Skip to content

13.12 Analyzer Updates (public issue)

THIS ISSUE DUPLICATES A PRIVATE INTERNAL RELEASE ISSUE PURELY FOR PUBLIC VISIBLITY https://gitlab.com/gitlab-org/security-products/release/-/issues/110

Prepare

@twoodham:

SAST

  • Check the analyzers list and make sure it includes the analyzers/languages recently added.

@gonzoyumo:

Dependency Scanning

  • Check the analyzers list and make sure it includes the analyzers/languages recently added.

Check upstream updates

Static Analysis Analyzers

Please scrutinize the following dependencies according to our the guidance listed in the handbook.

@rossfuhrman:

@ssarka:

@dsearles:

  • [-] flawfinder already uses the latest 2.0.15
  • [-] gosec already uses the latest v2.7.0
  • [-] sobelow already uses the latest 0.11.1

@zrice:

@theoretick:


@thiagocsf:

Container Scanning Analyzers

For each upstream scanner having an available update, please open a dedicated issue with ./script/update_scanner_issue.rb template.


@gonzoyumo:

For each upstream scanner having an available update, please open a dedicated issue with ./script/update_scanner_issue.rb template.

License Compliance

Dependency Scanning Analyzers

Post release

QA