Skip to content

Release v22.8.1

Choose a tag to compare

@github-actions github-actions released this 01 Sep 11:36
8a8c6ac

Summary

ARCCHR0009 judged a command property by its name alone. Its first contact with real code found two kinds of false positive: properties like AccessTokenExpiresAt, which contain the word "token" and hold a DateTimeOffset, and properties whose secret is wrapped in a concept the application had already marked — which the runtime honors but the analyzer did not, so it reported correct code. Both are fixed, and the documentation now says what to do when the rule is still wrong.

Changed

  • ARCCHR0009 no longer reports a property whose type cannot hold a secret — a date, a duration, a number, a bool, a Guid or an enum — however it is named, so AccessTokenExpiresAt is left alone while AccessToken is still reported (#2625)
  • ARCCHR0009 honors [NotAudited] and [PII] on the property's type, matching what the runtime already withholds, so marking a concept once covers every command that takes one (#2625)
  • ARCCHR0009 judges a concept by the value it wraps, so a ConceptAs<string> holding a token is reported and a ConceptAs<DateTimeOffset> is not (#2625)

Fixed

  • The ARCCHR0009 documentation told you to mark a false positive [NotAudited], which silences the warning by withholding the value rather than recording it; it now says to suppress the diagnostic and keep the value (#2625)