github / github/codeql

CodeQL maps CWE-730, which MITRE prohibits from being used for mapping

オープン
#22,318 コメント 2 件 リアクション 0 件 担当者 0 名 GitHub で見る
question
主要言語
CodeQL
スター
10.1k
フォーク
2.1k
平均マージ
2日 15時間
マージ済み PR(30日)
141

説明

CodeQL maps weakness CWE-730 on Code Scanning alerts. According to [MITRE](https://cwe.mitre.org/data/definitions/730.html), CWE-730 is a Category and it is marked PROHIBITED (this CWE ID must not be used to map to real-world vulnerabilities).

Also note that this CWE is not listed in [CodeQL's CWE coverage](https://codeql.github.com/codeql-query-help/full-cwe/) page in the docs.

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

Start by comparing the CodeQL alert mapping for CWE-730 with MITRE's definition and prohibition notice. Then inspect the CodeQL CWE coverage documentation to determine how the mapping is represented. Done means prohibited CWE-730 is no longer mapped to alerts and the documented coverage is consistent.

索引モデルが issue の本文から書いたものです。

評価

領域
documentation, security
issue の種類
バグ
難易度
3/5
見積もり時間
1〜2日
活発さ
静か
明瞭さ
おおむね明確
初心者へのやさしさ
55/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。