
taint/WrapperPropagatorRepro
    - #3 ResponseEntity.header(..., "*") (varargs) ->
custom/BuilderChainMatchRepro
    - #9 (File $F).getCanonicalFile() sanitizer    ->
taint/InstanceSanitizerRepro
misonijnik added a commit that referenced this pull request Jul 3, 2026
- #7 PreparedStatementCreatorFactory:
newPreparedStatementCreator(String, Object[])
  DOES exist in Spring JDBC 5.3.x (arg0 is the SQL) — the "no String
overload" note
  was about the single-arg form. Added unsafeNewPSC using the 2-arg
overload;
  re-enabled. Suite: OK 979 | Skip 0 | FP 0 | FN 0.

- Removed the three disabled samples whose behavior is now captured by
minimal
  engine repros on misonijnik/core-engine-repros, leaving a NOTE that
points to
  each repro:
    - #2 staticResource(new URL("..."+resource))  ->
taint/WrapperPropagatorRepro
    - #3 ResponseEntity.header(..., "*") (varargs) ->
custom/BuilderChainMatchRepro
    - #9 (File $F).getCanonicalFile() sanitizer    ->
taint/InstanceSanitizerRepro
misonijnik added a commit that referenced this pull request Jul 3, 2026
- #7 PreparedStatementCreatorFactory:
newPreparedStatementCreator(String, Object[])
  DOES exist in Spring JDBC 5.3.x (arg0 is the SQL) — the "no String
overload" note
  was about the single-arg form. Added unsafeNewPSC using the 2-arg
overload;
  re-enabled. Suite: OK 979 | Skip 0 | FP 0 | FN 0.

- Removed the three disabled samples whose behavior is now captured by
minimal
  engine repros on misonijnik/core-engine-repros, leaving a NOTE that
points to
  each repro:
    - #2 staticResource(new URL("..."+resource))  ->
taint/WrapperPropagatorRepro
    - #3 ResponseEntity.header(..., "*") (varargs) ->
custom/BuilderChainMatchRepro
    - #9 (File $F).getCanonicalFile() sanitizer    ->
taint/InstanceSanitizerRepro
misonijnik added a commit that referenced this pull request Jul 4, 2026
- #7 PreparedStatementCreatorFactory:
newPreparedStatementCreator(String, Object[])
  DOES exist in Spring JDBC 5.3.x (arg0 is the SQL) — the "no String
overload" note
  was about the single-arg form. Added unsafeNewPSC using the 2-arg
overload;
  re-enabled. Suite: OK 979 | Skip 0 | FP 0 | FN 0.

- Removed the three disabled samples whose behavior is now captured by
minimal
  engine repros on misonijnik/core-engine-repros, leaving a NOTE that
points to
  each repro:
    - #2 staticResource(new URL("..."+resource))  ->
taint/WrapperPropagatorRepro
    - #3 ResponseEntity.header(..., "*") (varargs) ->
custom/BuilderChainMatchRepro
    - #9 (File $F).getCanonicalFile() sanitizer    ->
taint/InstanceSanitizerRepro
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant