github / github/codeql

CodeQL maps CWE-730, which MITRE prohibits from being used for mapping

Offen
#22,318 2 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
question
Vorherrschende Sprache
CodeQL
Sterne
10.1k
Forks
2.1k
Ø Merge
2 T. 15 Std.
Gemergte PRs (30 T.)
141

Beschreibung

CodeQL maps weakness CWE-730 on Code Scanning alerts. According to [MITRE](https://cwe.mitre.org/data/definitions/730.html), CWE-730 is a Category and it is marked PROHIBITED (this CWE ID must not be used to map to real-world vulnerabilities).

Also note that this CWE is not listed in [CodeQL's CWE coverage](https://codeql.github.com/codeql-query-help/full-cwe/) page in the docs.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Start by comparing the CodeQL alert mapping for CWE-730 with MITRE's definition and prohibition notice. Then inspect the CodeQL CWE coverage documentation to determine how the mapping is represented. Done means prohibited CWE-730 is no longer mapped to alerts and the documented coverage is consistent.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Bereich
documentation, security
Issue-Typ
Bug
Schwierigkeit
3/5
Geschätzter Aufwand
1-2 Tage
Aktivitätsstatus
Ruhig
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
55/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.