Adding Semgrep Rules for SSRF in Java #462
Conversation
|
@salecharohit thank you for PR! I will review it this week as I want to review rules also :) But it looks solid on first glance |
Sure. I have a PR pending at Semgrep side as well. It'll be reviewed soon and will be published too. |
|
I reviewed the rules and it looks fine but I think that the url will change after they will merge it on sempgrep side. |
| [Semgrep](https://semgrep.dev/) is a command-line tool for offline static analysis. Use pre-built or custom rules to enforce code and security standards in your codebase. | ||
| Checkout the Semgrep rule for SSRF to identify/investigate for SSRF vulnerabilities in Java | ||
| [https://semgrep.dev/salecharohit:owasp_java_ssrf](https://semgrep.dev/salecharohit:owasp_java_ssrf) |
mackowski
Aug 11, 2020
Collaborator
I see that this link is to semgrep.dev/salecharohit:owsap_java_ssrf will it change after they merge your PR? Should we wait with this PR until they merge it master?
I see that this link is to semgrep.dev/salecharohit:owsap_java_ssrf will it change after they merge your PR? Should we wait with this PR until they merge it master?
|
@salecharohit any updates on this? Is your PR at Semgrep side merged? |
Yep. Here is the files in github Let me know if any other details are required. |
|
@salecharohit apologies for late replay but I was on a short break last week :) |
Absolutely fine , please don't apologise :-) Yep sure absolutely no problem. The only reason why I added the link to semgrep.live is because people can quickly run the rule and see the results. Update : The link mentioned by you is no longer valid. We had a re-arrangement of folders and below is the new link |
|
Hi @mackowski awaiting your decision as my XXE rules are also ready to integrate. I'd rather wait to send a PR for XXE once the SSRF is approved. |
|
Looks good |
|
@salecharohit go ahead and create PR for XXE - thank you for your contribution and apologies for long reply. |
Thank you for submitting a Pull Request (PR) to the Cheat Sheet Series.
Please make sure that for your contribution:
If your PR is related to an issue, please finish your PR text with the following line:
This PR covers issue #457
Thank you again for your contribution😃