GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Wednesday, 22-May-2024 22:23:12 JSTHaelwenn /элвэн/ :triskell:Haelwenn /элвэн/ :triskell:
    in reply to
    • Kornel
    @kornel flawfinder matches on function names but not only.

    For example if you pass any kind of variable as formatting argument to printf family of functions, it's going to trigger because users able to pass an arbitrary string can end up being a flaw.
    Meanwhile a much more useful static analyzer would check if a buffer ends up set to said variable.

    Similarly checks against known TOCTOU flaws can be done much better with flow checks than labelling some functions as footguns.

    And while I guess something like flawfinder which is eager to label footguns can be useful for audits, it's way too noisy as a regular tool.
    In conversationabout a year ago from gnusocial.jppermalink
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.