14.4 Analyzer Updates - public issue

THIS ISSUE DUPLICATES A PRIVATE INTERNAL RELEASE ISSUE PURELY FOR PUBLIC VISIBILITY https://gitlab.com/gitlab-org/security-products/release/-/issues/115

Static Analysis Analyzers

Please scrutinize the following dependencies according to our the guidance listed in the handbook.

  • brakeman

  • phpcs-security-audit

  • security-code-scan

  • bandit

  • eslint - gitlab-org/security-products/analyzers/eslint!92 (merged)

  • eslint package.json and other dependencies - gitlab-org/security-products/analyzers/eslint!92 (merged)

  • mobSF - gitlab-org/security-products/analyzers/mobsf!38 (merged)

  • flawfinder | gitlab-org/security-products/analyzers/flawfinder!68 (merged)

  • gosec

  • sobelow

  • semgrep | gitlab-org/security-products/analyzers/semgrep!82 (merged) | gitlab-org/security-products/analyzers/semgrep!83 (merged)

  • kubesec

  • nodejs-scan

  • secrets

  • pmd-apex gitlab-org/security-products/analyzers/pmd-apex!70 (merged)

  • spotbugs


Edited Oct 21, 2021 by Taylor McCaslin
Assignee Loading
Time tracking Loading