Skip to content

Commit 01f0d05

Browse files
committed
Python: Turn off default taint steps for
subscript and for.
1 parent 1db15b4 commit 01f0d05

File tree

1 file changed

+4
-4
lines changed

1 file changed

+4
-4
lines changed

python/ql/src/semmle/python/dataflow/new/internal/TaintTrackingPrivate.qll

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -27,16 +27,16 @@ predicate defaultAdditionalTaintStep(DataFlow::Node nodeFrom, DataFlow::Node nod
2727
predicate localAdditionalTaintStep(DataFlow::Node nodeFrom, DataFlow::Node nodeTo) {
2828
concatStep(nodeFrom, nodeTo)
2929
or
30-
subscriptStep(nodeFrom, nodeTo)
31-
or
30+
// subscriptStep(nodeFrom, nodeTo)
31+
// or
3232
stringManipulation(nodeFrom, nodeTo)
3333
or
3434
containerStep(nodeFrom, nodeTo)
3535
or
3636
copyStep(nodeFrom, nodeTo)
3737
or
38-
forStep(nodeFrom, nodeTo)
39-
or
38+
// forStep(nodeFrom, nodeTo)
39+
// or
4040
unpackingAssignmentStep(nodeFrom, nodeTo)
4141
}
4242

0 commit comments

Comments
 (0)