Skip to content

Python: Limit what functions we treat as returning sensitive data#2248

Merged
tausbn merged 1 commit intogithub:masterfrom
RasmusWL:python-sensitive-data-fewer-fp
Nov 4, 2019
Merged

Python: Limit what functions we treat as returning sensitive data#2248
tausbn merged 1 commit intogithub:masterfrom
RasmusWL:python-sensitive-data-fewer-fp

Conversation

@RasmusWL
Copy link
Member

@RasmusWL RasmusWL commented Nov 4, 2019

Before this change, any function that has a parameter that was called
password/credentials would be treated as returning sensitive data of that
kind. py/clear-text-logging-sensitive-data would alert if one of these are
logged, which has a LOT of false-positives.

Before this change, any function that has a parameter that was called
password/credentials would be treated as returning sensitive data of that
kind. `py/clear-text-logging-sensitive-data` would alert if one of these are
logged, which has a LOT of false-positives.
@RasmusWL RasmusWL requested a review from tausbn November 4, 2019 14:00
@RasmusWL RasmusWL added the Python label Nov 4, 2019
@RasmusWL RasmusWL marked this pull request as ready for review November 4, 2019 14:00
Copy link
Contributor

@tausbn tausbn left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We discussed this already, and it looks good to me.

We should revisit this at a future date to see if there is some way to make use of sensitive-data-indicating keyword arguments, but for now I think it's fine to drop them.

@tausbn tausbn merged commit aa7a997 into github:master Nov 4, 2019
@RasmusWL RasmusWL deleted the python-sensitive-data-fewer-fp branch November 4, 2019 14:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants