7e0abe3c7e
* add semgrep yml * add semgrep ci job * remove replication semgrep rule in oss * fix makefile * add semgrep to ci * upwind triple if in ui.go semgrep refactoring
22 lines
723 B
YAML
22 lines
723 B
YAML
rules:
|
|
- id: logger-used-with-format-string
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: |
|
|
$LOGGER.Trace("=~/.*%[v#T%tbcdoOqxXUbeEfFgGps].*/",...)
|
|
- pattern: |
|
|
$LOGGER.Debug("=~/.*%[v#T%tbcdoOqxXUbeEfFgGps].*/",...)
|
|
- pattern: |
|
|
$LOGGER.Info("=~/.*%[v#T%tbcdoOqxXUbeEfFgGps].*/",...)
|
|
- pattern: |
|
|
$LOGGER.Warn("=~/.*%[v#T%tbcdoOqxXUbeEfFgGps].*/",...)
|
|
- pattern: |
|
|
$LOGGER.Error("=~/.*%[v#T%tbcdoOqxXUbeEfFgGps].*/",...)
|
|
- pattern-inside: |
|
|
import $LOG "github.com/hashicorp/go-hclog"
|
|
...
|
|
message: "Logger message looks like format string"
|
|
languages: [go]
|
|
severity: ERROR
|
|
|
|
|