github / github/codeql

False positive - when json.Marshal output is used - cant result in "Potentially unsafe quoting"

オープン
#14,159 コメント 3 件 リアクション 0 件 担当者 0 名 GitHub で見る
acknowledged false-positive Go
主要言語
CodeQL
スター
10.1k
フォーク
2.1k
平均マージ
2日 15時間
マージ済み PR(30日)
141

説明

**Description of the false positive**

An output of golang json.Marshal is apparently not at risk for `unsafe quoting`

**Code samples or links to source code**
```
...
learned, errMarshal := json.Marshal(guardianSpec.Learned)
...
str := fmt.Sprintf(`[{"op":"replace","path":"/spec/learned","value":%s},{"op":"replace","path":"/spec/samples","value":%d}]`, learned, guardianSpec.NumSamples)
...
```

**URL to the alert on GitHub code scanning (optional)**
https://github.com/knative-extensions/security-guard/pull/236

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。