Skip to content

13.11 Analyzer Updates

THIS ISSUE DUPLICATES A PRIVATE INTERNAL RELEASE ISSUE PURELY FOR PUBLIC VISIBLITY https://gitlab.com/gitlab-org/security-products/release/-/issues/109

Prepare

@twoodham:

SAST

  • Check the analyzers list and make sure it includes the analyzers/languages recently added.

@gonzoyumo:

Dependency Scanning

  • Check the analyzers list and make sure it includes the analyzers/languages recently added.

Check upstream updates

Static Analysis Analyzers

Please scrutinize the following dependencies according to our the guidance listed in the handbook.

@rossfuhrman:

@ssarka:

@dsearles:

  • [-] flawfinder no updated needed as v0.11.1 is the latest release
  • [-] gosec no update needed as v2.7.0 is the latest release
  • [-] sobelow no update needed as v2.0.15 is the latest release

@zrice:

@theoretick:


@thiagocsf:

Container Scanning Analyzers

For each upstream scanner having an available update, please open a dedicated issue with ./script/update_scanner_issue.rb template.


@gonzoyumo:

For each upstream scanner having an available update, please open a dedicated issue with ./script/update_scanner_issue.rb template.

License Compliance

Dependency Scanning Analyzers

Post release

QA

Edited by Taylor McCaslin