7e0abe3c7e
* add semgrep yml * add semgrep ci job * remove replication semgrep rule in oss * fix makefile * add semgrep to ci * upwind triple if in ui.go semgrep refactoring
10 lines
317 B
YAML
10 lines
317 B
YAML
rules:
|
|
- id: physical-storage-bypass-encryption
|
|
patterns:
|
|
- pattern-either:
|
|
- pattern: $CORE.physical.Put(...)
|
|
- pattern: $CORE.underlyingPhysical.Put(...)
|
|
message: "Bypassing encryption by accessing physical storage directly"
|
|
languages: [go]
|
|
severity: WARNING
|