Open
Description
Hello,
I am getting some false positives with some of my queries, which are usually centered around a source node flowing into an object and then other data from that object flowing into a sink node.
Here is a simple example,
env.put(Context.SECURITY_CREDENTIALS, password);
LOG.error("connection error [{}], failover connection to [{}]", env.get(Context.PROVIDER_URL), this.ldapURI.toString());
In this case, password
is a source variable. While LOG.error
is a sink. However, by having it flow into env
, it now marks any use of the object as a detection eventough this case has nothing to do with password
. Is there any way to reduce cases like this?
Thank you