Repository navigation
LogDrop Taint v1.24.2
Your configuration now says when it did nothing.
.logdrop.json has always refused what it cannot understand — an unknown field,
an unknown rule id, an unknown label. It said nothing about an entry that is
perfectly well-formed and never matches: a sink spelled differently in the code,
a sanitizer since renamed, a name written as three words. Those parsed, merged,
and never fired, and a clean report read as "nothing to find" when it meant "the
rule I added never ran".
When part of your config matched nothing in a scan, it is now named:
4 entries in your config matched nothing in this scan:
passthrough.nosuchcall
sanitizers.maskItt
sinks.myLoggerr
sources.noSuchMember
They were accepted; nothing in the scanned code reached them.
One case is not a typo and is worth stating on its own. A sensitiveNames entry
is matched against one word of a name or two adjacent ones, so a name of three
or more words never matches — including the field it was copied from. The
message says so, and points at sources, which matches a whole name exactly.
This is a notice, not a failure, and the exit code is untouched. An entry can
legitimately match nothing in a run: the code that uses it may sit behind
exclude, or in a directory that run did not scan. Printed without --verbose,
and silent when every entry matched.
No rule, default, exit code or flag changed. Findings on the same code are
identical to 1.24.1.