konveyor / konveyor/rulesets

[BUG] [RULES] False positive on hardcorded IP rule hardcoded-ip-address

Open
#83 4 comments 0 reactions 0 assignees View on GitHub
kind/bug priority/important-soon triage/accepted
Dominant language
Java
Stars
6
Forks
49
PR merge metrics
No merged PRs in 30d

Description

### Konveyor version

0.5 beta 1

Tested with Kantra b0.5 beta1
**Target:** openjdk
**Source:** none
**Source code used:** https://github.com/openmrs/openmrs-core
**Rule triggered:** Hardcoded IP Address hardcoded-ip-address
**Report:** https://drive.google.com/file/d/12alisbavSvJ9-3O_8GNBkQ5-muk5Pgo

The rule is detecting ids and other elements like IPs.
This rule is also searching for IPs in comments.

![image](https://github.com/konveyor/analyzer-lsp/assets/117646518/4a073f0a-109c-4343-818b-cebeb7714ca0)
![image](https://github.com/konveyor/analyzer-lsp/assets/117646518/9c536315-5eae-4a94-8dbc-843c6ae5fea2)

Contributor guide

Open the contributing guide

Research direction

Start with the hardcoded-ip-address rule in the rulesets repository and reproduce it against the linked openmrs-core source or the provided report. Check how the rule handles identifiers and comments, then verify that genuine hardcoded IP addresses remain detected while those false positives no longer appear.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
devtools, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
52/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.