Repository navigation
Releases: initialcodess/logdrop-taint-ios-action
Release list
LogDrop Taint v1.24.2
LogDrop Taint v1.24.2
Your configuration now says when it did nothing.
.logdrop.json has always refused what it cannot understand — an unknown field,
an unknown rule id, an unknown label. It said nothing about an entry that is
perfectly well-formed and never matches: a sink spelled differently in the code,
a sanitizer since renamed, a name written as three words. Those parsed, merged,
and never fired, and a clean report read as "nothing to find" when it meant "the
rule I added never ran".
When part of your config matched nothing in a scan, it is now named:
4 entries in your config matched nothing in this scan:
passthrough.nosuchcall
sanitizers.maskItt
sinks.myLoggerr
sources.noSuchMember
They were accepted; nothing in the scanned code reached them.
One case is not a typo and is worth stating on its own. A sensitiveNames entry
is matched against one word of a name or two adjacent ones, so a name of three
or more words never matches — including the field it was copied from. The
message says so, and points at sources, which matches a whole name exactly.
This is a notice, not a failure, and the exit code is untouched. An entry can
legitimately match nothing in a run: the code that uses it may sit behind
exclude, or in a directory that run did not scan. Printed without --verbose,
and silent when every entry matched.
No rule, default, exit code or flag changed. Findings on the same code are
identical to 1.24.1.
LogDrop Taint v1.24.1
LogDrop Taint v1.24.1
Two things reach you with this release, and the larger one is not the version
number.
A report that never arrives no longer fails your build. Every outcome of
sending to the panel — unreachable, refused key, rejected report — is now a loud
warning and a green step. It used to depend on which code came back: a rejected
report broke the build, an unreachable panel did not. That split rested on "a
400 is your own fault", which is not always true. A bundle id deleted or renamed
in the panel answers 400. A licence moved to another project answers 400.
Neither is something the developer whose pull request just went red can fix.
Set fail-on-delivery-error: "true" if you want the hard gate: then any failure
to deliver is exit 1. One switch, no per-code table.
A fix in the same area, which mattered more than the policy: GitHub runs shell:
bash with -e, and an unreachable panel was killing the step on the curl line —
before the branch that handles it and before the switch could be read. So the
one case the promise is most needed for was the one case it did not hold.
The action repository has been renamed to
initialcodess/logdrop-taint-ios-action, matching the Android half, which already
named its platform. Your existing uses: initialcodess/logdrop-taint-action@v1
keeps working — GitHub redirects — but new pipelines should use the new name,
and so should the download URLs in the CircleCI, GitLab, Jenkins, Bitrise,
fastlane and local recipes.
The analyzer itself changed in one line: the informationUri in every SARIF now
names the renamed repository, so the link in your report and in the panel points
at somewhere that exists rather than somewhere that forwards.
No rule, default, exit code or flag of the scan itself changed. Findings on the
same code are identical to 1.24.0.
LogDrop Taint v1.24.0
LogDrop Taint v1.24.0
The leak engine reaches a released binary for the first time, and it is on by
default. Three new rules, one of which does not port to Android and says so.
SWIFT-LEAK-RETAIN-CYCLE CWE-401 two objects keeping each
other alive, one of them
something the framework
meant to destroy
SWIFT-LEAK-MANUAL-ALLOCATION-NOT-RELEASED CWE-401 memory taken and not given
back on some path out
SWIFT-STRUCT-TLS-VALIDATION-DISABLED CWE-295 a certificate accepted with
nothing having checked it
--leaks is on by default; --no-leaks switches it off. The decision was measured on
what enters the report of somebody who did not ask: two findings across six real
projects, both confirmed by hand, neither wrong, at about 24% more scan time.
A scan now says how many bodies it could not model rather than skipping them in
silence, projects are indexed in one pass instead of two, and extensions are
indexed at all.
Verified as a prerelease first: v1.24.0-alpha1 was downloaded through the customer
path, checksum and all, and found the same real cycle in NetNewsWire that the
local build finds.
LogDrop Taint v1.24.0-alpha1 (test build)
A prerelease for testing. Not for customers.
@v1 is untouched and still serves v1.23.2. Nothing downloads this unless it is
asked for by name:
- uses: initialcodess/logdrop-taint-action@main
with:
analyzer-version: v1.24.0-alpha1The binary reports 1.24.0 — the version constant is the release's, and the
-alpha1 suffix belongs to this test tag rather than to the code.
What it carries, none of which has reached a released binary before:
- the leak engine, and
--leakson by default (--no-leaksswitches it off) SWIFT-LEAK-RETAIN-CYCLE,SWIFT-LEAK-MANUAL-ALLOCATION-NOT-RELEASEDSWIFT-STRUCT-TLS-VALIDATION-DISABLED- a scan that says how many bodies it could not model
- single-pass project indexing, extensions indexed
Verified before publishing, the way the release job verifies a real one:
universal binary (x86_64 + arm64), refuses to run without a licence (exit 2),
30 findings over examples/ across 13 rules, SARIF tool.driver.version 1.24.0.
LogDrop Taint v1.23.2
Update iOS suppression verification key
The analyzer now trusts suppression files signed by the Analyze API
Files signed with the previous key must be downloaded again
Analysis rules findings licence verification and SARIF format are unchanged
LogDrop Taint v1.23.1
1.23.1 — rotate the analyzer licence verification key
The analyzer now trusts the new licence signing pair used by LogDrop CRM. Licences signed with the previous key must be reissued before upgrading. Analysis rules, findings and the SARIF format are unchanged.
LogDrop Taint v1.23.0
LogDrop Taint 1.23.0 — rotate the suppressions signing key
The private half of the previous pair was printed to a terminal while verifying
the dev deploy. It never left that machine, never entered git and reached no
third party — but this key exists so that what it signs cannot be forged, and
that property is not something to reason about after the fact.
Rotated instead. The old key is worthless from this release on.
Done now because the cost is currently zero: the feature shipped yesterday and no
signed suppression file exists anywhere. The same rotation in six months would
invalidate every file in every customer repository.
The licence key pair is untouched. Different pair, never exposed, and every
licence already issued keeps working.
LogDrop Taint v1.22.0
LogDrop Taint 1.22.0
Signed suppressions. A customer can mark a finding "does not apply to us" in the
panel, and the analyzer honours that judgement — verified offline against a public
key it now embeds, with no request to anything.
The key is a different pair from the licence one. One key for both would mean
anyone able to issue a trial licence could also silence findings in any
repository.
Both analyzers embed the same public half, because one panel signs for both.
LogDrop Taint v1.21.0
LogDrop Taint 1.21.0
The first two rules that are not data flow: a hardcoded credential, where the
declaration itself is the finding, and configuration checks over Info.plist.
--fail-on-findings now counts errors and warnings, not notes.
LogDrop Taint v1.20.0
LogDrop Taint 1.20.0
A source can name its receiver, the way a sink already could. The half that reaches
customers is the config file: .logdrop.json's sources could only take a bare member
name, which for anything worth naming matches everything in a codebase. Qualified is
tried first and falls back, so every source registered before this is untouched.