-
Notifications
You must be signed in to change notification settings - Fork 33
Create rule S8347: ASP.NET applications should prefer file providers over direct file access (APPSEC-2834) #5953
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
4fd4bea to
1d65429
Compare
daniel-teuchert-sonarsource
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM!
I guess because we are not raising with a taint flow here it is also okay to not map any security standard to it right?
Otherwise we could also use this rule as an example for defining the new process of mapping standards.
|
@daniel-teuchert-sonarsource I simply don't know the process at this point of adding rules to existing standards, so I left it out. It would be a good example, I do agree. |
|
|





You can preview this rule here (updated a few minutes after each push).
Review
A dedicated reviewer checked the rule description successfully for: