Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Perl analysis with zarn #1047

Merged
merged 22 commits into from Feb 26, 2024
Merged

Perl analysis with zarn #1047

merged 22 commits into from Feb 26, 2024

Conversation

m-1-k-3
Copy link
Member

@m-1-k-3 m-1-k-3 commented Feb 22, 2024

  • What kind of change does this PR introduce? (Bug fix, feature, docs update, ...)

Feature

  • What is the current behavior? (You can also link to an open issue here)

No perl code analysis integrated

  • What is the new behavior (if this is a feature change)? If possible add a screenshot.

Using zarn for code analysis - https://github.com/htrgouvea/zarn and https://heitorgouvea.me/2023/03/19/static-security-analysis-tool-perl

image

Important: This PR needs an update of the EMBA docker base image.

Important: We currently use commit 009331c in the EMBA base image. This results in more accurate line numbers but we are running into a higher false positive rate. See also htrgouvea/zarn#37 (comment)

@m-1-k-3 m-1-k-3 marked this pull request as draft February 22, 2024 14:46
@m-1-k-3 m-1-k-3 added enhancement New feature or request in progress Someone is working on this Core modules (Sxx) The core scanning modules (Sxx modules) EMBA labels Feb 22, 2024
@m-1-k-3 m-1-k-3 marked this pull request as ready for review February 25, 2024 09:35
@m-1-k-3
Copy link
Member Author

m-1-k-3 commented Feb 26, 2024

Base image updated ... will mergen now

@m-1-k-3 m-1-k-3 merged commit 055ba07 into e-m-b-a:master Feb 26, 2024
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Core modules (Sxx) The core scanning modules (Sxx modules) EMBA enhancement New feature or request in progress Someone is working on this
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant