Skip to content

Java: whitelist variable names containing "tokenizer" for java/sensitive-log #17100

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 5 commits into from
Jul 31, 2024

Conversation

owen-mc
Copy link
Contributor

@owen-mc owen-mc commented Jul 30, 2024

No description provided.

@owen-mc owen-mc requested a review from a team as a code owner July 30, 2024 14:45
@owen-mc
Copy link
Contributor Author

owen-mc commented Jul 31, 2024

I ran a Variant Analysis query to see how many alerts this will remove. Out of 998 java repos, there were 2,313 alerts, but with a very uneven distribution. One repo had 1,302 alerts, the next had 592. The next 11 had 10-50 results. The number of repos with at least one result was 51.

@owen-mc owen-mc merged commit 8901b1f into github:main Jul 31, 2024
18 checks passed
@owen-mc owen-mc deleted the java/sensitive-log/ignore-tokenizer branch July 31, 2024 11:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants