diff --git a/analyzer/codechecker_analyzer/analyzer_context.py b/analyzer/codechecker_analyzer/analyzer_context.py index 13d23c2f43..ace0f22f48 100644 --- a/analyzer/codechecker_analyzer/analyzer_context.py +++ b/analyzer/codechecker_analyzer/analyzer_context.py @@ -62,8 +62,8 @@ def __init__(self): lcfg_dict = self.__get_package_layout() self.pckg_layout = lcfg_dict['runtime'] - self._checker_labels = CheckerLabels(labels_dir) self._guidelines = Guidelines(guidelines_dir) + self._checker_labels = CheckerLabels(labels_dir, self._guidelines) self.__package_version = None self.__package_build_date = None self.__package_git_hash = None diff --git a/analyzer/codechecker_analyzer/cli/checkers.py b/analyzer/codechecker_analyzer/cli/checkers.py index d40aded869..07e9e7bb1a 100644 --- a/analyzer/codechecker_analyzer/cli/checkers.py +++ b/analyzer/codechecker_analyzer/cli/checkers.py @@ -190,27 +190,32 @@ def __uglify(text: str) -> str: def __guideline_to_label( - args: argparse.Namespace, - cl: CheckerLabels + args: argparse.Namespace ) -> str: """ Transforms --guideline parameter as if they were given through --label. For example "--guideline sei-cert-c" is equivalent with "--label guideline:sei-cert-c" and "--guideline sei-cert-c:str38-c" is the - same as "--label sei-cert-c:str38-c". + same as "--label rule:str38-c". + + A guideline is derived in memory from the "rule:" labels of a + checker, so a whole-guideline query is expressed as a "guideline:" + label and a single-rule query as a "rule:" label. """ - guidelines = [] - for analyzer in args.analyzers: - guidelines.extend(cl.occurring_values('guideline', analyzer)) + guidelines = analyzer_context.get_context().guideline + all_guidelines = list(guidelines.all_guidelines()) - if args.guideline in guidelines: + if args.guideline in all_guidelines: return f'guideline:{args.guideline}' elif args.guideline.find(':') == -1: LOG.error('--guideline parameter is either or ' ':') sys.exit(1) - return args.guideline + # ":" form -> query by the rule only, since the guideline + # is derived from the rule in memory. + _, rule = args.guideline.split(':', 1) + return f'rule:{rule}' def __get_detailed_checker_info( @@ -256,7 +261,8 @@ def __get_detailed_checker_info( profile_checkers.append((f'severity:{args.severity}', True)) if 'guideline' in args: - profile_checkers.append((__guideline_to_label(args, cl), True)) + profile_checkers.append( + (__guideline_to_label(args), True)) config_handler.initialize_checkers(checkers, profile_checkers) @@ -312,7 +318,7 @@ def __print_severities(args: argparse.Namespace, cl: CheckerLabels): print(twodim.to_str(args.output_format, header, rows)) -def __print_guidelines(args: argparse.Namespace, cl: CheckerLabels): +def __print_guidelines(args: argparse.Namespace): """ Print guidelines according to the command line arguments to the standard output. @@ -320,10 +326,11 @@ def __print_guidelines(args: argparse.Namespace, cl: CheckerLabels): if args.output_format == 'custom': args.output_format = 'rows' - result = {} + guidelines = analyzer_context.get_context().guideline - for guideline in cl.get_description('guideline'): - result[guideline] = set(cl.occurring_values(guideline)) + result = {} + for guideline in guidelines.all_guidelines(): + result[guideline] = set(guidelines.rules_of_guideline(guideline)) header = ['Guideline', 'Rules'] if args.output_format in ['csv', 'json']: @@ -468,7 +475,7 @@ def __print_checkers(args: argparse.Namespace, cl: CheckerLabels): labels.append(f'profile:{args.profile}') if 'guideline' in args: - labels.append(__guideline_to_label(args, cl)) + labels.append(__guideline_to_label(args)) if 'severity' in args: labels.append(f'severity:{args.severity}') @@ -594,7 +601,7 @@ def main(args): return if 'guideline' in args and not args.guideline: - __print_guidelines(args, cl) + __print_guidelines(args) return if 'label' in args and not args.label: diff --git a/analyzer/tests/unit/test_checker_labels.py b/analyzer/tests/unit/test_checker_labels.py index cbeaf8e5b9..e2f2ba2d43 100644 --- a/analyzer/tests/unit/test_checker_labels.py +++ b/analyzer/tests/unit/test_checker_labels.py @@ -17,6 +17,18 @@ from codechecker_common.checker_labels import CheckerLabels +class _FakeGuidelines: + """ + Minimal stand-in for the Guidelines object. Maps rule ids to the + guidelines that contain them. + """ + def __init__(self, rule_to_guidelines): + self._rule_to_guidelines = rule_to_guidelines + + def guidelines_of_rule(self, rule_id): + return list(self._rule_to_guidelines.get(rule_id, [])) + + class TestCheckerLabels(unittest.TestCase): def setUp(self) -> None: self.labels_dir = tempfile.TemporaryDirectory() @@ -38,8 +50,9 @@ def initialize_labels_dir(self): "MEDIUM": "Medium documentation", "UNSPECIFIED": "Unspecified documentation" }, - "guideline": { - "sei-cert-c": "SEI-CERT C documentation" + "profile-containment": { + "extreme": ["sensitive"], + "sensitive": ["default"] } } @@ -58,18 +71,14 @@ def initialize_labels_dir(self): "severity:HIGH" ], "core.DivideZero": [ - "profile:default", "profile:sensitive", "severity:HIGH" ], "core.NonNullParamChecker": [ - "profile:default", "profile:sensitive", "severity:HIGH" ], "core.builtin.NoReturnFunctions": [ - "profile:default", - "profile:sensitive", "profile:extreme", "severity:MEDIUM" ], @@ -89,8 +98,6 @@ def initialize_labels_dir(self): "severity:HIGH" ], "bugprone-undelegated-constructor": [ - "profile:default", - "profile:sensitive", "profile:extreme", "severity:MEDIUM" ], @@ -98,11 +105,9 @@ def initialize_labels_dir(self): "profile:extreme" ], "cert-err34-c": [ - "profile:sensitive", - "profile:security", "profile:extreme", - "guideline:sei-cert-c", - "sei-cert-c:err34-c", + "profile:security", + "rule:err34-c", "severity:LOW" ] } @@ -114,7 +119,8 @@ def initialize_labels_dir(self): json.dump(labels, f) def test_checker_labels(self): - cl = CheckerLabels(self.labels_dir.name) + guidelines = _FakeGuidelines({"err34-c": ["sei-cert-c"]}) + cl = CheckerLabels(self.labels_dir.name, guidelines) self.assertEqual( sorted(cl.get_analyzers()), @@ -123,15 +129,34 @@ def test_checker_labels(self): "clangsa" ])) + # Query "extreme" expands to {extreme, sensitive, default}, so it + # matches every checker with any containment tier. self.assertEqual( sorted(cl.checkers_by_labels([ 'profile:extreme'])), sorted([ + 'core.DivideZero', + 'core.NonNullParamChecker', 'core.builtin.NoReturnFunctions', 'bugprone-undelegated-constructor', 'google-objc-global-variable-declaration', 'cert-err34-c'])) + # Query "sensitive" expands to {sensitive, default}: extreme-labeled + # checkers are NOT matched. + self.assertEqual( + sorted(cl.checkers_by_labels([ + 'profile:sensitive'], 'clangsa')), + sorted([ + 'core.DivideZero', + 'core.NonNullParamChecker'])) + + # Query "default" matches only default-labeled checkers (smallest + # set). The test data has none in clangsa. + self.assertEqual( + sorted(cl.checkers_by_labels(['profile:default'], 'clangsa')), + []) + self.assertEqual( sorted(cl.checkers_by_labels([ 'profile:extreme', @@ -164,6 +189,18 @@ def test_checker_labels(self): cl.label_of_checker('globalChecker', 'profile'), ['security']) + # label_of_checker returns the checker's single containment tier; + # the containment relation is applied on the query side, not here. + self.assertEqual( + cl.label_of_checker( + 'core.builtin.NoReturnFunctions', 'profile', 'clangsa'), + ['extreme']) + + # Guideline derived from the rule label. + self.assertEqual( + cl.label_of_checker('cert-err34-c', 'guideline', 'clang-tidy'), + ['sei-cert-c']) + self.assertEqual( cl.label_of_checker( 'bugprone-undelegated-constructor', 'severity', 'clang-tidy'), @@ -180,14 +217,6 @@ def test_checker_labels(self): ('profile', 'security'), ('severity', 'HIGH')])) - self.assertEqual( - sorted(cl.labels()), - sorted(['guideline', 'profile', 'sei-cert-c', 'severity'])) - - self.assertEqual( - sorted(cl.occurring_values('profile')), - sorted(['default', 'extreme', 'security', 'sensitive'])) - self.assertEqual( cl.severity('bugprone-undelegated-constructor'), 'MEDIUM') diff --git a/analyzer/tests/unit/test_guidelines.py b/analyzer/tests/unit/test_guidelines.py index 568edc1f2e..e3560fad1c 100644 --- a/analyzer/tests/unit/test_guidelines.py +++ b/analyzer/tests/unit/test_guidelines.py @@ -20,48 +20,57 @@ class TestGuidelines(unittest.TestCase): def setUp(self) -> None: self.guidelines_dir = tempfile.TemporaryDirectory() + self.rules_dir = tempfile.TemporaryDirectory() self.initialize_guidelines_dir() def tearDown(self) -> None: self.guidelines_dir.cleanup() + self.rules_dir.cleanup() def initialize_guidelines_dir(self): + base_url = ("https://cmu-sei.github.io/secure-coding-standards/" + "sei-cert-cpp-coding-standard/rules/concurrency-con") + + # Rule details are the single source of truth (config/rules). + rules = [ + { + "rule_id": "con50-cpp", + "title": "", + "rule_url": f"{base_url}/con50-cpp/" + }, + { + "rule_id": "con51-cpp", + "title": "", + "rule_url": f"{base_url}/con51-cpp/" + }, + { + "rule_id": "con52-cpp", + "title": "", + "rule_url": f"{base_url}/con52-cpp/" + }, + { + "rule_id": "con53-cpp", + "title": "", + "rule_url": f"{base_url}/con53-cpp/" + }, + ] + + with open(os.path.join(self.rules_dir.name, 'sei-cert-rules.yaml'), + 'w', encoding='utf-8') as fp: + yaml.safe_dump(rules, fp, default_flow_style=False) + + # Guideline descriptor references rule ids only (config/guidelines). guidelines = { "guideline": "sei-cert-cpp", "guideline_title": "SEI CERT C++ Coding Standard", + "guideline_url": + "https://cmu-sei.github.io/secure-coding-standards/" + "sei-cert-cpp-coding-standard/", "rules": [ - { - "rule_id": "con50-cpp", - "rule_url": - "https://cmu-sei.github.io/secure-coding" - "-standards/sei-cert-cpp-coding-standard" - "/rules/concurrency-con/con50-cpp/", - "title": "" - }, - { - "rule_id": "con51-cpp", - "rule_url": - "https://cmu-sei.github.io/secure-coding" - "-standards/sei-cert-cpp-coding-standard" - "/rules/concurrency-con/con51-cpp/", - "title": "" - }, - { - "rule_id": "con52-cpp", - "rule_url": - "https://cmu-sei.github.io/secure-coding" - "-standards/sei-cert-cpp-coding-standard" - "/rules/concurrency-con/con52-cpp/", - "title": "" - }, - { - "rule_id": "con53-cpp", - "rule_url": - "https://cmu-sei.github.io/secure-coding" - "-standards/sei-cert-cpp-coding-standard" - "/rules/concurrency-con/con53-cpp/", - "title": "" - }, + {"rule_id": "con50-cpp"}, + {"rule_id": "con51-cpp"}, + {"rule_id": "con52-cpp"}, + {"rule_id": "con53-cpp"}, ] } @@ -70,7 +79,7 @@ def initialize_guidelines_dir(self): yaml.safe_dump(guidelines, fp, default_flow_style=False) def test_guidelines(self): - g = Guidelines(self.guidelines_dir.name) + g = Guidelines(self.guidelines_dir.name, self.rules_dir.name) self.assertNotEqual(len(g.rules_of_guideline("sei-cert-cpp")), 0) @@ -78,35 +87,46 @@ def test_guidelines(self): sorted(g.rules_of_guideline("sei-cert-cpp").keys()), ["con50-cpp", "con51-cpp", "con52-cpp", "con53-cpp"]) + base_url = ("https://cmu-sei.github.io/secure-coding-standards/" + "sei-cert-cpp-coding-standard/rules/concurrency-con") + self.assertEqual( g.rules_of_guideline("sei-cert-cpp"), { "con50-cpp": { - "rule_url": - "https://cmu-sei.github.io/secure-coding" - "-standards/sei-cert-cpp-coding-standard" - "/rules/concurrency-con/con50-cpp/", + "rule_url": f"{base_url}/con50-cpp/", "title": "" }, "con51-cpp": { - "rule_url": - "https://cmu-sei.github.io/secure-coding" - "-standards/sei-cert-cpp-coding-standard" - "/rules/concurrency-con/con51-cpp/", + "rule_url": f"{base_url}/con51-cpp/", "title": "" }, "con52-cpp": { - "rule_url": - "https://cmu-sei.github.io/secure-coding" - "-standards/sei-cert-cpp-coding-standard" - "/rules/concurrency-con/con52-cpp/", + "rule_url": f"{base_url}/con52-cpp/", "title": "" }, "con53-cpp": { - "rule_url": - "https://cmu-sei.github.io/secure-coding" - "-standards/sei-cert-cpp-coding-standard" - "/rules/concurrency-con/con53-cpp/", + "rule_url": f"{base_url}/con53-cpp/", "title": "" }, }) + + def test_guidelines_of_rule(self): + g = Guidelines(self.guidelines_dir.name, self.rules_dir.name) + + self.assertEqual( + g.guidelines_of_rule("con50-cpp"), ["sei-cert-cpp"]) + self.assertEqual(g.guidelines_of_rule("nonexistent"), []) + + def test_rule_details(self): + g = Guidelines(self.guidelines_dir.name, self.rules_dir.name) + + base_url = ("https://cmu-sei.github.io/secure-coding-standards/" + "sei-cert-cpp-coding-standard/rules/concurrency-con") + + self.assertEqual( + g.rule_details("con51-cpp"), + {"title": "", "rule_url": f"{base_url}/con51-cpp/"}) + self.assertEqual( + g.rule_details("nonexistent"), + {"title": "", "rule_url": ""}) diff --git a/codechecker_common/checker_labels.py b/codechecker_common/checker_labels.py index d3dcc69bf2..b8bbf9dabc 100644 --- a/codechecker_common/checker_labels.py +++ b/codechecker_common/checker_labels.py @@ -7,7 +7,8 @@ # ------------------------------------------------------------------------- from collections import defaultdict import os -from typing import Any, cast, Iterable + +from typing import Any, cast, Iterable, List from codechecker_common.util import load_json @@ -43,11 +44,15 @@ class CheckerLabels: 'blacklist': 'false', 'description': ''} - def __init__(self, checker_labels_dir: str): + def __init__(self, checker_labels_dir: str, guidelines=None): if not os.path.isdir(checker_labels_dir): raise NotADirectoryError( f'{checker_labels_dir} is not a directory.') + # Optional Guidelines object. When provided, the guidelines a checker + # belongs to are derived in memory from its "rule:" labels. + self.__guidelines = guidelines + label_json_files: Iterable[str] = os.listdir( os.path.join(checker_labels_dir, 'analyzers')) @@ -57,6 +62,13 @@ def __init__(self, checker_labels_dir: str): self.__descriptions = load_json(os.path.join( checker_labels_dir, 'descriptions.json')) + # Profile containment maps a profile to the profiles it also implies. + # E.g. { "extreme": ["sensitive"], "sensitive": ["default"] } means a + # checker labeled with "extreme" also belongs to "sensitive" and + # "default". The relation is applied transitively. + self.__profile_containment = \ + self.__descriptions.get('profile-containment', {}) + label_json_files = map( lambda f: os.path.join(checker_labels_dir, 'analyzers', f), label_json_files) @@ -155,6 +167,98 @@ def __get_analyzer_data( if analyzer is None or a == analyzer: yield a, c + def __expand_query_profiles(self, profiles: Iterable[str]) -> List[str]: + """ + Expand the requested profile values of a query through the + profile-containment relation. The containment maps a profile to the + profiles it contains, e.g. {"extreme": ["sensitive"], + "sensitive": ["default"]}. Filtering by a profile also matches the + checkers of the profiles it contains, applied transitively: + + query "default" -> matches {default} + query "sensitive" -> matches {sensitive, default} + query "extreme" -> matches {extreme, sensitive, default} + + This way "default" is the smallest set (only default-labeled + checkers), "sensitive" additionally includes default-labeled checkers, + and "extreme" includes default- and sensitive-labeled checkers too. + The result preserves uniqueness. + """ + result: List[str] = [] + stack = list(profiles) + + while stack: + profile = stack.pop() + if profile in result: + continue + result.append(profile) + stack.extend(self.__profile_containment.get(profile, [])) + + return result + + def __expand_filter_labels( + self, + filter_labels: Iterable[tuple[str, str]] + ) -> set[tuple[str, str]]: + """ + Expand the (label, value) pairs of a filter so that profile filters + also match the profiles they contain (see __expand_query_profiles). + Non-profile labels are kept unchanged. + """ + expanded: set[tuple[str, str]] = set() + + for key, value in filter_labels: + if key == 'profile': + for prof in self.__expand_query_profiles([value]): + expanded.add(('profile', prof)) + else: + expanded.add((key, value)) + + return expanded + + def __derived_guidelines( + self, + rule_values: Iterable[str] + ) -> List[tuple[str, str]]: + """ + Derive the guideline labels of a checker from its rule values. For + every "rule:" of a checker the guidelines that contain the + given rule are looked up and returned as ("guideline", ) pairs. + Requires a Guidelines object to be injected; without it an empty list + is returned. + """ + if self.__guidelines is None: + return [] + + guidelines: List[tuple[str, str]] = [] + seen: set[str] = set() + + for rule_id in rule_values: + for guideline in self.__guidelines.guidelines_of_rule(rule_id): + if guideline not in seen: + seen.add(guideline) + guidelines.append(('guideline', guideline)) + + return guidelines + + def __augment_labels( + self, + labels: List[tuple[str, str]] + ) -> List[tuple[str, str]]: + """ + Augment a checker's raw (label, value) pairs with the information that + is derived in memory. Currently this derives the guideline labels from + the checker's rule values. The checker's profile label is left as its + single tier; the containment relation is applied on the query side + (see __expand_filter_labels) instead of expanding checker membership. + """ + rule_values = [value for key, value in labels if key == 'rule'] + + augmented: List[tuple[str, str]] = list(labels) + augmented.extend(self.__derived_guidelines(rule_values)) + + return augmented + def get_analyzers(self) -> Iterable[str]: return self.__data.keys() @@ -174,11 +278,13 @@ def checkers_by_labels( """ collection = [] - label_set = set(map(split_label_kv, filter_labels)) + label_set = self.__expand_filter_labels( + map(split_label_kv, filter_labels)) for _, checkers in self.__get_analyzer_data(analyzer): for checker, labels in checkers.items(): - labels = set(map(split_label_kv, labels)) + labels = set(self.__augment_labels( + list(map(split_label_kv, labels)))) if labels.intersection(label_set): collection.append(checker) @@ -246,6 +352,8 @@ def labels_of_checker( labels.extend(map(split_label_kv, checkers.get(c, []))) + labels = self.__augment_labels(labels) + # TODO set() is used for uniqueing results in case a checker name is # provided by multiple analyzers. This will be unnecessary when we # cover this case properly. @@ -270,7 +378,9 @@ def checkers(self, analyzer: str | None = None) -> list[str]: def labels(self, analyzer: str | None = None) -> list[str]: """ - Returns a list of occurring labels. + Returns a list of occurring labels. When a Guidelines object is + available the derived "guideline" label is also reported, since a + checker's guidelines are derived in memory from its "rule" labels. """ collection: set[str] = set() @@ -279,6 +389,9 @@ def labels(self, analyzer: str | None = None) -> list[str]: collection.update(map( lambda x: split_label_kv(x)[0], labels)) + if self.__guidelines is not None: + collection.add('guideline') + return list(collection) def occurring_values( @@ -290,6 +403,11 @@ def occurring_values( Return the list of values belonging to the given label which were used for at least one checker. """ + # Guidelines are derived from rules, so their values come from the + # Guidelines object rather than from raw labels. + if label == 'guideline' and self.__guidelines is not None: + return list(self.__guidelines.all_guidelines()) + values = set() for _, checkers in self.__get_analyzer_data(analyzer): diff --git a/codechecker_common/guidelines.py b/codechecker_common/guidelines.py index 828965d812..1bc0f7a8fd 100644 --- a/codechecker_common/guidelines.py +++ b/codechecker_common/guidelines.py @@ -6,7 +6,7 @@ # # ------------------------------------------------------------------------- import os -from typing import Iterable +from typing import Iterable, List, Optional from collections import defaultdict from codechecker_common.util import load_yaml @@ -16,21 +16,99 @@ class Guidelines: - def __init__(self, guidelines_dir: str): + """ + Represents the guideline and rule descriptors. + + A guideline (e.g. "sei-cert-c") is a named grouping of rule ids. Guideline + descriptors live in the guidelines directory and only reference rule ids. + The detailed information of a rule (title, url) is stored separately in the + rules directory (one file per rule type, e.g. "cwe-rules.yaml") which is + the single source of truth for rule details. + + This class joins the two sources so that: + - guideline membership comes from the guideline descriptors, + - rule details (title, url) come from the rules descriptors, + and provides a reverse lookup from a rule id to the guidelines that + contain it. + """ + + def __init__( + self, + guidelines_dir: str, + rules_dir: Optional[str] = None + ): if not os.path.isdir(guidelines_dir): raise NotADirectoryError( f'{guidelines_dir} is not a directory.') - guideline_yaml_files = map( - lambda f: os.path.join(guidelines_dir, f), - filter(lambda f: not f.endswith('.license'), - os.listdir(guidelines_dir))) + # By default the rules directory is a sibling of the guidelines + # directory: <...>/config/guidelines and <...>/config/rules. + if rules_dir is None: + rules_dir = os.path.join( + os.path.dirname(os.path.normpath(guidelines_dir)), 'rules') + + # Rule details are the single source of truth for title/url. + # { rule_id: { "title": ..., "rule_url": ... } } + self.__rule_details = self.__load_rule_details(rules_dir) + + # Guideline membership and metadata. + # { guideline: { rule_id: { "title": ..., "rule_url": ... } } } + # { guideline: { "title": ..., "url": ... } } + self.__all_rules, self.__guideline_meta = \ + self.__union_guideline_files(guidelines_dir) + + # Reverse index: { rule_id: [ guideline, ... ] } + self.__rule_to_guidelines: defaultdict[str, List[str]] = \ + defaultdict(list) + for guideline_name, rules in self.__all_rules.items(): + for rule_id in rules: + self.__rule_to_guidelines[rule_id].append(guideline_name) + + def __load_rule_details( + self, + rules_dir: str + ) -> dict[str, dict[str, str]]: + """ + Load every rule descriptor file from the rules directory. Each file is + a flat list of dictionaries with at least a 'rule_id' key and optional + 'title' and 'rule_url' keys. Returns a mapping from rule id to its + details. + """ + rule_details: dict[str, dict[str, str]] = {} + + if not os.path.isdir(rules_dir): + LOG.warning("Rules directory '%s' does not exist. Rule details " + "(title, url) will be empty.", rules_dir) + return rule_details + + rule_files = filter( + lambda f: f.endswith('.yaml') or f.endswith('.yml'), + os.listdir(rules_dir)) + + for rule_file in rule_files: + rule_path = os.path.join(rules_dir, rule_file) + rules_data = load_yaml(rule_path) - self.__all_rules = self.__union_guideline_files(guideline_yaml_files) + if not isinstance(rules_data, list): + LOG.warning("%s does not contain a list of rules.", rule_path) + continue + + for rule in rules_data: + if not isinstance(rule, dict) or 'rule_id' not in rule: + LOG.warning("A rule in %s has no 'rule_id'.", rule_path) + continue + + rule_id = rule['rule_id'] + rule_details[rule_id] = { + 'title': rule.get('title', ''), + 'rule_url': rule.get('rule_url', '') + } + + return rule_details def __check_guideline_format(self, guideline_data: dict): """ - Check the format of a guideline, It must contain specific values with + Check the format of a guideline. It must contain specific values with specific types. In case of any format error a ValueError exception is thrown with the description of the wrong format. """ @@ -49,7 +127,7 @@ def __check_guideline_format(self, guideline_data: dict): if not isinstance(rules, list) \ or not all(map(lambda r: isinstance(r, dict), rules)): raise ValueError( - "The 'rules' field must exist and be a list of dictionaris.") + "The 'rules' field must exist and be a list of dictionaries.") if any(map(lambda rule: "rule_id" not in rule or not isinstance(rule["rule_id"], str), rules)): @@ -58,29 +136,37 @@ def __check_guideline_format(self, guideline_data: dict): def __union_guideline_files( self, - guideline_files: Iterable[str] - ) -> defaultdict[str, dict[str, dict[str, str]]]: + guidelines_dir: str + ) -> tuple[defaultdict[str, dict[str, dict[str, str]]], + dict[str, dict[str, str]]]: """ - This function creates a union object of the given guideline files. The - resulting object maps guidelines to the collection of their rules. - E.g.: - { - "guideline1": { - "rule_id1": { - "rule_url": ... - "title": ... + Create a union object of the guideline descriptor files. Each guideline + descriptor references rule ids only; the rule details (title, url) are + joined in from the rules descriptors loaded separately. + + Returns a tuple of: + all_rules -- maps guidelines to the collection of their rules: + { + "guideline1": { + "rule_id1": { "title": ..., "rule_url": ... }, + "rule_id2": { ... } }, - "rule_id2": { - ... - } - ], - "guideline2": { + "guideline2": { ... } + } + guideline_meta -- maps guidelines to their metadata: + { + "guideline1": { "title": ..., "url": ... }, ... - }, - } + } """ + guideline_files = map( + lambda f: os.path.join(guidelines_dir, f), + filter(lambda f: f.endswith('.yaml') or f.endswith('.yml'), + os.listdir(guidelines_dir))) + all_rules: defaultdict[ str, dict[str, dict[str, str]]] = defaultdict(dict) + guideline_meta: dict[str, dict[str, str]] = {} for guideline_file in guideline_files: guideline_data = load_yaml(guideline_file) @@ -90,26 +176,83 @@ def __union_guideline_files( guideline_name = guideline_data["guideline"] rules = guideline_data["rules"] - all_rules[guideline_name] = {rule.pop("rule_id"): rule - for rule in rules} + + all_rules[guideline_name] = { + rule["rule_id"]: self.__details_of(rule) + for rule in rules + } + + guideline_meta[guideline_name] = { + "title": guideline_data.get("guideline_title", ""), + "url": guideline_data.get("guideline_url", "") + } except ValueError as ex: LOG.warning("%s does not have a correct guideline format.", guideline_file) LOG.warning(ex) - return all_rules + return all_rules, guideline_meta + + def __details_of(self, rule: dict) -> dict[str, str]: + """ + Return the details (title, url) of a rule. The single source of truth + is the rules descriptor. If the guideline descriptor itself carries + inline 'title'/'rule_url' (legacy format) those are used as a fallback + when the rule is not present among the loaded rule details. + """ + rule_id = rule["rule_id"] + + if rule_id in self.__rule_details: + return dict(self.__rule_details[rule_id]) + + return { + "title": rule.get("title", ""), + "rule_url": rule.get("rule_url", "") + } def rules_of_guideline( self, guideline_name: str, ) -> dict[str, dict[str, str]]: """ - Return the list of rules of a guideline. + Return the rules of a guideline as a mapping from rule id to its + details (title, url). """ + return self.__all_rules[guideline_name] - guideline_rules = self.__all_rules[guideline_name] + def guidelines_of_rule(self, rule_id: str) -> List[str]: + """ + Return the list of guidelines that contain the given rule id. + """ + return list(self.__rule_to_guidelines.get(rule_id, [])) + + def rule_details(self, rule_id: str) -> dict[str, str]: + """ + Return the details (title, url) of a single rule id. If the rule id is + unknown an empty details dictionary is returned. + """ + return dict(self.__rule_details.get( + rule_id, {"title": "", "rule_url": ""})) + + def guideline_titles(self) -> dict[str, str]: + """ + Return a mapping from guideline name to its title. + """ + return {name: meta.get("title", "") + for name, meta in self.__guideline_meta.items()} + + def guideline_urls(self) -> dict[str, str]: + """ + Return a mapping from guideline name to its url. + """ + return {name: meta.get("url", "") + for name, meta in self.__guideline_meta.items()} - return guideline_rules + def all_guidelines(self) -> Iterable[str]: + """ + Return the names of all existing guidelines. + """ + return list(self.__all_rules.keys()) def all_guideline_rules( self diff --git a/config/guidelines/cwe-top-25-2024.yaml b/config/guidelines/cwe-top-25-2024.yaml index 4af7154796..c985864689 100644 --- a/config/guidelines/cwe-top-25-2024.yaml +++ b/config/guidelines/cwe-top-25-2024.yaml @@ -1,78 +1,29 @@ guideline: cwe-top-25-2024 guideline_title: CWE Top 25 Most Dangerous Software Weaknesses 2024 +guideline_url: https://cwe.mitre.org/top25/archive/2024/2024_top25_list rules: - rule_id: cwe-20 - title: Improper Input Validation - rule_url: https://cwe.mitre.org/data/definitions/20.html - rule_id: cwe-22 - title: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') - rule_url: https://cwe.mitre.org/data/definitions/22.html - rule_id: cwe-77 - title: Improper Neutralization of Special Elements used in a Command ('Command Injection') - rule_url: https://cwe.mitre.org/data/definitions/77.html - rule_id: cwe-78 - title: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') - rule_url: https://cwe.mitre.org/data/definitions/78.html - rule_id: cwe-79 - title: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') - rule_url: https://cwe.mitre.org/data/definitions/79.html - rule_id: cwe-89 - title: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') - rule_url: https://cwe.mitre.org/data/definitions/89.html - rule_id: cwe-94 - title: Improper Control of Generation of Code ('Code Injection') - rule_url: https://cwe.mitre.org/data/definitions/94.html - rule_id: cwe-119 - title: Improper Restriction of Operations within the Bounds of a Memory Buffer - rule_url: https://cwe.mitre.org/data/definitions/119.html - rule_id: cwe-125 - title: Out-of-bounds Read - rule_url: https://cwe.mitre.org/data/definitions/125.html - rule_id: cwe-190 - title: Integer Overflow or Wraparound - rule_url: https://cwe.mitre.org/data/definitions/190.html - rule_id: cwe-200 - title: Exposure of Sensitive Information to an Unauthorized Actor - rule_url: https://cwe.mitre.org/data/definitions/200.html - rule_id: cwe-269 - title: Improper Privilege Management - rule_url: https://cwe.mitre.org/data/definitions/269.html - rule_id: cwe-287 - title: Improper Authentication - rule_url: https://cwe.mitre.org/data/definitions/287.html - rule_id: cwe-306 - title: Missing Authentication for Critical Function - rule_url: https://cwe.mitre.org/data/definitions/306.html - rule_id: cwe-352 - title: Cross-Site Request Forgery (CSRF) - rule_url: https://cwe.mitre.org/data/definitions/352.html - rule_id: cwe-400 - title: Uncontrolled Resource Consumption - rule_url: https://cwe.mitre.org/data/definitions/400.html - rule_id: cwe-416 - title: Use After Free - rule_url: https://cwe.mitre.org/data/definitions/416.html - rule_id: cwe-434 - title: Unrestricted Upload of File with Dangerous Type - rule_url: https://cwe.mitre.org/data/definitions/434.html - rule_id: cwe-476 - title: NULL Pointer Dereference - rule_url: https://cwe.mitre.org/data/definitions/476.html - rule_id: cwe-502 - title: Deserialization of Untrusted Data - rule_url: https://cwe.mitre.org/data/definitions/502.html - rule_id: cwe-787 - title: Out-of-bounds Write - rule_url: https://cwe.mitre.org/data/definitions/787.html - rule_id: cwe-798 - title: Use of Hard-coded Credentials - rule_url: https://cwe.mitre.org/data/definitions/798.html - rule_id: cwe-862 - title: Missing Authorization - rule_url: https://cwe.mitre.org/data/definitions/862.html - rule_id: cwe-863 - title: Incorrect Authorization - rule_url: https://cwe.mitre.org/data/definitions/863.html - rule_id: cwe-918 - title: Server-Side Request Forgery (SSRF) - rule_url: https://cwe.mitre.org/data/definitions/918.html diff --git a/config/guidelines/cwe-top-25-2025.yaml b/config/guidelines/cwe-top-25-2025.yaml index faee822932..c021863aa1 100644 --- a/config/guidelines/cwe-top-25-2025.yaml +++ b/config/guidelines/cwe-top-25-2025.yaml @@ -1,78 +1,29 @@ guideline: cwe-top-25-2025 guideline_title: CWE Top 25 Most Dangerous Software Weaknesses 2025 +guideline_url: https://cwe.mitre.org/top25/archive/2025/2025_cwe_top25.html rules: - rule_id: cwe-79 - title: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') - rule_url: https://cwe.mitre.org/data/definitions/79.html - rule_id: cwe-89 - title: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') - rule_url: https://cwe.mitre.org/data/definitions/89.html - rule_id: cwe-352 - title: Cross-Site Request Forgery (CSRF) - rule_url: https://cwe.mitre.org/data/definitions/352.html - rule_id: cwe-862 - title: Missing Authorization - rule_url: https://cwe.mitre.org/data/definitions/862.html - rule_id: cwe-787 - title: Out-of-bounds Write - rule_url: https://cwe.mitre.org/data/definitions/787.html - rule_id: cwe-22 - title: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') - rule_url: https://cwe.mitre.org/data/definitions/22.html - rule_id: cwe-416 - title: Use After Free - rule_url: https://cwe.mitre.org/data/definitions/416.html - rule_id: cwe-125 - title: Out-of-bounds Read - rule_url: https://cwe.mitre.org/data/definitions/125.html - rule_id: cwe-78 - title: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') - rule_url: https://cwe.mitre.org/data/definitions/78.html - rule_id: cwe-94 - title: Improper Control of Generation of Code ('Code Injection') - rule_url: https://cwe.mitre.org/data/definitions/94.html - rule_id: cwe-120 - title: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') - rule_url: https://cwe.mitre.org/data/definitions/120.html - rule_id: cwe-434 - title: Unrestricted Upload of File with Dangerous Type - rule_url: https://cwe.mitre.org/data/definitions/434.html - rule_id: cwe-476 - title: NULL Pointer Dereference - rule_url: https://cwe.mitre.org/data/definitions/476.html - rule_id: cwe-121 - title: Stack-based Buffer Overflow - rule_url: https://cwe.mitre.org/data/definitions/121.html - rule_id: cwe-502 - title: Deserialization of Untrusted Data - rule_url: https://cwe.mitre.org/data/definitions/502.html - rule_id: cwe-122 - title: Heap-based Buffer Overflow - rule_url: https://cwe.mitre.org/data/definitions/122.html - rule_id: cwe-863 - title: Incorrect Authorization - rule_url: https://cwe.mitre.org/data/definitions/863.html - rule_id: cwe-20 - title: Improper Input Validation - rule_url: https://cwe.mitre.org/data/definitions/20.html - rule_id: cwe-284 - title: Improper Access Control - rule_url: https://cwe.mitre.org/data/definitions/284.html - rule_id: cwe-200 - title: Exposure of Sensitive Information to an Unauthorized Actor - rule_url: https://cwe.mitre.org/data/definitions/200.html - rule_id: cwe-306 - title: Missing Authentication for Critical Function - rule_url: https://cwe.mitre.org/data/definitions/306.html - rule_id: cwe-918 - title: Server-Side Request Forgery (SSRF) - rule_url: https://cwe.mitre.org/data/definitions/918.html - rule_id: cwe-77 - title: Improper Neutralization of Special Elements used in a Command ('Command Injection') - rule_url: https://cwe.mitre.org/data/definitions/77.html - rule_id: cwe-639 - title: Authorization Bypass Through User-Controlled Key - rule_url: https://cwe.mitre.org/data/definitions/639.html - rule_id: cwe-770 - title: Allocation of Resources Without Limits or Throttling - rule_url: https://cwe.mitre.org/data/definitions/770.html diff --git a/config/guidelines/cwe-vulnerabilities.yaml b/config/guidelines/cwe-vulnerabilities.yaml index e89742a3d8..992c90231d 100644 --- a/config/guidelines/cwe-vulnerabilities.yaml +++ b/config/guidelines/cwe-vulnerabilities.yaml @@ -1,135 +1,48 @@ guideline: cwe-vulnerabilities guideline_title: CWE Vulnerabilities +guideline_url: https://cwe.mitre.org/ rules: - rule_id: cwe-20 - title: Improper Input Validation - rule_url: https://cwe.mitre.org/data/definitions/20.html - rule_id: cwe-22 - title: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') - rule_url: https://cwe.mitre.org/data/definitions/22.html - rule_id: cwe-77 - title: Improper Neutralization of Special Elements used in a Command ('Command Injection') - rule_url: https://cwe.mitre.org/data/definitions/77.html - rule_id: cwe-78 - title: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') - rule_url: https://cwe.mitre.org/data/definitions/78.html - rule_id: cwe-79 - title: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') - rule_url: https://cwe.mitre.org/data/definitions/79.html - rule_id: cwe-89 - title: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') - rule_url: https://cwe.mitre.org/data/definitions/89.html - rule_id: cwe-94 - title: Improper Control of Generation of Code ('Code Injection') - rule_url: https://cwe.mitre.org/data/definitions/94.html - rule_id: cwe-119 - title: Improper Restriction of Operations within the Bounds of a Memory Buffer - rule_url: https://cwe.mitre.org/data/definitions/119.html - rule_id: cwe-121 - title: Stack-Based Buffer Overflow - rule_url: https://cwe.mitre.org/data/definitions/121.html - rule_id: cwe-122 - title: Heap-based Buffer Overflow - rule_url: https://cwe.mitre.org/data/definitions/122.html - rule_id: cwe-123 - title: Write-what-where Condition - rule_url: https://cwe.mitre.org/data/definitions/123.html - rule_id: cwe-124 - title: Buffer Underwrite ('Buffer Underflow') - rule_url: https://cwe.mitre.org/data/definitions/124.html - rule_id: cwe-125 - title: Out-of-bounds Read - rule_url: https://cwe.mitre.org/data/definitions/125.html - rule_id: cwe-126 - title: Buffer Over-read - rule_url: https://cwe.mitre.org/data/definitions/126.html - rule_id: cwe-127 - title: Buffer Under-read - rule_url: https://cwe.mitre.org/data/definitions/127.html - rule_id: cwe-129 - title: Improper Validation of Array Index - rule_url: https://cwe.mitre.org/data/definitions/129.html - rule_id: cwe-170 - title: Improper Null Termination - rule_url: https://cwe.mitre.org/data/definitions/170.html - rule_id: cwe-190 - title: Integer Overflow or Wraparound - rule_url: https://cwe.mitre.org/data/definitions/190.html - rule_id: cwe-252 - title: Unchecked Return Value - rule_url: https://cwe.mitre.org/data/definitions/252.html - rule_id: cwe-269 - title: Improper Privilege Management - rule_url: https://cwe.mitre.org/data/definitions/269.html - rule_id: cwe-335 - title: Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) - rule_url: https://cwe.mitre.org/data/definitions/335.html - rule_id: cwe-338 - title: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) - rule_url: https://cwe.mitre.org/data/definitions/338.html - rule_id: cwe-362 - title: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') - rule_url: https://cwe.mitre.org/data/definitions/362.html - rule_id: cwe-369 - title: Divide By Zero - rule_url: https://cwe.mitre.org/data/definitions/369.html - rule_id: cwe-377 - title: Insecure Temporary File - rule_url: https://cwe.mitre.org/data/definitions/377.html - rule_id: cwe-390 - title: Detection of Error Condition Without Action - rule_url: https://cwe.mitre.org/data/definitions/390.html - rule_id: cwe-400 - title: Uncontrolled Resource Consumption - rule_url: https://cwe.mitre.org/data/definitions/400.html - rule_id: cwe-401 - title: Missing Release of Memory after Effective Lifetime - rule_url: https://cwe.mitre.org/data/definitions/401.html - rule_id: cwe-415 - title: Double Free - rule_url: https://cwe.mitre.org/data/definitions/415.html - rule_id: cwe-416 - title: Use After Free - rule_url: https://cwe.mitre.org/data/definitions/416.html - rule_id: cwe-457 - title: Use of Uninitialized Variable - rule_url: https://cwe.mitre.org/data/definitions/457.html - rule_id: cwe-476 - title: "NULL Pointer Dereference" - rule_url: https://cwe.mitre.org/data/definitions/476.html - rule_id: cwe-478 - title: Missing Default Case in Multiple Condition Expression - rule_url: https://cwe.mitre.org/data/definitions/478.html - rule_id: cwe-562 - title: Return of Stack Variable Address - rule_url: https://cwe.mitre.org/data/definitions/562.html - rule_id: cwe-590 - title: Free of Memory not on the Heap - rule_url: https://cwe.mitre.org/data/definitions/590.html - rule_id: cwe-664 - title: Improper Control of a Resource Through its Lifetime - rule_url: https://cwe.mitre.org/data/definitions/664.html - rule_id: cwe-668 - title: Exposure of Resource to Wrong Sphere - rule_url: https://cwe.mitre.org/data/definitions/668.html - rule_id: cwe-676 - title: Use of Potentially Dangerous Function - rule_url: https://cwe.mitre.org/data/definitions/676.html - rule_id: cwe-732 - title: Incorrect Permission Assignment for Critical Resource - rule_url: https://cwe.mitre.org/data/definitions/732.html - rule_id: cwe-761 - title: Free of Pointer not at Start of Buffer - rule_url: https://cwe.mitre.org/data/definitions/761.html - rule_id: cwe-762 - title: Mismatched Memory Management Routines - rule_url: https://cwe.mitre.org/data/definitions/762.html - rule_id: cwe-787 - title: Out-of-bounds Write - rule_url: https://cwe.mitre.org/data/definitions/787.html - rule_id: cwe-789 - title: Memory Allocation with Excessive Size Value - rule_url: https://cwe.mitre.org/data/definitions/789.html - rule_id: cwe-843 - title: Access of Resource Using Incompatible Type ('Type Confusion') - rule_url: https://cwe.mitre.org/data/definitions/843.html diff --git a/config/guidelines/memory-safety.yaml b/config/guidelines/memory-safety.yaml index 26459d70f8..d21d81f2b8 100644 --- a/config/guidelines/memory-safety.yaml +++ b/config/guidelines/memory-safety.yaml @@ -1,60 +1,23 @@ guideline: memory-safety guideline_title: Memory-safety related CWEs +guideline_url: https://cwe.mitre.org/data/definitions/1399.html rules: - rule_id: cwe-121 - title: Stack-Based Buffer Overflow - rule_url: https://cwe.mitre.org/data/definitions/121.html - rule_id: cwe-122 - title: Heap-based Buffer Overflow - rule_url: https://cwe.mitre.org/data/definitions/122.html - rule_id: cwe-123 - title: Write-what-where Condition - rule_url: https://cwe.mitre.org/data/definitions/123.html - rule_id: cwe-124 - title: Buffer Underwrite ('Buffer Underflow') - rule_url: https://cwe.mitre.org/data/definitions/124.html - rule_id: cwe-126 - title: Buffer Over-read - rule_url: https://cwe.mitre.org/data/definitions/126.html - rule_id: cwe-127 - title: Buffer Under-read - rule_url: https://cwe.mitre.org/data/definitions/127.html - rule_id: cwe-244 - title: Improper Clearing of Heap Memory Before Release ('Heap Inspection') - rule_url: https://cwe.mitre.org/data/definitions/244.html - rule_id: cwe-401 - title: Missing Release of Memory after Effective Lifetime ('Memory Leak') - rule_url: https://cwe.mitre.org/data/definitions/401.html - rule_id: cwe-415 - title: Double Free - rule_url: https://cwe.mitre.org/data/definitions/415.html - rule_id: cwe-416 - title: Use After Free - rule_url: https://cwe.mitre.org/data/definitions/416.html - rule_id: cwe-457 - title: Use of Uninitialized Variable - rule_url: https://cwe.mitre.org/data/definitions/457.html - rule_id: cwe-476 - title: Nullptr Dereference - rule_url: https://cwe.mitre.org/data/definitions/476.html - rule_id: cwe-562 - title: Return of Stack Variable Address - rule_url: https://cwe.mitre.org/data/definitions/562.html - rule_id: cwe-590 - title: Free of Memory not on the Heap - rule_url: https://cwe.mitre.org/data/definitions/590.html - rule_id: cwe-761 - title: Free of Pointer not at Start of Buffer - rule_url: https://cwe.mitre.org/data/definitions/761.html - rule_id: cwe-762 - title: Mismatched Memory Management Routines - rule_url: https://cwe.mitre.org/data/definitions/762.html - rule_id: cwe-785 - title: Use of Path Manipulation Function without Maximum Sized Buffer - rule_url: https://cwe.mitre.org/data/definitions/785.html - rule_id: cwe-789 - title: Uncontrolled Memory Allocation - rule_url: https://cwe.mitre.org/data/definitions/789.html - rule_id: cwe-843 - title: Access of Resource Using Incompatible Type ('Type Confusion') - rule_url: https://cwe.mitre.org/data/definitions/843.html \ No newline at end of file diff --git a/config/guidelines/misra-c.yaml b/config/guidelines/misra-c.yaml new file mode 100644 index 0000000000..bd1a76d605 --- /dev/null +++ b/config/guidelines/misra-c.yaml @@ -0,0 +1,5 @@ +guideline: misra-c +guideline_title: MISRA C +guideline_url: https://www.misra.org.uk/ +rules: +- rule_id: '14.9' diff --git a/config/guidelines/owasp-top-10-2021.yaml b/config/guidelines/owasp-top-10-2021.yaml index a5f39751b8..353eaee249 100644 --- a/config/guidelines/owasp-top-10-2021.yaml +++ b/config/guidelines/owasp-top-10-2021.yaml @@ -1,33 +1,14 @@ guideline: owasp-top-10-2021 guideline_title: OWASP Top 10 Web Application Security Risks 2021 +guideline_url: https://owasp.org/Top10/2021/ rules: - rule_id: owasp-A01-2021 - title: Broken Access Control - rule_url: https://owasp.org/Top10/A01_2021-Broken_Access_Control/ - rule_id: owasp-A02-2021 - title: Cryptographic Failures - rule_url: https://owasp.org/Top10/A02_2021-Cryptographic_Failures/ - rule_id: owasp-A03-2021 - title: Injection - rule_url: https://owasp.org/Top10/A03_2021-Injection/ - rule_id: owasp-A04-2021 - title: Insecure Design - rule_url: https://owasp.org/Top10/A04_2021-Insecure_Design/ - rule_id: owasp-A05-2021 - title: Security Misconfiguration - rule_url: https://owasp.org/Top10/A05_2021-Security_Misconfiguration/ - rule_id: owasp-A06-2021 - title: Vulnerable and Outdated Components - rule_url: https://owasp.org/Top10/A06_2021-Vulnerable_and_Outdated_Components/ - rule_id: owasp-A07-2021 - title: Identification and Authentication Failures - rule_url: https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/ - rule_id: owasp-A08-2021 - title: Software and Data Integrity Failures - rule_url: https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures/ - rule_id: owasp-A09-2021 - title: Security Logging and Monitoring Failures - rule_url: https://owasp.org/Top10/A09_2021-Security_Logging_and_Monitoring_Failures/ - rule_id: owasp-A10-2021 - title: Server-Side Request Forgery (SSRF) - rule_url: https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ diff --git a/config/guidelines/owasp-top-10-2025.yaml b/config/guidelines/owasp-top-10-2025.yaml index af49b09f8e..0c37fd4b76 100644 --- a/config/guidelines/owasp-top-10-2025.yaml +++ b/config/guidelines/owasp-top-10-2025.yaml @@ -1,33 +1,14 @@ guideline: owasp-top-10-2025 guideline_title: OWASP Top 10 Web Application Security Risks 2025 +guideline_url: https://owasp.org/Top10/2025/ rules: - rule_id: owasp-A01-2025 - title: Broken Access Control - rule_url: https://owasp.org/Top10/2025/A01_2025-Broken_Access_Control/ - rule_id: owasp-A02-2025 - title: Security Misconfiguration - rule_url: https://owasp.org/Top10/2025/A02_2025-Security_Misconfiguration/ - rule_id: owasp-A03-2025 - title: Software Supply Chain Failures - rule_url: https://owasp.org/Top10/2025/A03_2025-Software_Supply_Chain_Failures/ - rule_id: owasp-A04-2025 - title: Cryptographic Failures - rule_url: https://owasp.org/Top10/2025/A04_2025-Cryptographic_Failures/ - rule_id: owasp-A05-2025 - title: Injection - rule_url: https://owasp.org/Top10/2025/A05_2025-Injection/ - rule_id: owasp-A06-2025 - title: Insecure Design - rule_url: https://owasp.org/Top10/2025/A06_2025-Insecure_Design/ - rule_id: owasp-A07-2025 - title: Authentication Failures - rule_url: https://owasp.org/Top10/2025/A07_2025-Authentication_Failures/ - rule_id: owasp-A08-2025 - title: Software or Data Integrity Failures - rule_url: https://owasp.org/Top10/2025/A08_2025-Software_or_Data_Integrity_Failures/ - rule_id: owasp-A09-2025 - title: Security Logging and Alerting Failures - rule_url: https://owasp.org/Top10/2025/A09_2025-Security_Logging_and_Alerting_Failures/ - rule_id: owasp-A10-2025 - title: Mishandling of Exceptional Conditions - rule_url: https://owasp.org/Top10/2025/A10_2025-Mishandling_of_Exceptional_Conditions/ diff --git a/config/guidelines/sei-cert-c.yaml b/config/guidelines/sei-cert-c.yaml index 8eee6c2bc4..4f346cd5d6 100644 --- a/config/guidelines/sei-cert-c.yaml +++ b/config/guidelines/sei-cert-c.yaml @@ -1,243 +1,131 @@ guideline: sei-cert-c guideline_title: SEI CERT Coding Standard (C) +guideline_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/ rules: - rule_id: arr30-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/arrays-arr/arr30-c/ - rule_id: arr32-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/arrays-arr/arr32-c/ - rule_id: arr36-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/arrays-arr/arr36-c/ - rule_id: arr37-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/arrays-arr/arr37-c/ - rule_id: arr38-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/arrays-arr/arr38-c/ - rule_id: arr39-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/arrays-arr/arr39-c/ - rule_id: con30-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con30-c/ - rule_id: con31-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con31-c/ - rule_id: con32-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con32-c/ - rule_id: con33-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con33-c/ - rule_id: con34-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con34-c/ - rule_id: con35-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con35-c/ - rule_id: con36-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con36-c/ - rule_id: con37-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con37-c/ - rule_id: con38-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con38-c/ - rule_id: con39-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con39-c/ - rule_id: con40-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con40-c/ - rule_id: con41-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con41-c/ - rule_id: con43-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con43-c/ - rule_id: dcl30-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/declarations-and-initialization-dcl/dcl30-c/ - rule_id: dcl31-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/declarations-and-initialization-dcl/dcl31-c/ - rule_id: dcl36-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/declarations-and-initialization-dcl/dcl36-c/ - rule_id: dcl37-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/declarations-and-initialization-dcl/dcl37-c/ - rule_id: dcl38-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/declarations-and-initialization-dcl/dcl38-c/ - rule_id: dcl39-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/declarations-and-initialization-dcl/dcl39-c/ - rule_id: dcl40-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/declarations-and-initialization-dcl/dcl40-c/ - rule_id: dcl41-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/declarations-and-initialization-dcl/dcl41-c/ - rule_id: env30-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/environment-env/env30-c/ - rule_id: env31-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/environment-env/env31-c/ - rule_id: env32-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/environment-env/env32-c/ - rule_id: env33-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/environment-env/env33-c/ - rule_id: env34-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/environment-env/env34-c/ - rule_id: err30-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/error-handling-err/err30-c/ - rule_id: err32-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/error-handling-err/err32-c/ - rule_id: err33-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/error-handling-err/err33-c/ - rule_id: err34-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/error-handling-err/err34-c/ - rule_id: exp30-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp30-c/ - rule_id: exp32-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp32-c/ - rule_id: exp33-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp33-c/ - rule_id: exp34-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp34-c/ - rule_id: exp35-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp35-c/ - rule_id: exp36-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp36-c/ - rule_id: exp37-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp37-c/ - rule_id: exp39-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp39-c/ - rule_id: exp40-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp40-c/ - rule_id: exp42-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp42-c/ - rule_id: exp43-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp43-c/ - rule_id: exp44-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp44-c/ - rule_id: exp45-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp45-c/ - rule_id: exp46-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp46-c/ - rule_id: exp47-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp47-c/ - rule_id: fio30-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio30-c/ - rule_id: fio32-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio32-c/ - rule_id: fio34-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio34-c/ - rule_id: fio37-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio37-c/ - rule_id: fio38-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio38-c/ - rule_id: fio39-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio39-c/ - rule_id: fio40-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio40-c/ - rule_id: fio41-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio41-c/ - rule_id: fio42-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio42-c/ - rule_id: fio44-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio44-c/ - rule_id: fio45-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio45-c/ - rule_id: fio46-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio46-c/ - rule_id: fio47-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio47-c/ - rule_id: flp30-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/floating-point-flp/flp30-c/ - rule_id: flp32-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/floating-point-flp/flp32-c/ - rule_id: flp34-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/floating-point-flp/flp34-c/ - rule_id: flp36-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/floating-point-flp/flp36-c/ - rule_id: flp37-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/floating-point-flp/flp37-c/ - rule_id: int30-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/integers-int/int30-c/ - rule_id: int31-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/integers-int/int31-c/ - rule_id: int32-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/integers-int/int32-c/ - rule_id: int33-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/integers-int/int33-c/ - rule_id: int34-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/integers-int/int34-c/ - rule_id: int35-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/integers-int/int35-c/ - rule_id: int36-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/integers-int/int36-c/ - rule_id: mem30-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/memory-management-mem/mem30-c/ - rule_id: mem31-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/memory-management-mem/mem31-c/ - rule_id: mem33-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/memory-management-mem/mem33-c/ - rule_id: mem34-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/memory-management-mem/mem34-c/ - rule_id: mem35-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/memory-management-mem/mem35-c/ - rule_id: mem36-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/memory-management-mem/mem36-c/ - rule_id: msc30-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/miscellaneous-msc/msc30-c/ - rule_id: msc32-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/miscellaneous-msc/msc32-c/ - rule_id: msc33-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/miscellaneous-msc/msc33-c/ - rule_id: msc37-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/miscellaneous-msc/msc37-c/ - rule_id: msc38-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/miscellaneous-msc/msc38-c/ - rule_id: msc39-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/miscellaneous-msc/msc39-c/ - rule_id: msc40-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/miscellaneous-msc/msc40-c/ - rule_id: msc41-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/miscellaneous-msc/msc41-c/ - rule_id: pos30-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos30-c/ - rule_id: pos34-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos34-c/ - rule_id: pos35-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos35-c/ - rule_id: pos36-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos36-c/ - rule_id: pos37-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos37-c/ - rule_id: pos38-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos38-c/ - rule_id: pos39-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos39-c/ - rule_id: pos44-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos44-c/ - rule_id: pos47-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos47-c/ - rule_id: pos48-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos48-c/ - rule_id: pos49-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos49-c/ - rule_id: pos50-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos50-c/ - rule_id: pos51-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos51-c/ - rule_id: pos52-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos52-c/ - rule_id: pos53-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos53-c/ - rule_id: pos54-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos54-c/ - rule_id: pre30-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/preprocessor-pre/pre30-c/ - rule_id: pre31-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/preprocessor-pre/pre31-c/ - rule_id: pre32-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/preprocessor-pre/pre32-c/ - rule_id: sig30-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/signals-sig/sig30-c/ - rule_id: sig31-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/signals-sig/sig31-c/ - rule_id: sig34-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/signals-sig/sig34-c/ - rule_id: sig35-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/signals-sig/sig35-c/ - rule_id: str30-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/characters-and-strings-str/str30-c/ - rule_id: str31-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/characters-and-strings-str/str31-c/ - rule_id: str32-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/characters-and-strings-str/str32-c/ - rule_id: str34-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/characters-and-strings-str/str34-c/ - rule_id: str37-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/characters-and-strings-str/str37-c/ - rule_id: str38-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/characters-and-strings-str/str38-c/ - rule_id: win30-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/microsoft-windows-win/win30-c/ +- rule_id: dcl03-c +- rule_id: dcl16-c +- rule_id: int09-c +- rule_id: int10-c +- rule_id: msc12-c +- rule_id: msc24-c +- rule_id: pre02-c diff --git a/config/guidelines/sei-cert-cpp.yaml b/config/guidelines/sei-cert-cpp.yaml index 7a801e2458..5fcd5bd01d 100644 --- a/config/guidelines/sei-cert-cpp.yaml +++ b/config/guidelines/sei-cert-cpp.yaml @@ -1,329 +1,167 @@ guideline: sei-cert-cpp guideline_title: SEI CERT Coding Standard (C++) +guideline_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/ rules: - rule_id: arr30-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/arrays-arr/arr30-c/ - rule_id: arr37-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/arrays-arr/arr37-c/ - rule_id: arr38-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/arrays-arr/arr38-c/ - rule_id: arr39-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/arrays-arr/arr39-c/ - rule_id: con33-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con33-c/ - rule_id: con37-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con37-c/ - rule_id: con40-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con40-c/ - rule_id: con41-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con41-c/ - rule_id: con43-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con43-c/ - rule_id: con50-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/concurrency-con/con50-cpp/ - rule_id: con51-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/concurrency-con/con51-cpp/ - rule_id: con52-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/concurrency-con/con52-cpp/ - rule_id: con53-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/concurrency-con/con53-cpp/ - rule_id: con54-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/concurrency-con/con54-cpp/ - rule_id: con55-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/concurrency-con/con55-cpp/ - rule_id: con56-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/concurrency-con/con56-cpp/ - rule_id: ctr50-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/containers-ctr/ctr50-cpp/ - rule_id: ctr51-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/containers-ctr/ctr51-cpp/ - rule_id: ctr52-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/containers-ctr/ctr52-cpp/ - rule_id: ctr53-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/containers-ctr/ctr53-cpp/ - rule_id: ctr54-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/containers-ctr/ctr54-cpp/ - rule_id: ctr55-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/containers-ctr/ctr55-cpp/ - rule_id: ctr56-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/containers-ctr/ctr56-cpp/ - rule_id: ctr57-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/containers-ctr/ctr57-cpp/ - rule_id: ctr58-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/containers-ctr/ctr58-cpp/ - rule_id: dcl30-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/declarations-and-initialization-dcl/dcl30-c/ - rule_id: dcl39-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/declarations-and-initialization-dcl/dcl39-c/ - rule_id: dcl40-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/declarations-and-initialization-dcl/dcl40-c/ - rule_id: dcl50-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/declarations-and-initialization-dcl/dcl50-cpp/ - rule_id: dcl51-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/declarations-and-initialization-dcl/dcl51-cpp/ - rule_id: dcl52-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/declarations-and-initialization-dcl/dcl52-cpp/ - rule_id: dcl53-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/declarations-and-initialization-dcl/dcl53-cpp/ - rule_id: dcl54-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/declarations-and-initialization-dcl/dcl54-cpp/ - rule_id: dcl55-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/declarations-and-initialization-dcl/dcl55-cpp/ - rule_id: dcl56-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/declarations-and-initialization-dcl/dcl56-cpp/ - rule_id: dcl57-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/declarations-and-initialization-dcl/dcl57-cpp/ - rule_id: dcl58-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/declarations-and-initialization-dcl/dcl58-cpp/ - rule_id: dcl59-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/declarations-and-initialization-dcl/dcl59-cpp/ - rule_id: dcl60-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/declarations-and-initialization-dcl/dcl60-cpp/ - rule_id: env30-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/environment-env/env30-c/ - rule_id: env31-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/environment-env/env31-c/ - rule_id: env32-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/environment-env/env32-c/ - rule_id: env33-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/environment-env/env33-c/ - rule_id: env34-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/environment-env/env34-c/ - rule_id: err30-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/error-handling-err/err30-c/ - rule_id: err32-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/error-handling-err/err32-c/ - rule_id: err33-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/error-handling-err/err33-c/ - rule_id: err34-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/error-handling-err/err34-c/ - rule_id: err50-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/exceptions-and-error-handling-err/err50-cpp/ - rule_id: err51-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/exceptions-and-error-handling-err/err51-cpp/ - rule_id: err52-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/exceptions-and-error-handling-err/err52-cpp/ - rule_id: err53-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/exceptions-and-error-handling-err/err53-cpp/ - rule_id: err54-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/exceptions-and-error-handling-err/err54-cpp/ - rule_id: err55-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/exceptions-and-error-handling-err/err55-cpp/ - rule_id: err56-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/exceptions-and-error-handling-err/err56-cpp/ - rule_id: err57-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/exceptions-and-error-handling-err/err57-cpp/ - rule_id: err58-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/exceptions-and-error-handling-err/err58-cpp/ - rule_id: err59-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/exceptions-and-error-handling-err/err59-cpp/ - rule_id: err60-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/exceptions-and-error-handling-err/err60-cpp/ - rule_id: err61-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/exceptions-and-error-handling-err/err61-cpp/ - rule_id: err62-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/exceptions-and-error-handling-err/err62-cpp/ - rule_id: exp34-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp34-c/ - rule_id: exp35-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp35-c/ - rule_id: exp36-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp36-c/ - rule_id: exp37-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp37-c/ - rule_id: exp39-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp39-c/ - rule_id: exp42-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp42-c/ - rule_id: exp45-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp45-c/ - rule_id: exp46-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp46-c/ - rule_id: exp47-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp47-c/ - rule_id: exp50-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/expressions-exp/exp50-cpp/ - rule_id: exp51-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/expressions-exp/exp51-cpp/ - rule_id: exp52-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/expressions-exp/exp52-cpp/ - rule_id: exp53-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/expressions-exp/exp53-cpp/ - rule_id: exp54-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/expressions-exp/exp54-cpp/ - rule_id: exp55-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/expressions-exp/exp55-cpp/ - rule_id: exp56-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/expressions-exp/exp56-cpp/ - rule_id: exp57-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/expressions-exp/exp57-cpp/ - rule_id: exp58-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/expressions-exp/exp58-cpp/ - rule_id: exp59-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/expressions-exp/exp59-cpp/ - rule_id: exp60-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/expressions-exp/exp60-cpp/ - rule_id: exp61-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/expressions-exp/exp61-cpp/ - rule_id: exp62-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/expressions-exp/exp62-cpp/ - rule_id: exp63-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/expressions-exp/exp63-cpp/ - rule_id: fio30-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio30-c/ - rule_id: fio32-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio32-c/ - rule_id: fio34-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio34-c/ - rule_id: fio37-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio37-c/ - rule_id: fio38-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio38-c/ - rule_id: fio39-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio39-c/ - rule_id: fio40-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio40-c/ - rule_id: fio41-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio41-c/ - rule_id: fio42-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio42-c/ - rule_id: fio44-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio44-c/ - rule_id: fio45-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio45-c/ - rule_id: fio46-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio46-c/ - rule_id: fio47-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio47-c/ - rule_id: fio50-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/input-output-fio/fio50-cpp/ - rule_id: fio51-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/input-output-fio/fio51-cpp/ - rule_id: flp30-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/floating-point-flp/flp30-c/ - rule_id: flp32-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/floating-point-flp/flp32-c/ - rule_id: flp34-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/floating-point-flp/flp34-c/ - rule_id: flp36-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/floating-point-flp/flp36-c/ - rule_id: flp37-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/floating-point-flp/flp37-c/ - rule_id: int30-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/integers-int/int30-c/ - rule_id: int31-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/integers-int/int31-c/ - rule_id: int32-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/integers-int/int32-c/ - rule_id: int33-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/integers-int/int33-c/ - rule_id: int34-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/integers-int/int34-c/ - rule_id: int35-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/integers-int/int35-c/ - rule_id: int36-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/integers-int/int36-c/ - rule_id: int50-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/integers-int/int50-cpp/ - rule_id: mem30-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/memory-management-mem/mem30-c/ - rule_id: mem31-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/memory-management-mem/mem31-c/ - rule_id: mem34-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/memory-management-mem/mem34-c/ - rule_id: mem35-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/memory-management-mem/mem35-c/ - rule_id: mem36-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/memory-management-mem/mem36-c/ - rule_id: mem50-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/memory-management-mem/mem50-cpp/ - rule_id: mem51-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/memory-management-mem/mem51-cpp/ - rule_id: mem52-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/memory-management-mem/mem52-cpp/ - rule_id: mem53-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/memory-management-mem/mem53-cpp/ - rule_id: mem54-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/memory-management-mem/mem54-cpp/ - rule_id: mem55-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/memory-management-mem/mem55-cpp/ - rule_id: mem56-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/memory-management-mem/mem56-cpp/ - rule_id: mem57-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/memory-management-mem/mem57-cpp/ - rule_id: msc30-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/miscellaneous-msc/msc30-c/ - rule_id: msc32-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/miscellaneous-msc/msc32-c/ - rule_id: msc33-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/miscellaneous-msc/msc33-c/ - rule_id: msc37-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/miscellaneous-msc/msc37-c/ - rule_id: msc38-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/miscellaneous-msc/msc38-c/ - rule_id: msc39-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/miscellaneous-msc/msc39-c/ - rule_id: msc40-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/miscellaneous-msc/msc40-c/ - rule_id: msc41-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/miscellaneous-msc/msc41-c/ - rule_id: msc50-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/miscellaneous-msc/msc50-cpp/ - rule_id: msc51-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/miscellaneous-msc/msc51-cpp/ - rule_id: msc52-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/miscellaneous-msc/msc52-cpp/ - rule_id: msc53-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/miscellaneous-msc/msc53-cpp/ - rule_id: msc54-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/miscellaneous-msc/msc54-cpp/ - rule_id: oop50-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/object-oriented-programming-oop/oop50-cpp/ - rule_id: oop51-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/object-oriented-programming-oop/oop51-cpp/ - rule_id: oop52-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/object-oriented-programming-oop/oop52-cpp/ - rule_id: oop53-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/object-oriented-programming-oop/oop53-cpp/ - rule_id: oop54-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/object-oriented-programming-oop/oop54-cpp/ - rule_id: oop55-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/object-oriented-programming-oop/oop55-cpp/ - rule_id: oop56-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/object-oriented-programming-oop/oop56-cpp/ - rule_id: oop57-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/object-oriented-programming-oop/oop57-cpp/ - rule_id: oop58-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/object-oriented-programming-oop/oop58-cpp/ - rule_id: pre30-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/preprocessor-pre/pre30-c/ - rule_id: pre31-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/preprocessor-pre/pre31-c/ - rule_id: pre32-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/preprocessor-pre/pre32-c/ - rule_id: sig31-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/signals-sig/sig31-c/ - rule_id: sig34-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/signals-sig/sig34-c/ - rule_id: sig35-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/signals-sig/sig35-c/ - rule_id: str30-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/characters-and-strings-str/str30-c/ - rule_id: str31-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/characters-and-strings-str/str31-c/ - rule_id: str32-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/characters-and-strings-str/str32-c/ - rule_id: str34-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/characters-and-strings-str/str34-c/ - rule_id: str37-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/characters-and-strings-str/str37-c/ - rule_id: str38-c - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/characters-and-strings-str/str38-c/ - rule_id: str50-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/characters-and-strings-str/str50-cpp/ - rule_id: str51-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/characters-and-strings-str/str51-cpp/ - rule_id: str52-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/characters-and-strings-str/str52-cpp/ - rule_id: str53-cpp - rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/characters-and-strings-str/str53-cpp/ diff --git a/config/labels/analyzers/clang-tidy.json b/config/labels/analyzers/clang-tidy.json index 8c4f66dcb7..6847068f20 100644 --- a/config/labels/analyzers/clang-tidy.json +++ b/config/labels/analyzers/clang-tidy.json @@ -143,12 +143,9 @@ ], "android-cloexec-open": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/android/cloexec-open.html", - "guideline:owasp-top-10-2021", - "guideline:owasp-top-10-2025", - "guideline:cwe-vulnerabilities", - "cwe-vulnerabilities:cwe-668", - "owasp-top-10-2021:owasp-A01-2021", - "owasp-top-10-2025:owasp-A01-2025", + "rule:cwe-668", + "rule:owasp-A01-2021", + "rule:owasp-A01-2025", "severity:HIGH" ], "android-cloexec-pipe": [ @@ -174,26 +171,19 @@ ], "boost-use-to-string": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/boost/use-to-string.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], "bugprone-argument-comment": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/argument-comment.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], "bugprone-assert-side-effect": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/assert-side-effect.html", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:pre31-c", - "sei-cert-cpp:pre31-c", + "rule:pre31-c", "severity:MEDIUM" ], "bugprone-assignment-in-if-condition": [ @@ -203,130 +193,95 @@ ], "bugprone-assignment-in-selection-statement": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/assignment-in-selection-statement.html", - "guideline:sei-cert-c", - "sei-cert-c:exp45-c", + "rule:exp45-c", "severity:MEDIUM" ], "bugprone-bad-signal-to-kill-thread": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/bad-signal-to-kill-thread.html", - "guideline:sei-cert-c", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:pos44-c", + "rule:pos44-c", "severity:MEDIUM" ], "bugprone-bitwise-pointer-cast": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/bitwise-pointer-cast.html", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", "severity:MEDIUM" ], "bugprone-bool-pointer-implicit-conversion": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/bool-pointer-implicit-conversion.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:LOW" ], "bugprone-branch-clone": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/branch-clone.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], "bugprone-capturing-this-in-member-variable": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/capturing-this-in-member-variable.html", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], "bugprone-casting-through-void": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/casting-through-void.html", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], "bugprone-chained-comparison": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/chained-comparison.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:LOW" ], "bugprone-command-processor": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/command-processor.html", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", "profile:extreme", - "cwe-vulnerabilities:cwe-78", - "cwe-top-25-2025:cwe-78", - "sei-cert-c:env33-c", - "sei-cert-cpp:env33-c", + "rule:cwe-78", + "rule:env33-c", "severity:MEDIUM" ], "bugprone-compare-pointer-to-member-virtual-function": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/compare-pointer-to-member-virtual-function.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "bugprone-copy-constructor-init": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/copy-constructor-init.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "bugprone-copy-constructor-mutates-argument": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/copy-constructor-mutates-argument.html", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", - "profile:sensitive", - "sei-cert-cpp:oop58-cpp", + "rule:oop58-cpp", "severity:MEDIUM" ], "bugprone-crtp-constructor-accessibility": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/crtp-constructor-accessibility.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], "bugprone-dangling-handle": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/dangling-handle.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "bugprone-default-operator-new-on-overaligned-type": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/default-operator-new-on-overaligned-type.html", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:mem57-cpp", + "rule:mem57-cpp", "severity:HIGH" ], "bugprone-derived-method-shadowing-base-method": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/derived-method-shadowing-base-method.html", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], "bugprone-dynamic-static-initializers": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/dynamic-static-initializers.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "bugprone-easily-swappable-parameters": [ @@ -336,119 +291,86 @@ ], "bugprone-empty-catch": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/empty-catch.html", - "guideline:cwe-vulnerabilities", - "cwe-vulnerabilities:cwe-390", + "rule:cwe-390", "severity:STYLE" ], "bugprone-exception-copy-constructor-throws": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/exception-copy-constructor-throws.html", - "guideline:sei-cert-cpp", - "profile:extreme", - "profile:security", "profile:sensitive", - "sei-cert-cpp:err60-cpp", + "profile:security", + "rule:err60-cpp", "severity:HIGH" ], "bugprone-exception-escape": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/exception-escape.html", - "guideline:sei-cert-cpp", - "profile:extreme", - "profile:security", "profile:sensitive", - "sei-cert-cpp:dcl57-cpp", - "sei-cert-cpp:err55-cpp", - "sei-cert-cpp:msc53-cpp", + "profile:security", + "rule:dcl57-cpp", + "rule:err55-cpp", + "rule:msc53-cpp", "severity:MEDIUM" ], "bugprone-float-loop-counter": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/float-loop-counter.html", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:flp30-c", - "sei-cert-cpp:flp30-c", + "rule:flp30-c", "severity:MEDIUM" ], "bugprone-fold-init-type": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/fold-init-type.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "bugprone-forward-declaration-namespace": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/forward-declaration-namespace.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:LOW" ], "bugprone-forwarding-reference-overload": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/forwarding-reference-overload.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:LOW" ], "bugprone-implicit-widening-of-multiplication-result": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/implicit-widening-of-multiplication-result.html", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], "bugprone-inaccurate-erase": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/inaccurate-erase.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "bugprone-inc-dec-in-conditions": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/inc-dec-in-conditions.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "bugprone-incorrect-enable-if": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/incorrect-enable-if.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "bugprone-incorrect-enable-shared-from-this": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/incorrect-enable-shared-from-this.html", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], "bugprone-incorrect-roundings": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/incorrect-roundings.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "bugprone-infinite-loop": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/infinite-loop.html", - "guideline:cwe-top-25-2024", - "guideline:cwe-vulnerabilities", "profile:default", - "profile:extreme", - "profile:sensitive", - "cwe-top-25-2024:cwe-400", - "cwe-vulnerabilities:cwe-400", + "rule:cwe-400", "severity:MEDIUM" ], "bugprone-integer-division": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/integer-division.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "bugprone-invalid-enum-default-initialization": [ @@ -459,58 +381,41 @@ "bugprone-lambda-function-name": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/lambda-function-name.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:LOW" ], "bugprone-macro-parentheses": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/macro-parentheses.html", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:extreme", "profile:security", - "sei-cert-c:pre02-c", - "sei-cert-cpp:pre02-c", + "rule:pre02-c", "severity:MEDIUM" ], "bugprone-macro-repeated-side-effects": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/macro-repeated-side-effects.html", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:pre31-c", - "sei-cert-cpp:pre31-c", + "rule:pre31-c", "severity:MEDIUM" ], "bugprone-misleading-setter-of-reference": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/misleading-setter-of-reference.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], "bugprone-misplaced-operator-in-strlen-in-alloc": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/misplaced-operator-in-strlen-in-alloc.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "bugprone-misplaced-pointer-arithmetic-in-alloc": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/misplaced-pointer-arithmetic-in-alloc.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "bugprone-misplaced-widening-cast": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/misplaced-widening-cast.html", "profile:default", - "profile:extreme", "profile:portability", - "profile:sensitive", "severity:HIGH" ], "bugprone-missing-end-comparison": [ @@ -520,59 +425,41 @@ "bugprone-move-forwarding-reference": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/move-forwarding-reference.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "bugprone-multi-level-implicit-pointer-conversion": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/multi-level-implicit-pointer-conversion.html", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], "bugprone-multiple-new-in-one-expression": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/multiple-new-in-one-expression.html", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:err51-cpp", - "sei-cert-cpp:exp50-cpp", - "sei-cert-cpp:mem51-cpp", - "sei-cert-cpp:mem52-cpp", + "rule:err51-cpp", + "rule:exp50-cpp", + "rule:mem51-cpp", + "rule:mem52-cpp", "severity:HIGH" ], "bugprone-multiple-statement-macro": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/multiple-statement-macro.html", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], "bugprone-narrowing-conversions": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/narrowing-conversions.html", - "guideline:cwe-top-25-2024", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "guideline:cwe-vulnerabilities", - "profile:extreme", - "profile:security", "profile:sensitive", - "cwe-top-25-2024:cwe-190", - "sei-cert-c:exp45-c", - "sei-cert-c:fio34-c", - "sei-cert-c:flp34-c", - "sei-cert-c:flp36-c", - "sei-cert-cpp:exp45-c", - "sei-cert-cpp:fio34-c", - "sei-cert-cpp:flp34-c", - "sei-cert-cpp:flp36-c", - "cwe-vulnerabilities:cwe-190", + "profile:security", + "rule:cwe-190", + "rule:exp45-c", + "rule:fio34-c", + "rule:flp34-c", + "rule:flp36-c", "severity:MEDIUM" ], "bugprone-no-escape": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/no-escape.html", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -584,118 +471,86 @@ "bugprone-nondeterministic-pointer-iteration-order": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/nondeterministic-pointer-iteration-order.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "bugprone-not-null-terminated-result": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/not-null-terminated-result.html", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", "profile:default", - "profile:extreme", - "profile:sensitive", - "cwe-vulnerabilities:cwe-120", - "cwe-top-25-2025:cwe-120", + "rule:cwe-120", "severity:MEDIUM" ], "bugprone-optional-value-conversion": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/optional-value-conversion.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:LOW" ], "bugprone-parent-virtual-call": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/parent-virtual-call.html", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], "bugprone-pointer-arithmetic-on-polymorphic-object": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/pointer-arithmetic-on-polymorphic-object.html", - "guideline:sei-cert-cpp", "profile:extreme", "profile:security", - "sei-cert-cpp:ctr56-cpp", + "rule:ctr56-cpp", "severity:HIGH" ], "bugprone-posix-return": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/posix-return.html", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], "bugprone-random-generator-seed": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/random-generator-seed.html", - "guideline:owasp-top-10-2021", - "guideline:owasp-top-10-2025", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "guideline:cwe-vulnerabilities", - "profile:extreme", - "profile:security", "profile:sensitive", - "cwe-vulnerabilities:cwe-335", - "owasp-top-10-2021:owasp-A02-2021", - "owasp-top-10-2025:owasp-A04-2025", - "sei-cert-c:msc32-c", - "sei-cert-cpp:msc51-cpp", + "profile:security", + "rule:cwe-335", + "rule:owasp-A02-2021", + "rule:owasp-A04-2025", + "rule:msc32-c", + "rule:msc51-cpp", "severity:MEDIUM" ], "bugprone-raw-memory-call-on-non-trivial-type": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/raw-memory-call-on-non-trivial-type.html", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:exp62-cpp", - "sei-cert-cpp:oop57-cpp", + "rule:exp62-cpp", + "rule:oop57-cpp", "severity:HIGH" ], "bugprone-redundant-branch-condition": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/redundant-branch-condition.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], "bugprone-reserved-identifier": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/reserved-identifier.html", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:extreme", "profile:security", - "sei-cert-c:dcl37-c", - "sei-cert-cpp:dcl51-cpp", + "rule:dcl37-c", + "rule:dcl51-cpp", "severity:LOW" ], "bugprone-return-const-ref-from-parameter": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/return-const-ref-from-parameter.html", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], "bugprone-shared-ptr-array-mismatch": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/shared-ptr-array-mismatch.html", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:mem51-cpp", + "rule:mem51-cpp", "severity:HIGH" ], "bugprone-signal-handler": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/signal-handler.html", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:msc54-cpp", - "sei-cert-c:sig30-c", + "rule:msc54-cpp", + "rule:sig30-c", "severity:MEDIUM" ], "bugprone-signed-bitwise": [ @@ -704,231 +559,157 @@ ], "bugprone-signed-char-misuse": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/signed-char-misuse.html", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:str34-c", - "sei-cert-cpp:str34-c", + "rule:str34-c", "severity:MEDIUM" ], "bugprone-sizeof-container": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/sizeof-container.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "bugprone-sizeof-expression": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/sizeof-expression.html", - "guideline:cwe-top-25-2024", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "guideline:cwe-vulnerabilities", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-top-25-2024:cwe-190", - "sei-cert-c:mem35-c", - "sei-cert-cpp:mem35-c", - "cwe-vulnerabilities:cwe-190", + "rule:cwe-190", + "rule:mem35-c", "severity:HIGH" ], "bugprone-spuriously-wake-up-functions": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/spuriously-wake-up-functions.html", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "profile:extreme", - "profile:security", "profile:sensitive", - "sei-cert-c:con36-c", - "sei-cert-cpp:con54-cpp", + "profile:security", + "rule:con36-c", + "rule:con54-cpp", "severity:MEDIUM" ], "bugprone-standalone-empty": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/standalone-empty.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "bugprone-std-exception-baseclass": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/std-exception-baseclass.html", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], "bugprone-std-namespace-modification": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/std-namespace-modification.html", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:dcl58-cpp", + "rule:dcl58-cpp", "severity:HIGH" ], "bugprone-string-constructor": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/string-constructor.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "bugprone-string-integer-assignment": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/string-integer-assignment.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], "bugprone-string-literal-with-embedded-nul": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/string-literal-with-embedded-nul.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "bugprone-stringview-nullptr": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/stringview-nullptr.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "bugprone-suspicious-enum-usage": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/suspicious-enum-usage.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "bugprone-suspicious-include": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/suspicious-include.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], "bugprone-suspicious-memory-comparison": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/suspicious-memory-comparison.html", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:exp42-c", - "sei-cert-c:flp37-c", - "sei-cert-cpp:exp42-c", - "sei-cert-cpp:flp37-c", + "rule:exp42-c", + "rule:flp37-c", "severity:MEDIUM" ], "bugprone-suspicious-memset-usage": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/suspicious-memset-usage.html", - "guideline:owasp-top-10-2021", - "guideline:owasp-top-10-2025", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "owasp-top-10-2021:owasp-A04-2021", - "owasp-top-10-2025:owasp-A06-2025", - "sei-cert-c:int31-c", - "sei-cert-cpp:int31-c", + "rule:owasp-A04-2021", + "rule:owasp-A06-2025", + "rule:int31-c", "severity:HIGH" ], "bugprone-suspicious-missing-comma": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/suspicious-missing-comma.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "bugprone-suspicious-realloc-usage": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/suspicious-realloc-usage.html", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:err33-c", - "sei-cert-cpp:err33-c", + "rule:err33-c", "severity:HIGH" ], "bugprone-suspicious-semicolon": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/suspicious-semicolon.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "bugprone-suspicious-string-compare": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/suspicious-string-compare.html", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], "bugprone-suspicious-stringview-data-usage": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/suspicious-stringview-data-usage.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "bugprone-swapped-arguments": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/swapped-arguments.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "bugprone-switch-missing-default-case": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/switch-missing-default-case.html", - "guideline:cwe-vulnerabilities", "profile:default", - "profile:extreme", - "profile:sensitive", - "cwe-vulnerabilities:cwe-478", + "rule:cwe-478", "severity:LOW" ], "bugprone-tagged-union-member-count": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/tagged-union-member-count.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "bugprone-terminating-continue": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/terminating-continue.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "bugprone-throw-keyword-missing": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/throw-keyword-missing.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "bugprone-throwing-static-initialization": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/throwing-static-initialization.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "bugprone-too-small-loop-variable": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/too-small-loop-variable.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "bugprone-unchecked-optional-access": [ @@ -938,33 +719,23 @@ ], "bugprone-unchecked-string-to-number-conversion": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/unchecked-string-to-number-conversion.html", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:extreme", - "sei-cert-c:err34-c", - "sei-cert-cpp:err34-c", + "rule:err34-c", "severity:MEDIUM" ], "bugprone-undefined-memory-manipulation": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/undefined-memory-manipulation.html", - "guideline:owasp-top-10-2021", - "guideline:owasp-top-10-2025", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "owasp-top-10-2021:owasp-A01-2021", - "owasp-top-10-2025:owasp-A06-2025", - "sei-cert-cpp:exp62-cpp", - "sei-cert-cpp:oop57-cpp", + "rule:owasp-A01-2021", + "rule:owasp-A06-2025", + "rule:exp62-cpp", + "rule:oop57-cpp", "severity:MEDIUM" ], "bugprone-undelegated-constructor": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/undelegated-constructor.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "bugprone-unhandled-code-paths": [ @@ -973,125 +744,82 @@ ], "bugprone-unhandled-exception-at-new": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/unhandled-exception-at-new.html", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:err51-cpp", - "sei-cert-cpp:mem52-cpp", + "rule:err51-cpp", + "rule:mem52-cpp", "severity:MEDIUM" ], "bugprone-unhandled-self-assignment": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/unhandled-self-assignment.html", - "guideline:sei-cert-cpp", - "profile:extreme", - "profile:security", "profile:sensitive", - "sei-cert-cpp:oop54-cpp", + "profile:security", + "rule:oop54-cpp", "severity:MEDIUM" ], "bugprone-unintended-char-ostream-output": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/unintended-char-ostream-output.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:LOW" ], "bugprone-unique-ptr-array-mismatch": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/unique-ptr-array-mismatch.html", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:mem51-cpp", + "rule:mem51-cpp", "severity:MEDIUM" ], "bugprone-unsafe-functions": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/unsafe-functions.html", - "guideline:cwe-top-25-2024", - "guideline:owasp-top-10-2021", - "guideline:owasp-top-10-2025", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", - "profile:extreme", - "profile:security", "profile:sensitive", - "cwe-top-25-2024:cwe-119", - "cwe-top-25-2024:cwe-125", - "cwe-top-25-2024:cwe-787", - "cwe-vulnerabilities:cwe-676", - "cwe-vulnerabilities:cwe-119", - "cwe-vulnerabilities:cwe-125", - "cwe-top-25-2025:cwe-125", - "cwe-vulnerabilities:cwe-787", - "cwe-top-25-2025:cwe-787", - "cwe-vulnerabilities:cwe-120", - "cwe-top-25-2025:cwe-120", - "owasp-top-10-2021:owasp-A04-2021", - "owasp-top-10-2025:owasp-A06-2025", - "sei-cert-c:msc24-c", - "sei-cert-c:msc33-c", - "sei-cert-cpp:msc24-c", - "sei-cert-cpp:msc33-c", + "profile:security", + "rule:cwe-119", + "rule:cwe-125", + "rule:cwe-787", + "rule:cwe-676", + "rule:cwe-120", + "rule:owasp-A04-2021", + "rule:owasp-A06-2025", + "rule:msc24-c", + "rule:msc33-c", "severity:LOW" ], "bugprone-unsafe-to-allow-exceptions": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/unsafe-to-allow-exceptions.html", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:dcl57-cpp", - "sei-cert-cpp:err55-cpp", + "rule:dcl57-cpp", + "rule:err55-cpp", "severity:HIGH" ], "bugprone-unused-local-non-trivial-variable": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/unused-local-non-trivial-variable.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], "bugprone-unused-raii": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/unused-raii.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "bugprone-unused-return-value": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/unused-return-value.html", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "guideline:cwe-vulnerabilities", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-vulnerabilities:cwe-252", - "sei-cert-c:err33-c", - "sei-cert-cpp:err33-c", + "rule:cwe-252", + "rule:err33-c", "severity:MEDIUM" ], "bugprone-use-after-move": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/use-after-move.html", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:exp63-cpp", + "rule:exp63-cpp", "severity:HIGH" ], "bugprone-virtual-near-miss": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/bugprone/virtual-near-miss.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cert-arr39-c": [ @@ -1112,33 +840,22 @@ ], "cert-dcl03-c": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cert/dcl03-c.html", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "profile:extreme", - "profile:security", "profile:sensitive", - "sei-cert-c:dcl03-c", - "sei-cert-cpp:dcl03-c", + "profile:security", + "rule:dcl03-c", "severity:MEDIUM" ], "cert-dcl16-c": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cert/dcl16-c.html", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "profile:extreme", - "profile:security", "profile:sensitive", - "sei-cert-c:dcl16-c", - "sei-cert-cpp:dcl16-c", + "profile:security", + "rule:dcl16-c", "severity:STYLE" ], "cert-dcl21-cpp": [ "doc_url:https://releases.llvm.org/18.1.1/tools/clang/tools/extra/docs/clang-tidy/checks/cert/dcl21-cpp.html", - "guideline:sei-cert-cpp", - "profile:extreme", - "profile:security", "profile:sensitive", - "sei-cert-cpp:dcl21-cpp", + "profile:security", "severity:LOW" ], "cert-dcl37-c": [ @@ -1147,11 +864,9 @@ ], "cert-dcl50-cpp": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cert/dcl50-cpp.html", - "guideline:sei-cert-cpp", - "profile:extreme", - "profile:security", "profile:sensitive", - "sei-cert-cpp:dcl50-cpp", + "profile:security", + "rule:dcl50-cpp", "severity:LOW" ], "cert-dcl51-cpp": [ @@ -1164,12 +879,9 @@ ], "cert-dcl58-cpp": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cert/dcl58-cpp.html", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:dcl58-cpp", + "rule:dcl58-cpp", "severity:HIGH" ], "cert-dcl59-cpp": [ @@ -1178,21 +890,12 @@ ], "cert-env33-c": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cert/env33-c.html", - "guideline:owasp-top-10-2021", - "guideline:owasp-top-10-2025", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", - "profile:extreme", - "profile:security", "profile:sensitive", - "cwe-vulnerabilities:cwe-78", - "cwe-top-25-2025:cwe-78", - "owasp-top-10-2021:owasp-A03-2021", - "owasp-top-10-2025:owasp-A05-2025", - "sei-cert-c:env33-c", - "sei-cert-cpp:env33-c", + "profile:security", + "rule:cwe-78", + "rule:owasp-A03-2021", + "rule:owasp-A05-2025", + "rule:env33-c", "severity:MEDIUM" ], "cert-err09-cpp": [ @@ -1201,56 +904,39 @@ ], "cert-err33-c": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cert/err33-c.html", - "guideline:owasp-top-10-2025", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "guideline:cwe-vulnerabilities", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-vulnerabilities:cwe-252", - "owasp-top-10-2025:owasp-A10-2025", - "sei-cert-c:err33-c", - "sei-cert-cpp:err33-c", + "rule:cwe-252", + "rule:owasp-A10-2025", + "rule:err33-c", "severity:MEDIUM" ], "cert-err34-c": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cert/err34-c.html", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "profile:extreme", - "profile:security", "profile:sensitive", - "sei-cert-c:err34-c", - "sei-cert-cpp:err34-c", + "profile:security", + "rule:err34-c", "severity:LOW" ], "cert-err52-cpp": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cert/err52-cpp.html", - "guideline:sei-cert-cpp", - "profile:extreme", - "profile:security", "profile:sensitive", - "sei-cert-cpp:err52-cpp", + "profile:security", + "rule:err52-cpp", "severity:LOW" ], "cert-err58-cpp": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cert/err58-cpp.html", - "guideline:sei-cert-cpp", - "profile:extreme", - "profile:security", "profile:sensitive", - "sei-cert-cpp:err58-cpp", + "profile:security", + "rule:err58-cpp", "severity:LOW" ], "cert-err60-cpp": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cert/err60-cpp.html", - "guideline:sei-cert-cpp", - "profile:extreme", - "profile:security", "profile:sensitive", - "sei-cert-cpp:err60-cpp", + "profile:security", + "rule:err60-cpp", "severity:MEDIUM" ], "cert-err61-cpp": [ @@ -1271,14 +957,9 @@ ], "cert-flp30-c": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cert/flp30-c.html", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:flp30-c", - "sei-cert-cpp:flp30-c", + "rule:flp30-c", "severity:HIGH" ], "cert-flp37-c": [ @@ -1291,96 +972,59 @@ ], "cert-mem57-cpp": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cert/mem57-cpp.html", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:mem57-cpp", + "rule:mem57-cpp", "severity:MEDIUM" ], "cert-msc24-c": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cert/msc24-c.html", - "guideline:cwe-top-25-2024", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", - "cwe-top-25-2024:cwe-119", - "cwe-top-25-2024:cwe-125", - "cwe-top-25-2024:cwe-787", - "cwe-vulnerabilities:cwe-119", - "cwe-vulnerabilities:cwe-125", - "cwe-top-25-2025:cwe-125", - "cwe-vulnerabilities:cwe-787", - "cwe-top-25-2025:cwe-787", + "rule:cwe-119", + "rule:cwe-125", + "rule:cwe-787", "severity:LOW" ], "cert-msc30-c": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cert/msc30-c.html", - "guideline:owasp-top-10-2021", - "guideline:owasp-top-10-2025", - "guideline:cwe-vulnerabilities", - "cwe-vulnerabilities:cwe-338", - "owasp-top-10-2021:owasp-A02-2021", - "owasp-top-10-2025:owasp-A04-2025", + "rule:cwe-338", + "rule:owasp-A02-2021", + "rule:owasp-A04-2025", "severity:LOW" ], "cert-msc32-c": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cert/msc32-c.html", - "guideline:owasp-top-10-2021", - "guideline:owasp-top-10-2025", - "guideline:cwe-vulnerabilities", - "cwe-vulnerabilities:cwe-335", - "owasp-top-10-2021:owasp-A02-2021", - "owasp-top-10-2025:owasp-A04-2025", + "rule:cwe-335", + "rule:owasp-A02-2021", + "rule:owasp-A04-2025", "severity:MEDIUM" ], "cert-msc33-c": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cert/msc33-c.html", - "guideline:cwe-top-25-2024", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", - "cwe-top-25-2024:cwe-119", - "cwe-top-25-2024:cwe-125", - "cwe-top-25-2024:cwe-787", - "cwe-vulnerabilities:cwe-119", - "cwe-vulnerabilities:cwe-125", - "cwe-top-25-2025:cwe-125", - "cwe-vulnerabilities:cwe-787", - "cwe-top-25-2025:cwe-787", + "rule:cwe-119", + "rule:cwe-125", + "rule:cwe-787", "severity:LOW" ], "cert-msc50-cpp": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cert/msc50-cpp.html", - "guideline:owasp-top-10-2021", - "guideline:owasp-top-10-2025", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "guideline:cwe-vulnerabilities", - "profile:extreme", - "profile:security", "profile:sensitive", - "cwe-vulnerabilities:cwe-338", - "owasp-top-10-2021:owasp-A02-2021", - "owasp-top-10-2025:owasp-A04-2025", - "sei-cert-c:msc30-c", - "sei-cert-cpp:msc50-cpp", + "profile:security", + "rule:cwe-338", + "rule:owasp-A02-2021", + "rule:owasp-A04-2025", + "rule:msc30-c", + "rule:msc50-cpp", "severity:LOW" ], "cert-msc51-cpp": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cert/msc51-cpp.html", - "guideline:owasp-top-10-2021", - "guideline:owasp-top-10-2025", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "guideline:cwe-vulnerabilities", - "profile:extreme", - "profile:security", "profile:sensitive", - "cwe-vulnerabilities:cwe-335", - "owasp-top-10-2021:owasp-A02-2021", - "owasp-top-10-2025:owasp-A04-2025", - "sei-cert-c:msc32-c", - "sei-cert-cpp:msc51-cpp", + "profile:security", + "rule:cwe-335", + "rule:owasp-A02-2021", + "rule:owasp-A04-2025", + "rule:msc32-c", + "rule:msc51-cpp", "severity:MEDIUM" ], "cert-msc54-cpp": [ @@ -1389,12 +1033,8 @@ ], "cert-oop11-cpp": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cert/oop11-cpp.html", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:oop11-cpp", "severity:MEDIUM" ], "cert-oop54-cpp": [ @@ -1403,21 +1043,16 @@ ], "cert-oop57-cpp": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cert/oop57-cpp.html", - "guideline:sei-cert-cpp", - "profile:extreme", - "profile:security", "profile:sensitive", - "sei-cert-cpp:oop57-cpp", + "profile:security", + "rule:oop57-cpp", "severity:HIGH" ], "cert-oop58-cpp": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cert/oop58-cpp.html", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:oop58-cpp", + "rule:oop58-cpp", "severity:MEDIUM" ], "cert-pos44-c": [ @@ -1451,8 +1086,6 @@ "clang-diagnostic-TU-local-entity-exposure": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wtu-local-entity-exposure", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-aarch64-sme-attributes": [ @@ -1510,8 +1143,6 @@ "clang-diagnostic-alloc-size": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#walloc-size", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-alloca": [ @@ -1616,7 +1247,6 @@ ], "clang-diagnostic-arm-interrupt-save-fp-no-vfp-unit": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#warm-interrupt-save-fp-no-vfp-unit", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -1626,25 +1256,18 @@ ], "clang-diagnostic-array-bounds-pointer-arithmetic": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#warray-bounds-pointer-arithmetic", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:arr39-c", - "sei-cert-cpp:arr39-c", + "rule:arr39-c", "severity:MEDIUM" ], "clang-diagnostic-array-compare": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#warray-compare", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-array-compare-cxx26": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#warray-compare-cxx26", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -1787,22 +1410,16 @@ "clang-diagnostic-bitwise-conditional-parentheses": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wbitwise-conditional-parentheses", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-bitwise-instead-of-logical": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wbitwise-instead-of-logical", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-bitwise-op-parentheses": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wbitwise-op-parentheses", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-block-capture-autoreleasing": [ @@ -1820,8 +1437,6 @@ "clang-diagnostic-bool-operation": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wbool-operation", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-braced-scalar-init": [ @@ -1846,10 +1461,7 @@ ], "clang-diagnostic-builtin-memcpy-chk-size": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wbuiltin-memcpy-chk-size", - "guideline:cwe-top-25-2024", - "guideline:cwe-vulnerabilities", - "cwe-top-25-2024:cwe-119", - "cwe-vulnerabilities:cwe-119", + "rule:cwe-119", "severity:MEDIUM" ], "clang-diagnostic-builtin-requires-header": [ @@ -1862,7 +1474,6 @@ ], "clang-diagnostic-c++-keyword": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wc-keyword", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -2145,8 +1756,6 @@ "clang-diagnostic-cast-of-sel-type": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wcast-of-sel-type", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-cast-qual": [ @@ -2160,8 +1769,6 @@ "clang-diagnostic-cfi-unchecked-callee": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wcfi-unchecked-callee", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "clang-diagnostic-cfstring-literal": [ @@ -2175,15 +1782,11 @@ "clang-diagnostic-char-subscripts": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wchar-subscripts", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-character-conversion": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wcharacter-conversion", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-cl4": [ @@ -2213,8 +1816,6 @@ "clang-diagnostic-comment": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wcomment", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-comments": [ @@ -2255,13 +1856,10 @@ ], "clang-diagnostic-conditional-uninitialized": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wconditional-uninitialized", - "guideline:sei-cert-c", - "label-tool-skip:severity", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:exp33-c", + "rule:exp33-c", + "label-tool-skip:severity", "severity:HIGH" ], "clang-diagnostic-config-macros": [ @@ -2302,7 +1900,6 @@ ], "clang-diagnostic-coro-type-aware-allocation-function": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wcoro-type-aware-allocation-function", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -2352,24 +1949,19 @@ ], "clang-diagnostic-dangling": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wdangling", - "guideline:sei-cert-cpp", - "label-tool-skip:severity", "profile:security", - "sei-cert-cpp:mem50-cpp", + "rule:mem50-cpp", + "label-tool-skip:severity", "severity:HIGH" ], "clang-diagnostic-dangling-capture": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wdangling-capture", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-dangling-else": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wdangling-else", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-dangling-field": [ @@ -2407,42 +1999,31 @@ "clang-diagnostic-default-const-init": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wdefault-const-init", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-default-const-init-field": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wdefault-const-init-field", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-default-const-init-field-unsafe": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wdefault-const-init-field-unsafe", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-default-const-init-unsafe": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wdefault-const-init-unsafe", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-default-const-init-var": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wdefault-const-init-var", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-default-const-init-var-unsafe": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wdefault-const-init-var-unsafe", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-defaulted-function-deleted": [ @@ -2459,43 +2040,31 @@ ], "clang-diagnostic-delete-abstract-non-virtual-dtor": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wdelete-abstract-non-virtual-dtor", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:oop52-cpp", + "rule:oop52-cpp", "severity:MEDIUM" ], "clang-diagnostic-delete-incomplete": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wdelete-incomplete", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:exp57-cpp", + "rule:exp57-cpp", "severity:MEDIUM" ], "clang-diagnostic-delete-non-abstract-non-virtual-dtor": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wdelete-non-abstract-non-virtual-dtor", - "guideline:sei-cert-cpp", - "label-tool-skip:severity", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:oop52-cpp", + "rule:oop52-cpp", + "label-tool-skip:severity", "severity:MEDIUM" ], "clang-diagnostic-delete-non-virtual-dtor": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wdelete-non-virtual-dtor", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:oop52-cpp", + "rule:oop52-cpp", "severity:MEDIUM" ], "clang-diagnostic-delimited-escape-sequence-extension": [ @@ -2537,8 +2106,6 @@ "clang-diagnostic-deprecated-copy": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wdeprecated-copy", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-deprecated-copy-dtor": [ @@ -2552,8 +2119,6 @@ "clang-diagnostic-deprecated-copy-with-user-provided-copy": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wdeprecated-copy-with-user-provided-copy", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-deprecated-copy-with-user-provided-dtor": [ @@ -2571,8 +2136,6 @@ "clang-diagnostic-deprecated-declarations-switch-case": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wdeprecated-declarations-switch-case", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-deprecated-dynamic-exception-spec": [ @@ -2609,7 +2172,6 @@ ], "clang-diagnostic-deprecated-missing-comma-variadic-parameter": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wdeprecated-missing-comma-variadic-parameter", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -2635,7 +2197,6 @@ ], "clang-diagnostic-deprecated-octal-literals": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wdeprecated-octal-literals", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -2697,11 +2258,8 @@ ], "clang-diagnostic-division-by-zero": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wdivision-by-zero", - "guideline:cwe-vulnerabilities", "profile:default", - "profile:extreme", - "profile:sensitive", - "cwe-vulnerabilities:cwe-369", + "rule:cwe-369", "severity:MEDIUM" ], "clang-diagnostic-dll-attribute-on-redeclaration": [ @@ -2742,14 +2300,9 @@ ], "clang-diagnostic-double-promotion": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wdouble-promotion", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:flp34-c", - "sei-cert-cpp:flp34-c", + "rule:flp34-c", "severity:MEDIUM" ], "clang-diagnostic-dtor-name": [ @@ -2786,10 +2339,9 @@ ], "clang-diagnostic-dynamic-class-memaccess": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wdynamic-class-memaccess", - "guideline:sei-cert-cpp", "profile:security", - "sei-cert-cpp:exp62-cpp", - "sei-cert-cpp:oop57-cpp", + "rule:exp62-cpp", + "rule:oop57-cpp", "severity:MEDIUM" ], "clang-diagnostic-dynamic-exception-spec": [ @@ -2814,14 +2366,9 @@ ], "clang-diagnostic-embedded-directive": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wembedded-directive", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:pre32-c", - "sei-cert-cpp:pre32-c", + "rule:pre32-c", "severity:MEDIUM" ], "clang-diagnostic-empty-body": [ @@ -2835,8 +2382,6 @@ "clang-diagnostic-empty-init-stmt": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wempty-init-stmt", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-empty-translation-unit": [ @@ -2866,8 +2411,6 @@ "clang-diagnostic-enum-compare-typo": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wenum-compare-typo", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "clang-diagnostic-enum-constexpr-conversion": [ @@ -2891,20 +2434,15 @@ "severity:MEDIUM" ], "clang-diagnostic-error": [ - "severity:CRITICAL", "profile:default", - "profile:extreme", - "profile:sensitive" + "severity:CRITICAL" ], "clang-diagnostic-exceptions": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wexceptions", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:err53-cpp", - "sei-cert-cpp:err54-cpp", + "rule:err53-cpp", + "rule:err54-cpp", "severity:MEDIUM" ], "clang-diagnostic-excess-initializers": [ @@ -2962,8 +2500,6 @@ "clang-diagnostic-extern-c-compat": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wextern-c-compat", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-extern-initializer": [ @@ -3020,16 +2556,10 @@ ], "clang-diagnostic-float-conversion": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wfloat-conversion", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:flp32-c", - "sei-cert-c:flp34-c", - "sei-cert-cpp:flp32-c", - "sei-cert-cpp:flp34-c", + "rule:flp32-c", + "rule:flp34-c", "severity:MEDIUM" ], "clang-diagnostic-float-equal": [ @@ -3047,42 +2577,29 @@ "clang-diagnostic-for-loop-analysis": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wfor-loop-analysis", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-format": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wformat", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "label-tool-skip:severity", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:fio47-c", - "sei-cert-cpp:fio47-c", + "rule:fio47-c", + "label-tool-skip:severity", "severity:MEDIUM" ], "clang-diagnostic-format-extra-args": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wformat-extra-args", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-format-insufficient-args": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wformat-insufficient-args", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-format-invalid-specifier": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wformat-invalid-specifier", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-format-non-iso": [ @@ -3091,35 +2608,24 @@ ], "clang-diagnostic-format-nonliteral": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wformat-nonliteral", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "label-tool-skip:severity", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:fio30-c", - "sei-cert-cpp:fio30-c", + "rule:fio30-c", + "label-tool-skip:severity", "severity:MEDIUM" ], "clang-diagnostic-format-overflow": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wformat-overflow", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "label-tool-skip:severity", "profile:security", - "sei-cert-c:mem35-c", - "sei-cert-cpp:mem35-c", + "rule:mem35-c", + "label-tool-skip:severity", "severity:HIGH" ], "clang-diagnostic-format-overflow-non-kprintf": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wformat-overflow-non-kprintf", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "label-tool-skip:severity", "profile:security", - "sei-cert-c:mem35-c", - "sei-cert-cpp:mem35-c", + "rule:mem35-c", + "label-tool-skip:severity", "severity:HIGH" ], "clang-diagnostic-format-pedantic": [ @@ -3128,22 +2634,11 @@ ], "clang-diagnostic-format-security": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wformat-security", - "guideline:cwe-top-25-2024", - "guideline:owasp-top-10-2025", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-top-25-2024:cwe-20", - "owasp-top-10-2025:owasp-A05-2025", - "sei-cert-c:fio30-c", - "sei-cert-cpp:fio30-c", - "cwe-vulnerabilities:cwe-20", - "cwe-top-25-2025:cwe-20", + "rule:cwe-20", + "rule:owasp-A05-2025", + "rule:fio30-c", "severity:MEDIUM" ], "clang-diagnostic-format-signedness": [ @@ -3165,15 +2660,11 @@ "clang-diagnostic-format-y2k": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wformat-y2k", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-format-zero-length": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wformat-zero-length", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-format=2": [ @@ -3182,10 +2673,7 @@ ], "clang-diagnostic-fortify-source": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wfortify-source", - "guideline:cwe-top-25-2024", - "guideline:cwe-vulnerabilities", - "cwe-top-25-2024:cwe-119", - "cwe-vulnerabilities:cwe-119", + "rule:cwe-119", "severity:MEDIUM" ], "clang-diagnostic-four-char-constants": [ @@ -3195,18 +2683,16 @@ "clang-diagnostic-frame-address": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wframe-address", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-frame-larger-than": [ - "blacklist:true", "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wframe-larger-than", + "blacklist:true", "severity:MEDIUM" ], "clang-diagnostic-frame-larger-than=": [ - "blacklist:true", "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#id1", + "blacklist:true", "severity:MEDIUM" ], "clang-diagnostic-framework-include-private-from-public": [ @@ -3236,8 +2722,6 @@ "clang-diagnostic-fuse-ld-path": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wfuse-ld-path", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-future-attribute-extensions": [ @@ -3439,7 +2923,6 @@ ], "clang-diagnostic-hlsl-implicit-binding": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#whlsl-implicit-binding", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -3457,7 +2940,6 @@ ], "clang-diagnostic-ignored-base-class-qualifiers": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wignored-base-class-qualifiers", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -3484,25 +2966,18 @@ "clang-diagnostic-ignored-qualifiers": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wignored-qualifiers", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-ignored-reference-qualifiers": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wignored-reference-qualifiers", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-implicit": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wimplicit", - "guideline:sei-cert-c", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:dcl31-c", + "rule:dcl31-c", "severity:MEDIUM" ], "clang-diagnostic-implicit-atomic-properties": [ @@ -3519,7 +2994,6 @@ ], "clang-diagnostic-implicit-enum-enum-cast": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wimplicit-enum-enum-cast", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -3545,32 +3019,23 @@ ], "clang-diagnostic-implicit-function-declaration": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wimplicit-function-declaration", - "guideline:sei-cert-c", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:dcl31-c", + "rule:dcl31-c", "severity:HIGH" ], "clang-diagnostic-implicit-int": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wimplicit-int", - "guideline:sei-cert-c", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:dcl31-c", + "rule:dcl31-c", "severity:HIGH" ], "clang-diagnostic-implicit-int-conversion": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wimplicit-int-conversion", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "label-tool-skip:severity", "profile:security", - "sei-cert-c:int36-c", - "sei-cert-cpp:int36-c", + "rule:int36-c", + "label-tool-skip:severity", "severity:MEDIUM" ], "clang-diagnostic-implicit-int-conversion-on-negation": [ @@ -3579,7 +3044,6 @@ ], "clang-diagnostic-implicit-int-enum-cast": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wimplicit-int-enum-cast", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -3664,12 +3128,9 @@ ], "clang-diagnostic-incompatible-function-pointer-types-strict": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wincompatible-function-pointer-types-strict", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "label-tool-skip:severity", "profile:security", - "sei-cert-c:exp37-c", - "sei-cert-cpp:exp37-c", + "rule:exp37-c", + "label-tool-skip:severity", "severity:MEDIUM" ], "clang-diagnostic-incompatible-library-redeclaration": [ @@ -3686,40 +3147,24 @@ ], "clang-diagnostic-incompatible-pointer-types": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wincompatible-pointer-types", - "guideline:cwe-top-25-2024", - "guideline:sei-cert-c", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-top-25-2024:cwe-119", - "cwe-top-25-2024:cwe-125", - "cwe-top-25-2024:cwe-787", - "sei-cert-c:exp32-c", - "cwe-vulnerabilities:cwe-119", - "cwe-vulnerabilities:cwe-125", - "cwe-top-25-2025:cwe-125", - "cwe-vulnerabilities:cwe-787", - "cwe-top-25-2025:cwe-787", + "rule:cwe-119", + "rule:cwe-125", + "rule:cwe-787", + "rule:exp32-c", "severity:MEDIUM" ], "clang-diagnostic-incompatible-pointer-types-discards-overflow-behavior": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wincompatible-pointer-types-discards-overflow-behavior", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-incompatible-pointer-types-discards-qualifiers": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wincompatible-pointer-types-discards-qualifiers", - "guideline:sei-cert-c", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:exp32-c", + "rule:exp32-c", "severity:MEDIUM" ], "clang-diagnostic-incompatible-property-type": [ @@ -3772,17 +3217,13 @@ ], "clang-diagnostic-infinite-recursion": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#winfinite-recursion", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:dcl56-cpp", + "rule:dcl56-cpp", "severity:MEDIUM" ], "clang-diagnostic-init-priority-reserved": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#winit-priority-reserved", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -3793,8 +3234,6 @@ "clang-diagnostic-initializer-overrides": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#winitializer-overrides", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "clang-diagnostic-injected-class-name": [ @@ -3827,12 +3266,9 @@ ], "clang-diagnostic-int-conversion": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wint-conversion", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "label-tool-skip:severity", "profile:security", - "sei-cert-c:int36-c", - "sei-cert-cpp:int36-c", + "rule:int36-c", + "label-tool-skip:severity", "severity:HIGH" ], "clang-diagnostic-int-conversions": [ @@ -3842,8 +3278,6 @@ "clang-diagnostic-int-in-bool-context": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wint-in-bool-context", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-int-to-pointer-cast": [ @@ -3856,10 +3290,7 @@ ], "clang-diagnostic-integer-overflow": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#winteger-overflow", - "guideline:cwe-top-25-2024", - "guideline:cwe-vulnerabilities", - "cwe-top-25-2024:cwe-190", - "cwe-vulnerabilities:cwe-190", + "rule:cwe-190", "severity:MEDIUM" ], "clang-diagnostic-interrupt-service-routine": [ @@ -3896,9 +3327,8 @@ ], "clang-diagnostic-invalid-noreturn": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#winvalid-noreturn", - "guideline:sei-cert-cpp", "profile:security", - "sei-cert-cpp:msc53-cpp", + "rule:msc53-cpp", "severity:MEDIUM" ], "clang-diagnostic-invalid-offsetof": [ @@ -3927,7 +3357,6 @@ ], "clang-diagnostic-invalid-specialization": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#winvalid-specialization", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -3950,13 +3379,10 @@ "clang-diagnostic-invalid-version-availability": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#winvalid-version-availability", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-jump-misses-init": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wjump-misses-init", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -3994,14 +3420,7 @@ ], "clang-diagnostic-lifetime-safety": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wlifetime-safety", - "guideline:cwe-top-25-2024", - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", - "cwe-top-25-2024:cwe-416", - "memory-safety:cwe-416", - "cwe-vulnerabilities:cwe-416", - "cwe-top-25-2025:cwe-416", + "rule:cwe-416", "severity:HIGH" ], "clang-diagnostic-lifetime-safety-all": [ @@ -4014,56 +3433,24 @@ ], "clang-diagnostic-lifetime-safety-dangling-field": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wlifetime-safety-dangling-field", - "guideline:cwe-top-25-2024", - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", "profile:default", - "profile:extreme", - "profile:sensitive", - "cwe-top-25-2024:cwe-416", - "memory-safety:cwe-416", - "cwe-vulnerabilities:cwe-416", - "cwe-top-25-2025:cwe-416", + "rule:cwe-416", "severity:HIGH" ], "clang-diagnostic-lifetime-safety-dangling-field-moved": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wlifetime-safety-dangling-field-moved", - "guideline:cwe-top-25-2024", - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", - "cwe-top-25-2024:cwe-416", - "memory-safety:cwe-416", - "cwe-vulnerabilities:cwe-416", - "cwe-top-25-2025:cwe-416", + "rule:cwe-416", "severity:HIGH" ], "clang-diagnostic-lifetime-safety-dangling-global": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wlifetime-safety-dangling-global", - "guideline:cwe-top-25-2024", - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", "profile:default", - "profile:extreme", - "profile:sensitive", - "cwe-top-25-2024:cwe-416", - "memory-safety:cwe-416", - "cwe-vulnerabilities:cwe-416", - "cwe-top-25-2025:cwe-416", + "rule:cwe-416", "severity:HIGH" ], "clang-diagnostic-lifetime-safety-dangling-global-moved": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wlifetime-safety-dangling-global-moved", - "guideline:cwe-top-25-2024", - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", - "cwe-top-25-2024:cwe-416", - "memory-safety:cwe-416", - "cwe-vulnerabilities:cwe-416", - "cwe-top-25-2025:cwe-416", + "rule:cwe-416", "severity:HIGH" ], "clang-diagnostic-lifetime-safety-intra-tu-suggestions": [ @@ -4072,14 +3459,7 @@ ], "clang-diagnostic-lifetime-safety-invalidation": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wlifetime-safety-invalidation", - "guideline:cwe-top-25-2024", - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", - "cwe-top-25-2024:cwe-416", - "memory-safety:cwe-416", - "cwe-vulnerabilities:cwe-416", - "cwe-top-25-2025:cwe-416", + "rule:cwe-416", "severity:HIGH" ], "clang-diagnostic-lifetime-safety-noescape": [ @@ -4092,29 +3472,13 @@ ], "clang-diagnostic-lifetime-safety-return-stack-addr": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wlifetime-safety-return-stack-addr", - "guideline:cwe-top-25-2024", - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", "profile:default", - "profile:extreme", - "profile:sensitive", - "cwe-top-25-2024:cwe-416", - "memory-safety:cwe-416", - "cwe-vulnerabilities:cwe-416", - "cwe-top-25-2025:cwe-416", + "rule:cwe-416", "severity:HIGH" ], "clang-diagnostic-lifetime-safety-return-stack-addr-moved": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wlifetime-safety-return-stack-addr-moved", - "guideline:cwe-top-25-2024", - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", - "cwe-top-25-2024:cwe-416", - "memory-safety:cwe-416", - "cwe-vulnerabilities:cwe-416", - "cwe-top-25-2025:cwe-416", + "rule:cwe-416", "severity:HIGH" ], "clang-diagnostic-lifetime-safety-strict": [ @@ -4127,44 +3491,19 @@ ], "clang-diagnostic-lifetime-safety-use-after-free": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wlifetime-safety-use-after-free", - "guideline:cwe-top-25-2024", - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", "profile:default", - "profile:extreme", - "profile:sensitive", - "cwe-top-25-2024:cwe-416", - "memory-safety:cwe-416", - "cwe-vulnerabilities:cwe-416", - "cwe-top-25-2025:cwe-416", + "rule:cwe-416", "severity:HIGH" ], "clang-diagnostic-lifetime-safety-use-after-scope": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wlifetime-safety-use-after-scope", - "guideline:cwe-top-25-2024", - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", "profile:default", - "profile:extreme", - "profile:sensitive", - "cwe-top-25-2024:cwe-416", - "memory-safety:cwe-416", - "cwe-vulnerabilities:cwe-416", - "cwe-top-25-2025:cwe-416", + "rule:cwe-416", "severity:HIGH" ], "clang-diagnostic-lifetime-safety-use-after-scope-moved": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wlifetime-safety-use-after-scope-moved", - "guideline:cwe-top-25-2024", - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", - "cwe-top-25-2024:cwe-416", - "memory-safety:cwe-416", - "cwe-vulnerabilities:cwe-416", - "cwe-top-25-2025:cwe-416", + "rule:cwe-416", "severity:HIGH" ], "clang-diagnostic-lifetime-safety-validations": [ @@ -4190,15 +3529,11 @@ "clang-diagnostic-logical-not-parentheses": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wlogical-not-parentheses", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-logical-op-parentheses": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wlogical-op-parentheses", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-long-long": [ @@ -4240,8 +3575,6 @@ "clang-diagnostic-matrix-conversion": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wmatrix-conversion", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-max-tokens": [ @@ -4362,7 +3695,6 @@ ], "clang-diagnostic-microsoft-inline-on-non-function": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wmicrosoft-inline-on-non-function", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -4421,16 +3753,13 @@ "clang-diagnostic-misleading-indentation": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wmisleading-indentation", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-mismatched-new-delete": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wmismatched-new-delete", - "guideline:sei-cert-cpp", - "label-tool-skip:severity", "profile:security", - "sei-cert-cpp:mem51-cpp", + "rule:mem51-cpp", + "label-tool-skip:severity", "severity:HIGH" ], "clang-diagnostic-mismatched-parameter-types": [ @@ -4444,15 +3773,11 @@ "clang-diagnostic-mismatched-tags": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wmismatched-tags", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-missing-braces": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wmissing-braces", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-missing-constinit": [ @@ -4474,8 +3799,6 @@ "clang-diagnostic-missing-field-initializers": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wmissing-field-initializers", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-missing-format-attribute": [ @@ -4489,8 +3812,6 @@ "clang-diagnostic-missing-method-return-type": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wmissing-method-return-type", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-missing-multilib": [ @@ -4547,7 +3868,6 @@ ], "clang-diagnostic-module-file-mapping-mismatch": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wmodule-file-mapping-mismatch", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -4569,7 +3889,6 @@ ], "clang-diagnostic-module-map": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#rmodule-map", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -4596,15 +3915,11 @@ "clang-diagnostic-most": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wmost", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-move": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wmove", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-ms-bitfield-padding": [ @@ -4626,8 +3941,6 @@ "clang-diagnostic-multichar": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wmultichar", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-multilib-not-found": [ @@ -4700,23 +4013,15 @@ ], "clang-diagnostic-non-virtual-dtor": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wnon-virtual-dtor", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:oop52-cpp", + "rule:oop52-cpp", "severity:MEDIUM" ], "clang-diagnostic-nonnull": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wnonnull", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", "profile:default", - "profile:extreme", - "profile:sensitive", - "cwe-vulnerabilities:cwe-476", - "cwe-top-25-2025:cwe-476", + "rule:cwe-476", "severity:MEDIUM" ], "clang-diagnostic-nonportable-cfstrings": [ @@ -4737,7 +4042,6 @@ ], "clang-diagnostic-nonportable-sycl": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wnonportable-sycl", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -4755,7 +4059,6 @@ ], "clang-diagnostic-nontrivial-memcall": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wnontrivial-memcall", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -4794,15 +4097,11 @@ "clang-diagnostic-null-pointer-arithmetic": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wnull-pointer-arithmetic", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-null-pointer-subtraction": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wnull-pointer-subtraction", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-nullability": [ @@ -4856,8 +4155,6 @@ "clang-diagnostic-objc-designated-initializers": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wobjc-designated-initializers", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-objc-dictionary-duplicate-keys": [ @@ -4871,8 +4168,6 @@ "clang-diagnostic-objc-flexible-array": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wobjc-flexible-array", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-objc-forward-class-redefinition": [ @@ -4910,8 +4205,6 @@ "clang-diagnostic-objc-missing-super-calls": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wobjc-missing-super-calls", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-objc-multiple-method-names": [ @@ -5004,7 +4297,6 @@ ], "clang-diagnostic-octal-prefix-extension": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#woctal-prefix-extension", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -5030,7 +4322,6 @@ ], "clang-diagnostic-openacc-confusing-routine-name": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wopenacc-confusing-routine-name", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -5108,10 +4399,9 @@ ], "clang-diagnostic-over-aligned": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wover-aligned", - "guideline:sei-cert-cpp", - "label-tool-skip:severity", "profile:security", - "sei-cert-cpp:mem57-cpp", + "rule:mem57-cpp", + "label-tool-skip:severity", "severity:MEDIUM" ], "clang-diagnostic-overflow": [ @@ -5133,15 +4423,11 @@ "clang-diagnostic-overloaded-shift-op-parentheses": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#woverloaded-shift-op-parentheses", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-overloaded-virtual": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#woverloaded-virtual", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-override-init": [ @@ -5155,15 +4441,11 @@ "clang-diagnostic-overriding-complex-range": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#woverriding-complex-range", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-overriding-deployment-version": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#woverriding-deployment-version", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-overriding-method-mismatch": [ @@ -5196,22 +4478,15 @@ ], "clang-diagnostic-parentheses": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wparentheses", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "label-tool-skip:severity", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:exp45-c", - "sei-cert-cpp:exp45-c", + "rule:exp45-c", + "label-tool-skip:severity", "severity:MEDIUM" ], "clang-diagnostic-parentheses-equality": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wparentheses-equality", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-partial-availability": [ @@ -5257,8 +4532,6 @@ "clang-diagnostic-pessimizing-move": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wpessimizing-move", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-pgo-coverage": [ @@ -5291,12 +4564,9 @@ ], "clang-diagnostic-pointer-to-int-cast": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wpointer-to-int-cast", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "label-tool-skip:severity", "profile:security", - "sei-cert-c:int36-c", - "sei-cert-cpp:int36-c", + "rule:int36-c", + "label-tool-skip:severity", "severity:MEDIUM" ], "clang-diagnostic-pointer-type-mismatch": [ @@ -5314,8 +4584,6 @@ "clang-diagnostic-potentially-evaluated-expression": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wpotentially-evaluated-expression", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-pragma-clang-attribute": [ @@ -5432,21 +4700,17 @@ ], "clang-diagnostic-preferred-type-bitfield-enum-conversion": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wpreferred-type-bitfield-enum-conversion", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-preferred-type-bitfield-width": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wpreferred-type-bitfield-width", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-private-extern": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wprivate-extern", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-private-header": [ @@ -5512,8 +4776,6 @@ "clang-diagnostic-range-loop-construct": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wrange-loop-construct", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-read-modules-implicitly": [ @@ -5542,13 +4804,11 @@ ], "clang-diagnostic-reduced-bmi-output-overrided": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wreduced-bmi-output-overrided", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-redundant-attribute": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wredundant-attribute", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -5563,8 +4823,6 @@ "clang-diagnostic-redundant-move": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wredundant-move", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-redundant-parens": [ @@ -5574,8 +4832,6 @@ "clang-diagnostic-reference-tu-local-entity-in-other-tu": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wreference-tu-local-entity-in-other-tu", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-register": [ @@ -5593,25 +4849,18 @@ "clang-diagnostic-reorder": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wreorder", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-reorder-ctor": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wreorder-ctor", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:oop53-cpp", + "rule:oop53-cpp", "severity:MEDIUM" ], "clang-diagnostic-reorder-init-list": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wreorder-init-list", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-requires-super-attribute": [ @@ -5620,7 +4869,6 @@ ], "clang-diagnostic-reserved-attribute-identifier": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wreserved-attribute-identifier", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -5630,35 +4878,25 @@ ], "clang-diagnostic-reserved-identifier": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wreserved-identifier", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:dcl37-c", - "sei-cert-cpp:dcl51-cpp", + "rule:dcl37-c", + "rule:dcl51-cpp", "severity:MEDIUM" ], "clang-diagnostic-reserved-macro-identifier": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wreserved-macro-identifier", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:dcl37-c", - "sei-cert-cpp:dcl51-cpp", + "rule:dcl37-c", + "rule:dcl51-cpp", "severity:MEDIUM" ], "clang-diagnostic-reserved-module-identifier": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wreserved-module-identifier", - "guideline:sei-cert-cpp", - "profile:extreme", - "profile:security", "profile:sensitive", - "sei-cert-cpp:dcl51-cpp", + "profile:security", + "rule:dcl51-cpp", "severity:MEDIUM" ], "clang-diagnostic-reserved-user-defined-literal": [ @@ -5683,46 +4921,31 @@ ], "clang-diagnostic-return-stack-address": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wreturn-stack-address", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:dcl30-c", - "sei-cert-cpp:exp54-cpp", - "sei-cert-cpp:exp61-cpp", - "memory-safety:cwe-562", - "cwe-vulnerabilities:cwe-562", + "rule:dcl30-c", + "rule:exp54-cpp", + "rule:exp61-cpp", + "rule:cwe-562", "severity:MEDIUM" ], "clang-diagnostic-return-std-move": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wreturn-std-move", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-return-type": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wreturn-type", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "label-tool-skip:severity", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:msc37-c", - "sei-cert-cpp:msc52-cpp", + "rule:msc37-c", + "rule:msc52-cpp", + "label-tool-skip:severity", "severity:MEDIUM" ], "clang-diagnostic-return-type-c-linkage": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wreturn-type-c-linkage", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-rewrite-not-bool": [ @@ -5772,40 +4995,29 @@ "clang-diagnostic-self-assign": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wself-assign", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-self-assign-field": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wself-assign-field", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-self-assign-overloaded": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wself-assign-overloaded", - "guideline:sei-cert-cpp", - "label-tool-skip:severity", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:oop54-cpp", + "rule:oop54-cpp", + "label-tool-skip:severity", "severity:MEDIUM" ], "clang-diagnostic-self-move": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wself-move", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-semicolon-before-method-body": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wsemicolon-before-method-body", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-sentinel": [ @@ -5854,7 +5066,6 @@ ], "clang-diagnostic-shift-bool": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wshift-bool", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -5864,10 +5075,7 @@ ], "clang-diagnostic-shift-count-overflow": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wshift-count-overflow", - "guideline:cwe-top-25-2024", - "guideline:cwe-vulnerabilities", - "cwe-top-25-2024:cwe-190", - "cwe-vulnerabilities:cwe-190", + "rule:cwe-190", "severity:MEDIUM" ], "clang-diagnostic-shift-negative-value": [ @@ -5877,47 +5085,31 @@ "clang-diagnostic-shift-op-parentheses": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wshift-op-parentheses", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-shift-overflow": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wshift-overflow", - "guideline:cwe-top-25-2024", - "guideline:cwe-vulnerabilities", - "cwe-top-25-2024:cwe-190", - "cwe-vulnerabilities:cwe-190", + "rule:cwe-190", "severity:MEDIUM" ], "clang-diagnostic-shift-sign-overflow": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wshift-sign-overflow", - "guideline:cwe-top-25-2024", - "guideline:cwe-vulnerabilities", - "cwe-top-25-2024:cwe-190", - "cwe-vulnerabilities:cwe-190", + "rule:cwe-190", "severity:MEDIUM" ], "clang-diagnostic-shorten-64-to-32": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wshorten-64-to-32", - "guideline:cwe-top-25-2024", - "guideline:cwe-vulnerabilities", - "cwe-top-25-2024:cwe-190", - "cwe-vulnerabilities:cwe-190", + "rule:cwe-190", "severity:MEDIUM" ], "clang-diagnostic-sign-compare": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wsign-compare", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-sign-conversion": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wsign-conversion", - "guideline:cwe-top-25-2024", - "guideline:cwe-vulnerabilities", - "cwe-top-25-2024:cwe-190", - "cwe-vulnerabilities:cwe-190", + "rule:cwe-190", "severity:MEDIUM" ], "clang-diagnostic-sign-promo": [ @@ -5943,15 +5135,11 @@ "clang-diagnostic-sizeof-array-argument": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wsizeof-array-argument", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-sizeof-array-decay": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wsizeof-array-decay", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-sizeof-array-div": [ @@ -5980,14 +5168,11 @@ ], "clang-diagnostic-sometimes-uninitialized": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wsometimes-uninitialized", - "guideline:sei-cert-c", - "label-tool-skip:severity", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:dcl41-c", - "sei-cert-c:exp33-c", + "rule:dcl41-c", + "rule:exp33-c", + "label-tool-skip:severity", "severity:MEDIUM" ], "clang-diagnostic-source-mgr": [ @@ -6024,14 +5209,9 @@ ], "clang-diagnostic-static-in-inline": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wstatic-in-inline", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:msc40-c", - "sei-cert-cpp:msc40-c", + "rule:msc40-c", "severity:MEDIUM" ], "clang-diagnostic-static-inline-explicit-instantiation": [ @@ -6045,8 +5225,6 @@ "clang-diagnostic-static-self-init": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wstatic-self-init", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-stdlibcxx-not-found": [ @@ -6120,8 +5298,6 @@ "clang-diagnostic-string-concatenation": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wstring-concatenation", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-string-conversion": [ @@ -6135,8 +5311,6 @@ "clang-diagnostic-string-plus-int": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wstring-plus-int", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-strlcpy-strlcat-size": [ @@ -6145,10 +5319,7 @@ ], "clang-diagnostic-strncat-size": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wstrncat-size", - "guideline:cwe-top-25-2024", - "guideline:cwe-vulnerabilities", - "cwe-top-25-2024:cwe-119", - "cwe-vulnerabilities:cwe-119", + "rule:cwe-119", "severity:MEDIUM" ], "clang-diagnostic-suggest-destructor-override": [ @@ -6177,20 +5348,13 @@ ], "clang-diagnostic-switch": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wswitch", - "guideline:cwe-top-25-2024", - "guideline:cwe-vulnerabilities", "profile:default", - "profile:extreme", - "profile:sensitive", - "cwe-top-25-2024:cwe-190", - "cwe-vulnerabilities:cwe-190", + "rule:cwe-190", "severity:MEDIUM" ], "clang-diagnostic-switch-bool": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wswitch-bool", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-switch-default": [ @@ -6220,22 +5384,16 @@ "clang-diagnostic-tautological-bitwise-compare": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wtautological-bitwise-compare", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-tautological-compare": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wtautological-compare", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-tautological-constant-compare": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wtautological-constant-compare", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-tautological-constant-in-range-compare": [ @@ -6245,8 +5403,6 @@ "clang-diagnostic-tautological-constant-out-of-range-compare": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wtautological-constant-out-of-range-compare", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-tautological-negation-compare": [ @@ -6256,22 +5412,16 @@ "clang-diagnostic-tautological-objc-bool-compare": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wtautological-objc-bool-compare", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-tautological-overlap-compare": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wtautological-overlap-compare", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-tautological-pointer-compare": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wtautological-pointer-compare", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-tautological-type-limit-compare": [ @@ -6281,8 +5431,6 @@ "clang-diagnostic-tautological-undefined-compare": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wtautological-undefined-compare", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-tautological-unsigned-char-zero-compare": [ @@ -6315,7 +5463,6 @@ ], "clang-diagnostic-tentative-definition-compat": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wtentative-definition-compat", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -6345,12 +5492,8 @@ ], "clang-diagnostic-thread-safety-pointer": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wthread-safety-pointer", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "profile:extreme", "profile:sensitive", - "sei-cert-c:msc54-c", - "sei-cert-cpp:msc54-c", + "rule:msc54-cpp", "severity:MEDIUM" ], "clang-diagnostic-thread-safety-precise": [ @@ -6372,8 +5515,6 @@ "clang-diagnostic-trigraphs": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wtrigraphs", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-trivial-auto-var-init": [ @@ -6426,7 +5567,6 @@ ], "clang-diagnostic-undef-true": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wundef-true", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -6477,27 +5617,18 @@ "clang-diagnostic-underlying-atomic-qualifier-ignored": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wunderlying-atomic-qualifier-ignored", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:STYLE" ], "clang-diagnostic-underlying-cv-qualifier-ignored": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wunderlying-cv-qualifier-ignored", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:STYLE" ], "clang-diagnostic-unevaluated-expression": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wunevaluated-expression", - "guideline:sei-cert-cpp", - "guideline:sei-cert-c", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:exp44-c", - "sei-cert-c:exp44-c", + "rule:exp44-c", "severity:MEDIUM" ], "clang-diagnostic-unguarded-availability": [ @@ -6526,49 +5657,34 @@ ], "clang-diagnostic-uninitialized": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wuninitialized", - "guideline:sei-cert-c", - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "label-tool-skip:severity", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:exp33-c", - "memory-safety:cwe-457", - "cwe-vulnerabilities:cwe-457", + "rule:exp33-c", + "rule:cwe-457", + "label-tool-skip:severity", "severity:HIGH" ], "clang-diagnostic-uninitialized-const-pointer": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wuninitialized-const-pointer", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-uninitialized-const-reference": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wuninitialized-const-reference", - "guideline:sei-cert-c", - "label-tool-skip:severity", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:exp33-c", + "rule:exp33-c", + "label-tool-skip:severity", "severity:MEDIUM" ], "clang-diagnostic-uninitialized-explicit-init": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wuninitialized-explicit-init", - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "sei-cert-c:exp33-c", + "rule:exp33-c", "severity:MEDIUM" ], "clang-diagnostic-unique-object-duplication": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wunique-object-duplication", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -6603,8 +5719,6 @@ "clang-diagnostic-unknown-pragmas": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wunknown-pragmas", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-unknown-sanitizers": [ @@ -6622,15 +5736,11 @@ "clang-diagnostic-unnecessary-virtual-specifier": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wunnecessary-virtual-specifier", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-unneeded-internal-declaration": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wunneeded-internal-declaration", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-unneeded-member-function": [ @@ -6688,20 +5798,13 @@ "clang-diagnostic-unsafe-buffer-usage-in-unique-ptr-array-access": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wunsafe-buffer-usage-in-unique-ptr-array-access", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "clang-diagnostic-unsequenced": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wunsequenced", - "guideline:sei-cert-cpp", - "guideline:sei-cert-c", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:exp30-c", - "sei-cert-cpp:exp30-c", + "rule:exp30-c", "severity:MEDIUM" ], "clang-diagnostic-unsupported-abi": [ @@ -6750,7 +5853,6 @@ ], "clang-diagnostic-unterminated-string-initialization": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wunterminated-string-initialization", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -6765,8 +5867,6 @@ "clang-diagnostic-unused-argument": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wunused-argument", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-unused-but-set-global": [ @@ -6776,15 +5876,11 @@ "clang-diagnostic-unused-but-set-parameter": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wunused-but-set-parameter", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-unused-but-set-variable": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wunused-but-set-variable", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-unused-command-line-argument": [ @@ -6794,15 +5890,11 @@ "clang-diagnostic-unused-comparison": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wunused-comparison", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-unused-const-variable": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wunused-const-variable", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-unused-exception-parameter": [ @@ -6812,8 +5904,6 @@ "clang-diagnostic-unused-function": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wunused-function", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-unused-getter-return-value": [ @@ -6823,22 +5913,16 @@ "clang-diagnostic-unused-label": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wunused-label", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-unused-lambda-capture": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wunused-lambda-capture", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-unused-local-typedef": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wunused-local-typedef", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-unused-local-typedefs": [ @@ -6856,29 +5940,21 @@ "clang-diagnostic-unused-parameter": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wunused-parameter", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-unused-private-field": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wunused-private-field", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-unused-property-ivar": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wunused-property-ivar", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-unused-result": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wunused-result", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-unused-template": [ @@ -6888,15 +5964,11 @@ "clang-diagnostic-unused-value": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wunused-value", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-unused-variable": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wunused-variable", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-unused-volatile-lvalue": [ @@ -6909,34 +5981,26 @@ ], "clang-diagnostic-user-defined-literals": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wuser-defined-literals", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:dcl51-cpp", + "rule:dcl51-cpp", "severity:MEDIUM" ], "clang-diagnostic-user-defined-warnings": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wuser-defined-warnings", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-varargs": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wvarargs", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "label-tool-skip:severity", "profile:security", - "sei-cert-c:exp47-c", - "sei-cert-cpp:exp58-cpp", + "rule:exp47-c", + "rule:exp58-cpp", + "label-tool-skip:severity", "severity:MEDIUM" ], "clang-diagnostic-variadic-macro-arguments-omitted": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wvariadic-macro-arguments-omitted", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -6958,12 +6022,9 @@ ], "clang-diagnostic-vexing-parse": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wvexing-parse", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:dcl53-cpp", + "rule:dcl53-cpp", "severity:MEDIUM" ], "clang-diagnostic-visibility": [ @@ -7001,8 +6062,6 @@ "clang-diagnostic-volatile-register-var": [ "doc_url:https://clang.llvm.org/docs/DiagnosticsReference.html#wvolatile-register-var", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "clang-diagnostic-wasm-exception-spec": [ @@ -7039,27 +6098,18 @@ ], "concurrency-mt-unsafe": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/concurrency/mt-unsafe.html", - "guideline:owasp-top-10-2021", - "guideline:owasp-top-10-2025", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "guideline:cwe-vulnerabilities", "profile:security", - "cwe-vulnerabilities:cwe-362", - "owasp-top-10-2021:owasp-A02-2021", - "owasp-top-10-2025:owasp-A06-2025", - "sei-cert-c:con33-c", - "sei-cert-cpp:con33-c", + "rule:cwe-362", + "rule:owasp-A02-2021", + "rule:owasp-A06-2025", + "rule:con33-c", "severity:MEDIUM" ], "concurrency-thread-canceltype-asynchronous": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/concurrency/thread-canceltype-asynchronous.html", - "guideline:sei-cert-c", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:pos47-c", + "rule:pos47-c", "severity:MEDIUM" ], "cppcoreguidelines-avoid-c-arrays": [ @@ -7070,13 +6120,10 @@ "cppcoreguidelines-avoid-capturing-lambda-coroutines": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cppcoreguidelines/avoid-capturing-lambda-coroutines.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcoreguidelines-avoid-const-or-ref-data-members": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cppcoreguidelines/avoid-const-or-ref-data-members.html", - "profile:extreme", "profile:sensitive", "severity:STYLE" ], @@ -7103,8 +6150,6 @@ "cppcoreguidelines-avoid-reference-coroutine-parameters": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cppcoreguidelines/avoid-reference-coroutine-parameters.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcoreguidelines-c-copy-assignment-signature": [ @@ -7143,7 +6188,6 @@ ], "cppcoreguidelines-misleading-capture-default-by-value": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cppcoreguidelines/misleading-capture-default-by-value.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], @@ -7214,11 +6258,9 @@ ], "cppcoreguidelines-pro-type-const-cast": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cppcoreguidelines/pro-type-const-cast.html", - "guideline:sei-cert-cpp", - "profile:extreme", - "profile:security", "profile:sensitive", - "sei-cert-cpp:exp55-cpp", + "profile:security", + "rule:exp55-cpp", "severity:LOW" ], "cppcoreguidelines-pro-type-cstyle-cast": [ @@ -7238,7 +6280,6 @@ ], "cppcoreguidelines-pro-type-static-cast-downcast": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cppcoreguidelines/pro-type-static-cast-downcast.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], @@ -7254,22 +6295,18 @@ ], "cppcoreguidelines-rvalue-reference-param-not-moved": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cppcoreguidelines/rvalue-reference-param-not-moved.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], "cppcoreguidelines-slicing": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cppcoreguidelines/slicing.html", - "guideline:sei-cert-cpp", - "profile:extreme", - "profile:security", "profile:sensitive", - "sei-cert-cpp:oop51-cpp", + "profile:security", + "rule:oop51-cpp", "severity:LOW" ], "cppcoreguidelines-special-member-functions": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cppcoreguidelines/special-member-functions.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], @@ -7286,8 +6323,6 @@ "cppcoreguidelines-virtual-class-destructor": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/cppcoreguidelines/virtual-class-destructor.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "darwin-avoid-spinlock": [ @@ -7325,23 +6360,18 @@ ], "google-build-explicit-make-pair": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/google/build-explicit-make-pair.html", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], "google-build-namespaces": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/google/build-namespaces.html", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:dcl59-cpp", + "rule:dcl59-cpp", "severity:MEDIUM" ], "google-build-using-namespace": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/google/build-using-namespace.html", - "profile:extreme", "profile:sensitive", "severity:STYLE" ], @@ -7352,13 +6382,11 @@ ], "google-explicit-constructor": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/google/explicit-constructor.html", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], "google-global-names-in-headers": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/google/global-names-in-headers.html", - "profile:extreme", "profile:sensitive", "severity:STYLE" ], @@ -7385,9 +6413,8 @@ ], "google-readability-braces-around-statements": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/google/readability-braces-around-statements.html", - "guideline:misra-c", - "misra-c:14.9", "profile:extreme", + "rule:14.9", "severity:STYLE" ], "google-readability-casting": [ @@ -7422,31 +6449,26 @@ ], "google-runtime-int": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/google/runtime-int.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], "google-runtime-member-string-references": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/google-runtime-member-string-references.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], "google-runtime-memset": [ "doc_url:https://releases.llvm.org/4.0.0/tools/clang/tools/extra/docs/clang-tidy/checks/google-runtime-memset.html", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], "google-runtime-operator": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/google/runtime-operator.html", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], "google-runtime-references": [ "doc_url:https://releases.llvm.org/11.1.0/tools/clang/tools/extra/docs/clang-tidy/checks/google-runtime-references.html", - "profile:extreme", "profile:sensitive", "severity:STYLE" ], @@ -7661,40 +6683,29 @@ ], "misc-anonymous-namespace-in-header": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/misc/anonymous-namespace-in-header.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], "misc-argument-comment": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-argument-comment.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], "misc-assert-side-effect": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-assert-side-effect.html", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:pre31-c", - "sei-cert-cpp:pre31-c", + "rule:pre31-c", "severity:MEDIUM" ], "misc-bool-pointer-implicit-conversion": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-bool-pointer-implicit-conversion.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:LOW" ], "misc-confusable-identifiers": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/misc/confusable-identifiers.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "misc-const-correctness": [ @@ -7708,56 +6719,41 @@ "misc-dangling-handle": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-dangling-handle.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "misc-definitions-in-headers": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/misc/definitions-in-headers.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "misc-explicit-constructor": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/misc/explicit-constructor.html", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], "misc-fold-init-type": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-fold-init-type.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "misc-forward-declaration-namespace": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-forward-declaration-namespace.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:LOW" ], "misc-forwarding-reference-overload": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-forwarding-reference-overload.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:LOW" ], "misc-header-include-cycle": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/misc/header-include-cycle.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:LOW" ], "misc-inaccurate-erase": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-inaccurate-erase.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "misc-include-cleaner": [ @@ -7768,92 +6764,66 @@ "misc-incorrect-roundings": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-incorrect-roundings.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "misc-inefficient-algorithm": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-inefficient-algorithm.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "misc-lambda-function-name": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-lambda-function-name.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:LOW" ], "misc-macro-parentheses": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-macro-parentheses.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "misc-macro-repeated-side-effects": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-macro-repeated-side-effects.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "misc-misleading-bidirectional": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/misc/misleading-bidirectional.html", - "guideline:owasp-top-10-2025", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "owasp-top-10-2025:owasp-A05-2025", + "rule:owasp-A05-2025", "severity:HIGH" ], "misc-misleading-identifier": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/misc/misleading-identifier.html", - "guideline:owasp-top-10-2025", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "owasp-top-10-2025:owasp-A05-2025", + "rule:owasp-A05-2025", "severity:HIGH" ], "misc-misplaced-const": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/misc/misplaced-const.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:LOW" ], "misc-misplaced-widening-cast": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-misplaced-widening-cast.html", "profile:default", - "profile:extreme", "profile:portability", - "profile:sensitive", "severity:HIGH" ], "misc-move-const-arg": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-move-const-arg.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "misc-move-constructor-init": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-move-constructor-init.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "misc-move-forwarding-reference": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-move-forwarding-reference.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "misc-multiple-inheritance": [ @@ -7862,18 +6832,14 @@ ], "misc-multiple-statement-macro": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-multiple-statement-macro.html", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], "misc-new-delete-overloads": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/misc/new-delete-overloads.html", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:dcl54-cpp", + "rule:dcl54-cpp", "severity:MEDIUM" ], "misc-no-recursion": [ @@ -7887,14 +6853,9 @@ ], "misc-non-copyable-objects": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/misc/non-copyable-objects.html", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:fio38-c", - "sei-cert-cpp:fio38-c", + "rule:fio38-c", "severity:HIGH" ], "misc-non-private-member-variables-in-classes": [ @@ -7905,51 +6866,34 @@ "misc-override-with-different-visibility": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/misc/override-with-different-visibility.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "misc-predictable-rand": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/misc/predictable-rand.html", - "guideline:owasp-top-10-2021", - "guideline:owasp-top-10-2025", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "guideline:cwe-vulnerabilities", - "profile:extreme", - "profile:security", "profile:sensitive", - "cwe-vulnerabilities:cwe-338", - "owasp-top-10-2021:owasp-A02-2021", - "owasp-top-10-2025:owasp-A04-2025", - "sei-cert-c:msc30-c", - "sei-cert-cpp:msc50-cpp", + "profile:security", + "rule:cwe-338", + "rule:owasp-A02-2021", + "rule:owasp-A04-2025", + "rule:msc30-c", + "rule:msc50-cpp", "severity:MEDIUM" ], "misc-redundant-expression": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/misc/redundant-expression.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "misc-sizeof-container": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-sizeof-container.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "misc-sizeof-expression": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-sizeof-expression.html", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:arr39-c", - "sei-cert-cpp:arr39-c", + "rule:arr39-c", "severity:HIGH" ], "misc-static-assert": [ @@ -7964,80 +6908,58 @@ "misc-string-compare": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-string-compare.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:LOW" ], "misc-string-constructor": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-string-constructor.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "misc-string-integer-assignment": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-string-integer-assignment.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], "misc-string-literal-with-embedded-nul": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-string-literal-with-embedded-nul.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "misc-suspicious-enum-usage": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-suspicious-enum-usage.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "misc-suspicious-missing-comma": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-suspicious-missing-comma.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "misc-suspicious-semicolon": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-suspicious-semicolon.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "misc-suspicious-string-compare": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-suspicious-string-compare.html", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], "misc-swapped-arguments": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-swapped-arguments.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "misc-throw-by-value-catch-by-reference": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/misc/throw-by-value-catch-by-reference.html", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:err09-cpp", - "sei-cert-cpp:err61-cpp", + "rule:err61-cpp", "severity:HIGH" ], "misc-unconventional-assign-operator": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/misc/unconventional-assign-operator.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "misc-undelegated-constructor": [ @@ -8048,13 +6970,10 @@ "misc-uniqueptr-reset-release": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/misc/uniqueptr-reset-release.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "misc-unused-alias-decls": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/misc/unused-alias-decls.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], @@ -8066,29 +6985,22 @@ "misc-unused-raii": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-unused-raii.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "misc-unused-using-decls": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/misc/unused-using-decls.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], "misc-use-after-move": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-use-after-move.html", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:exp63-cpp", + "rule:exp63-cpp", "severity:HIGH" ], "misc-use-anonymous-namespace": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/misc/use-anonymous-namespace.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], @@ -8100,8 +7012,6 @@ "misc-virtual-near-miss": [ "doc_url:https://releases.llvm.org/6.0.1/tools/clang/tools/extra/docs/clang-tidy/checks/misc-virtual-near-miss.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "modernize-avoid-bind": [ @@ -8134,7 +7044,6 @@ ], "modernize-deprecated-headers": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/modernize/deprecated-headers.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], @@ -8166,8 +7075,6 @@ "modernize-min-max-use-initializer-list": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/modernize/min-max-use-initializer-list.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:LOW" ], "modernize-pass-by-value": [ @@ -8187,7 +7094,6 @@ ], "modernize-replace-auto-ptr": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/modernize/replace-auto-ptr.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], @@ -8198,7 +7104,6 @@ ], "modernize-replace-random-shuffle": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/modernize/replace-random-shuffle.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], @@ -8234,7 +7139,6 @@ ], "modernize-use-constraints": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/modernize/use-constraints.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], @@ -8353,13 +7257,11 @@ ], "mpi-buffer-deref": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/mpi/buffer-deref.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], "mpi-type-mismatch": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/mpi/type-mismatch.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], @@ -8398,13 +7300,11 @@ ], "performance-avoid-endl": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/performance/avoid-endl.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], "performance-enum-size": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/performance/enum-size.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], @@ -8414,135 +7314,106 @@ ], "performance-faster-string-find": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/performance/faster-string-find.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], "performance-for-range-copy": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/performance/for-range-copy.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], "performance-implicit-cast-in-loop": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/performance/implicit-cast-in-loop.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], "performance-implicit-conversion-in-loop": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/performance/implicit-conversion-in-loop.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], "performance-inefficient-algorithm": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/performance/inefficient-algorithm.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "performance-inefficient-string-concatenation": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/performance/inefficient-string-concatenation.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], "performance-inefficient-vector-operation": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/performance/inefficient-vector-operation.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], "performance-move-const-arg": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/performance/move-const-arg.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "performance-move-constructor-init": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/performance/move-constructor-init.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "performance-no-automatic-move": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/performance/no-automatic-move.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:LOW" ], "performance-no-int-to-ptr": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/performance/no-int-to-ptr.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], "performance-noexcept-destructor": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/performance/noexcept-destructor.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "performance-noexcept-move-constructor": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/performance/noexcept-move-constructor.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "performance-noexcept-swap": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/performance/noexcept-swap.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "performance-prefer-single-char-overloads": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/performance/prefer-single-char-overloads.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], "performance-string-view-conversions": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/performance/string-view-conversions.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], "performance-trivially-destructible": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/performance/trivially-destructible.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:LOW" ], "performance-type-promotion-in-math-fn": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/performance/type-promotion-in-math-fn.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], "performance-unnecessary-copy-initialization": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/performance/unnecessary-copy-initialization.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], "performance-unnecessary-value-param": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/performance/unnecessary-value-param.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], "performance-use-std-move": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/performance/use-std-move.html", - "profile:extreme", "profile:sensitive", "severity:LOW" ], @@ -8570,7 +7441,6 @@ ], "portability-template-virtual-member-function": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/portability/template-virtual-member-function.html", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -8606,15 +7476,11 @@ "readability-container-contains": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/readability/container-contains.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:STYLE" ], "readability-container-data-pointer": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/readability/container-data-pointer.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:STYLE" ], "readability-container-size-empty": [ @@ -8643,13 +7509,9 @@ ], "readability-enum-initial-value": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/readability/enum-initial-value.html", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "profile:extreme", - "profile:security", "profile:sensitive", - "sei-cert-c:int09-c", - "sei-cert-cpp:int09-c", + "profile:security", + "rule:int09-c", "severity:LOW" ], "readability-function-cognitive-complexity": [ @@ -8764,7 +7626,6 @@ ], "readability-redundant-parentheses": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/readability/redundant-parentheses.html", - "profile:extreme", "profile:sensitive", "severity:STYLE" ], @@ -8801,8 +7662,6 @@ "readability-reference-to-constructed-temporary": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/readability/reference-to-constructed-temporary.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:STYLE" ], "readability-simplify-boolean-expr": [ @@ -8828,8 +7687,6 @@ "readability-suspicious-call-argument": [ "doc_url:https://clang.llvm.org/extra/clang-tidy/checks/readability/suspicious-call-argument.html", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:LOW" ], "readability-trailing-comma": [ diff --git a/config/labels/analyzers/clangsa.json b/config/labels/analyzers/clangsa.json index 05ec7930c2..4d87f4af3a 100644 --- a/config/labels/analyzers/clangsa.json +++ b/config/labels/analyzers/clangsa.json @@ -261,449 +261,251 @@ ], "core.BitwiseShift": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#core-bitwiseshift-c-c", - "guideline:cwe-top-25-2024", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "guideline:cwe-vulnerabilities", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-top-25-2024:cwe-190", - "sei-cert-c:int32-c", - "sei-cert-c:int34-c", - "sei-cert-cpp:int32-c", - "sei-cert-cpp:int34-c", - "cwe-vulnerabilities:cwe-190", + "rule:cwe-190", + "rule:int32-c", + "rule:int34-c", "severity:HIGH" ], "core.CallAndMessage": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#core-callandmessage-c-c-objc", - "guideline:cwe-top-25-2024", - "guideline:owasp-top-10-2025", - "guideline:memory-safety", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-top-25-2024:cwe-476", - "cwe-vulnerabilities:cwe-476", - "cwe-top-25-2025:cwe-476", - "owasp-top-10-2025:owasp-A10-2025", - "memory-safety:cwe-476", - "sei-cert-c:dcl41-c", - "sei-cert-c:exp30-c", - "sei-cert-c:exp33-c", - "sei-cert-c:exp34-c", - "sei-cert-c:exp39-c", - "sei-cert-cpp:exp50-cpp", - "sei-cert-cpp:exp53-cpp", - "sei-cert-cpp:exp54-cpp", + "rule:cwe-476", + "rule:owasp-A10-2025", + "rule:dcl41-c", + "rule:exp30-c", + "rule:exp33-c", + "rule:exp34-c", + "rule:exp39-c", + "rule:exp50-cpp", + "rule:exp53-cpp", + "rule:exp54-cpp", "severity:HIGH" ], "core.CallAndMessageModeling": [ - "profile:default", - "profile:extreme", - "profile:sensitive" + "profile:default" ], "core.DivideZero": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#core-dividezero-c-c-objc", - "guideline:owasp-top-10-2025", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "guideline:cwe-vulnerabilities", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-vulnerabilities:cwe-369", - "owasp-top-10-2025:owasp-A10-2025", - "sei-cert-c:int33-c", - "sei-cert-cpp:int33-c", + "rule:cwe-369", + "rule:owasp-A10-2025", + "rule:int33-c", "severity:HIGH" ], "core.DynamicTypePropagation": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "core.FixedAddressDereference": [ - "cwe-top-25-2024:cwe-119", "doc_url:https://releases.llvm.org/22.1.0/tools/clang/docs/analyzer/checkers.html#core-fixedaddressdereference-c-c-objc", - "guideline:cwe-top-25-2024", - "guideline:cwe-vulnerabilities", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-vulnerabilities:cwe-119", + "rule:cwe-119", "severity:HIGH" ], "core.NonNullParamChecker": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#core-nonnullparamchecker-c-c-objc", - "guideline:cwe-top-25-2024", - "guideline:owasp-top-10-2025", - "guideline:memory-safety", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-top-25-2024:cwe-476", - "cwe-vulnerabilities:cwe-476", - "cwe-top-25-2025:cwe-476", - "owasp-top-10-2025:owasp-A10-2025", - "memory-safety:cwe-476", - "sei-cert-c:exp34-c", - "sei-cert-cpp:exp34-c", + "rule:cwe-476", + "rule:owasp-A10-2025", + "rule:exp34-c", "severity:HIGH" ], "core.NonnilStringConstants": [ - "profile:default", - "profile:extreme", - "profile:sensitive" + "profile:default" ], "core.NullDereference": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#core-nulldereference-c-c-objc", - "guideline:cwe-top-25-2024", - "guideline:memory-safety", - "guideline:owasp-top-10-2025", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-top-25-2024:cwe-476", - "cwe-vulnerabilities:cwe-476", - "cwe-top-25-2025:cwe-476", - "memory-safety:cwe-476", - "owasp-top-10-2025:owasp-A10-2025", - "sei-cert-c:exp34-c", - "sei-cert-cpp:exp34-c", + "rule:cwe-476", + "rule:owasp-A10-2025", + "rule:exp34-c", "severity:HIGH" ], "core.NullPointerArithm": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#core-nullpointerarithm-c-c", - "guideline:cwe-top-25-2024", - "guideline:memory-safety", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-top-25-2024:cwe-476", - "cwe-vulnerabilities:cwe-476", - "cwe-top-25-2025:cwe-476", - "memory-safety:cwe-476", - "sei-cert-c:arr30-c", - "sei-cert-c:exp34-c", - "sei-cert-cpp:exp34-c", - "sei-cert-cpp:arr30-c", - "sei-cert-cpp:exp34-c", + "rule:cwe-476", + "rule:arr30-c", + "rule:exp34-c", "severity:HIGH" ], "core.StackAddrEscapeBase": [ - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:dcl30-c", - "sei-cert-cpp:exp54-cpp", - "sei-cert-cpp:exp61-cpp" + "rule:dcl30-c", + "rule:exp54-cpp", + "rule:exp61-cpp" ], "core.StackAddressEscape": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#core-stackaddressescape-c", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:dcl30-c", - "sei-cert-cpp:exp54-cpp", - "sei-cert-cpp:exp61-cpp", - "memory-safety:cwe-123", - "memory-safety:cwe-562", - "cwe-vulnerabilities:cwe-123", - "cwe-vulnerabilities:cwe-562", + "rule:dcl30-c", + "rule:exp54-cpp", + "rule:exp61-cpp", + "rule:cwe-123", + "rule:cwe-562", "severity:HIGH" ], "core.UndefinedBinaryOperatorResult": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#core-undefinedbinaryoperatorresult-c", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:exp33-c", - "sei-cert-cpp:exp50-cpp", + "rule:exp33-c", + "rule:exp50-cpp", "severity:HIGH" ], "core.VLASize": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#core-vlasize-c", - "guideline:cwe-top-25-2024", - "guideline:sei-cert-c", - "guideline:cwe-vulnerabilities", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-top-25-2024:cwe-119", - "sei-cert-c:arr32-c", - "cwe-vulnerabilities:cwe-119", + "rule:cwe-119", + "rule:arr32-c", "severity:HIGH" ], "core.builtin.BuiltinFunctions": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "core.builtin.NoReturnFunctions": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "core.uninitialized.ArraySubscript": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#core-uninitialized-arraysubscript-c", - "guideline:cwe-top-25-2024", - "guideline:sei-cert-c", - "guideline:cwe-vulnerabilities", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-top-25-2024:cwe-119", - "sei-cert-c:exp33-c", - "cwe-vulnerabilities:cwe-119", + "rule:cwe-119", + "rule:exp33-c", "severity:HIGH" ], "core.uninitialized.Assign": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#core-uninitialized-assign-c", - "guideline:sei-cert-c", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:exp33-c", + "rule:exp33-c", "severity:HIGH" ], "core.uninitialized.Branch": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#core-uninitialized-branch-c", - "guideline:sei-cert-c", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:exp33-c", + "rule:exp33-c", "severity:HIGH" ], "core.uninitialized.CapturedBlockVariable": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#core-uninitialized-capturedblockvariable-c", - "guideline:sei-cert-c", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:exp33-c", + "rule:exp33-c", "severity:HIGH" ], "core.uninitialized.NewArraySize": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#core-uninitialized-newarraysize-c", - "guideline:cwe-top-25-2024", - "guideline:sei-cert-c", - "guideline:cwe-vulnerabilities", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-top-25-2024:cwe-119", - "sei-cert-c:exp33-c", - "cwe-vulnerabilities:cwe-119", + "rule:cwe-119", + "rule:exp33-c", "severity:HIGH" ], "core.uninitialized.UndefReturn": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#core-uninitialized-undefreturn-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:oop53-cpp", + "rule:oop53-cpp", "severity:HIGH" ], "cplusplus.ArrayDelete": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#cplusplus-arraydelete-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:exp51-cpp", + "rule:exp51-cpp", "severity:HIGH" ], "cplusplus.InnerPointer": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#cplusplus-innerpointer-c", - "guideline:cwe-top-25-2024", - "guideline:memory-safety", - "guideline:sei-cert-cpp", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-top-25-2024:cwe-416", - "memory-safety:cwe-416", - "sei-cert-cpp:mem50-cpp", - "sei-cert-cpp:str52-cpp", - "cwe-vulnerabilities:cwe-416", - "cwe-top-25-2025:cwe-416", + "rule:cwe-416", + "rule:mem50-cpp", + "rule:str52-cpp", "severity:HIGH" ], "cplusplus.Move": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#cplusplus-move-c", - "guideline:cwe-top-25-2024", - "guideline:memory-safety", - "guideline:sei-cert-cpp", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-top-25-2024:cwe-416", - "memory-safety:cwe-416", - "sei-cert-cpp:exp63-cpp", - "cwe-vulnerabilities:cwe-416", - "cwe-top-25-2025:cwe-416", + "rule:cwe-416", + "rule:exp63-cpp", "severity:HIGH" ], "cplusplus.NewDelete": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#cplusplus-newdelete-c", - "guideline:cwe-top-25-2024", - "guideline:sei-cert-cpp", - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-top-25-2024:cwe-416", - "sei-cert-cpp:exp54-cpp", - "sei-cert-cpp:mem50-cpp", - "sei-cert-cpp:mem51-cpp", - "sei-cert-cpp:oop54-cpp", - "memory-safety:cwe-415", - "memory-safety:cwe-416", - "memory-safety:cwe-590", - "cwe-vulnerabilities:cwe-415", - "cwe-vulnerabilities:cwe-416", - "cwe-top-25-2025:cwe-416", - "cwe-vulnerabilities:cwe-590", + "rule:cwe-416", + "rule:exp54-cpp", + "rule:mem50-cpp", + "rule:mem51-cpp", + "rule:oop54-cpp", + "rule:cwe-415", + "rule:cwe-590", "severity:HIGH" ], "cplusplus.NewDeleteLeaks": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#cplusplus-newdeleteleaks-c", - "guideline:sei-cert-cpp", - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:mem51-cpp", - "memory-safety:cwe-401", - "cwe-vulnerabilities:cwe-401", + "rule:mem51-cpp", + "rule:cwe-401", "severity:HIGH" ], "cplusplus.PlacementNew": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#cplusplus-placementnew-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:mem54-cpp", + "rule:mem54-cpp", "severity:HIGH" ], "cplusplus.PureVirtualCall": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cplusplus.SelfAssignment": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#cplusplus-selfassignment-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:oop54-cpp", + "rule:oop54-cpp", "severity:MEDIUM" ], "cplusplus.SmartPtrModeling": [ - "profile:default", - "profile:extreme", - "profile:sensitive" + "profile:default" ], "cplusplus.StringChecker": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#cplusplus-stringchecker-c", - "guideline:cwe-top-25-2024", - "guideline:memory-safety", - "guideline:sei-cert-cpp", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-top-25-2024:cwe-119", - "cwe-top-25-2024:cwe-476", - "memory-safety:cwe-476", - "sei-cert-cpp:str51-cpp", - "cwe-vulnerabilities:cwe-119", - "cwe-vulnerabilities:cwe-476", - "cwe-top-25-2025:cwe-476", + "rule:cwe-119", + "rule:cwe-476", + "rule:str51-cpp", "severity:HIGH" ], "cplusplus.VirtualCallModeling": [ - "profile:default", - "profile:extreme", - "profile:sensitive" + "profile:default" ], "deadcode.DeadStores": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#deadcode-deadstores-c", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:msc12-c", - "sei-cert-cpp:msc12-c", + "rule:msc12-c", "severity:LOW" ], "debug.AnalysisOrder": [ @@ -761,128 +563,68 @@ ], "nullability.NullPassedToNonnull": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#nullability-nullpassedtononnull-objc", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", "profile:default", - "profile:extreme", - "profile:sensitive", - "cwe-vulnerabilities:cwe-476", - "cwe-top-25-2025:cwe-476", - "sei-cert-c:exp34-c", - "sei-cert-cpp:exp34-c", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", + "rule:cwe-476", "severity:HIGH" ], "nullability.NullReturnedFromNonnull": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#nullability-nullreturnedfromnonnull-c-c-objc", - "guideline:cwe-top-25-2024", - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", "profile:default", - "profile:extreme", - "profile:sensitive", - "cwe-top-25-2024:cwe-476", - "cwe-vulnerabilities:cwe-476", - "cwe-top-25-2025:cwe-476", - "memory-safety:cwe-476", - "severity:HIGH", - "sei-cert-c:exp34-c", - "sei-cert-cpp:exp34-c", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp" + "rule:cwe-476", + "severity:HIGH" ], "nullability.NullabilityBase": [ - "profile:extreme", - "profile:sensitive", - "sei-cert-c:exp34-c", - "sei-cert-cpp:exp34-c", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp" + "profile:sensitive" ], "nullability.NullableDereferenced": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#nullability-nullabledereferenced-objc", - "profile:extreme", "profile:sensitive", - "severity:MEDIUM", - "sei-cert-c:exp34-c", - "sei-cert-cpp:exp34-c", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp" + "severity:MEDIUM" ], "nullability.NullablePassedToNonnull": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#nullability-nullablepassedtononnull-objc", - "profile:extreme", "profile:sensitive", - "severity:MEDIUM", - "sei-cert-c:exp34-c", - "sei-cert-cpp:exp34-c", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp" + "severity:MEDIUM" ], "nullability.NullableReturnedFromNonnull": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#nullability-nullablereturnedfromnonnull-objc", - "profile:extreme", "profile:sensitive", - "severity:MEDIUM", - "sei-cert-c:exp34-c", - "sei-cert-cpp:exp34-c", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp" + "severity:MEDIUM" ], "optin.core.EnumCastOutOfRange": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#optin-core-enumcastoutofrange-c-c", - "guideline:sei-cert-cpp", - "profile:extreme", - "profile:security", "profile:sensitive", - "sei-cert-cpp:mem54-cpp", + "profile:security", + "rule:mem54-cpp", "severity:MEDIUM" ], "optin.core.FixedAddressDereference": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#optin-core-fixedaddressdereference-c-c-objc", - "guideline:cwe-top-25-2024", - "guideline:cwe-vulnerabilities", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-top-25-2024:cwe-119", - "cwe-vulnerabilities:cwe-119", + "rule:cwe-119", "severity:HIGH" ], "optin.core.UnconditionalVAArg": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#optin-core-unconditionalvaarg", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", - "profile:sensitive", - "sei-cert-c:exp47-c", - "sei-cert-cpp:exp47-c", + "rule:exp47-c", "severity:MEDIUM" ], "optin.cplusplus.UninitializedObject": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#optin-cplusplus-uninitializedobject-c", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "optin.cplusplus.VirtualCall": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#optin-cplusplus-virtualcall-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:oop50-cpp", + "rule:oop50-cpp", "severity:MEDIUM" ], "optin.mpi.MPI-Checker": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#optin-mpi-mpi-checker-c", - "profile:extreme", "profile:sensitive", "severity:MEDIUM" ], @@ -908,90 +650,53 @@ ], "optin.portability.UnixAPI": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#optin-portability-unixapi", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:portability", "profile:security", - "profile:sensitive", - "sei-cert-c:mem30-c", - "sei-cert-cpp:mem30-c", + "rule:mem30-c", "severity:MEDIUM" ], "optin.taint.GenericTaint": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#optin-taint-generictaint-c-c", - "guideline:cwe-top-25-2024", - "guideline:owasp-top-10-2021", - "guideline:owasp-top-10-2025", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", - "profile:extreme", "profile:sensitive", - "cwe-top-25-2024:cwe-20", - "cwe-top-25-2024:cwe-22", - "cwe-top-25-2024:cwe-77", - "cwe-top-25-2024:cwe-78", - "cwe-top-25-2024:cwe-79", - "cwe-top-25-2024:cwe-89", - "cwe-top-25-2024:cwe-94", - "cwe-vulnerabilities:cwe-78", - "cwe-top-25-2025:cwe-78", - "cwe-vulnerabilities:cwe-20", - "cwe-top-25-2025:cwe-20", - "cwe-vulnerabilities:cwe-22", - "cwe-top-25-2025:cwe-22", - "cwe-vulnerabilities:cwe-77", - "cwe-top-25-2025:cwe-77", - "cwe-vulnerabilities:cwe-79", - "cwe-top-25-2025:cwe-79", - "cwe-vulnerabilities:cwe-89", - "cwe-top-25-2025:cwe-89", - "cwe-vulnerabilities:cwe-94", - "cwe-top-25-2025:cwe-94", - "cwe-vulnerabilities:cwe-120", - "cwe-top-25-2025:cwe-120", - "owasp-top-10-2021:owasp-A01-2021", - "owasp-top-10-2021:owasp-A03-2021", - "owasp-top-10-2021:owasp-A04-2021", - "owasp-top-10-2021:owasp-A08-2021", - "owasp-top-10-2021:owasp-A10-2021", - "owasp-top-10-2025:owasp-A01-2025", - "owasp-top-10-2025:owasp-A05-2025", + "rule:cwe-20", + "rule:cwe-22", + "rule:cwe-77", + "rule:cwe-78", + "rule:cwe-79", + "rule:cwe-89", + "rule:cwe-94", + "rule:cwe-120", + "rule:owasp-A01-2021", + "rule:owasp-A03-2021", + "rule:owasp-A04-2021", + "rule:owasp-A08-2021", + "rule:owasp-A10-2021", + "rule:owasp-A01-2025", + "rule:owasp-A05-2025", "severity:HIGH" ], "optin.taint.TaintPropagation": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#optin-taint-generictaint-c-c", - "profile:extreme", "profile:sensitive", "severity:HIGH" ], "optin.taint.TaintedAlloc": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#optin-taint-taintedalloc-c-c", - "guideline:memory-safety", - "guideline:owasp-top-10-2021", - "guideline:owasp-top-10-2025", - "guideline:cwe-vulnerabilities", - "profile:extreme", "profile:sensitive", - "memory-safety:cwe-789", - "owasp-top-10-2021:owasp-A03-2021", - "owasp-top-10-2025:owasp-A01-2025", - "owasp-top-10-2025:owasp-A05-2025", - "cwe-vulnerabilities:cwe-789", + "rule:cwe-789", + "rule:owasp-A03-2021", + "rule:owasp-A01-2025", + "rule:owasp-A05-2025", "severity:HIGH" ], "optin.taint.TaintedDiv": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#optin-taint-tainteddiv-c-c-objc", - "guideline:owasp-top-10-2021", - "guideline:owasp-top-10-2025", - "guideline:cwe-vulnerabilities", - "profile:extreme", "profile:sensitive", - "cwe-vulnerabilities:cwe-369", - "owasp-top-10-2021:owasp-A03-2021", - "owasp-top-10-2025:owasp-A01-2025", - "owasp-top-10-2025:owasp-A05-2025", + "rule:cwe-369", + "rule:owasp-A03-2021", + "rule:owasp-A01-2025", + "rule:owasp-A05-2025", "severity:HIGH" ], "osx.API": [ @@ -1081,132 +786,78 @@ ], "security.ArrayBound": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#security-arraybound-c-c", - "guideline:cwe-top-25-2024", - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-top-25-2024:cwe-119", - "cwe-top-25-2024:cwe-125", - "cwe-top-25-2024:cwe-787", - "cwe-vulnerabilities:cwe-129", - "cwe-vulnerabilities:cwe-119", - "cwe-vulnerabilities:cwe-121", - "cwe-top-25-2025:cwe-121", - "cwe-vulnerabilities:cwe-122", - "cwe-top-25-2025:cwe-122", - "cwe-vulnerabilities:cwe-124", - "cwe-vulnerabilities:cwe-125", - "cwe-top-25-2025:cwe-125", - "cwe-vulnerabilities:cwe-126", - "cwe-vulnerabilities:cwe-127", - "cwe-vulnerabilities:cwe-787", - "cwe-top-25-2025:cwe-787", - "cwe-vulnerabilities:cwe-120", - "cwe-top-25-2025:cwe-120", - "memory-safety:cwe-121", - "memory-safety:cwe-122", - "memory-safety:cwe-124", - "memory-safety:cwe-126", - "memory-safety:cwe-127", + "rule:cwe-119", + "rule:cwe-125", + "rule:cwe-787", + "rule:cwe-129", + "rule:cwe-121", + "rule:cwe-122", + "rule:cwe-124", + "rule:cwe-126", + "rule:cwe-127", + "rule:cwe-120", "severity:HIGH" ], "security.FloatLoopCounter": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#security-floatloopcounter-c", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:flp30-c", - "sei-cert-cpp:flp30-c", + "rule:flp30-c", "severity:MEDIUM" ], "security.MmapWriteExec": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#security-mmapwriteexec-c", - "guideline:owasp-top-10-2025", - "guideline:cwe-vulnerabilities", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-vulnerabilities:cwe-732", - "owasp-top-10-2025:owasp-A01-2025", + "rule:cwe-732", + "rule:owasp-A01-2025", "severity:MEDIUM" ], "security.PointerSub": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#security-pointersub-c", - "guideline:cwe-top-25-2024", - "guideline:sei-cert-c", - "guideline:cwe-vulnerabilities", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-top-25-2024:cwe-119", - "sei-cert-c:arr36-c", - "cwe-vulnerabilities:cwe-119", + "rule:cwe-119", + "rule:arr36-c", "severity:HIGH" ], "security.PutenvStackArray": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#security-putenvstackarray-c", - "guideline:sei-cert-c", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:pos34-c", + "rule:pos34-c", "severity:HIGH" ], "security.SetgidSetuidOrder": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#security-setgidsetuidorder-c", - "guideline:owasp-top-10-2021", - "guideline:owasp-top-10-2025", - "guideline:sei-cert-c", - "guideline:cwe-vulnerabilities", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-vulnerabilities:cwe-269", - "owasp-top-10-2021:owasp-A04-2021", - "owasp-top-10-2025:owasp-A06-2025", - "sei-cert-c:pos36-c", + "rule:cwe-269", + "rule:owasp-A04-2021", + "rule:owasp-A06-2025", + "rule:pos36-c", "severity:MEDIUM" ], "security.VAList": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#security-valist", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", "severity:HIGH" ], "security.cert.env.InvalidPtr": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#security-cert-env-invalidptr", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:env31-c", - "sei-cert-c:env34-c", - "sei-cert-cpp:env31-c", - "sei-cert-cpp:env34-c", + "rule:env31-c", + "rule:env34-c", "severity:MEDIUM" ], "security.insecureAPI.DeprecatedOrUnsafeBufferHandling": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#security-insecureapi-deprecatedorunsafebufferhandling-c", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", "profile:extreme", - "cwe-vulnerabilities:cwe-120", - "cwe-top-25-2025:cwe-120", + "rule:cwe-120", "severity:MEDIUM" ], "security.insecureAPI.SecuritySyntaxChecker": [ @@ -1214,13 +865,9 @@ ], "security.insecureAPI.UncheckedReturn": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#security-insecureapi-uncheckedreturn-c", - "guideline:owasp-top-10-2025", - "guideline:cwe-vulnerabilities", "profile:default", - "profile:extreme", - "profile:sensitive", - "cwe-vulnerabilities:cwe-252", - "owasp-top-10-2025:owasp-A10-2025", + "rule:cwe-252", + "rule:owasp-A10-2025", "severity:MEDIUM" ], "security.insecureAPI.bcmp": [ @@ -1244,362 +891,195 @@ "security.insecureAPI.getpw": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#security-insecureapi-getpw-c", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "security.insecureAPI.gets": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#security-insecureapi-gets-c", - "guideline:cwe-top-25-2024", - "guideline:owasp-top-10-2025", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-top-25-2024:cwe-119", - "cwe-top-25-2024:cwe-125", - "cwe-top-25-2024:cwe-787", - "cwe-vulnerabilities:cwe-676", - "cwe-vulnerabilities:cwe-119", - "cwe-vulnerabilities:cwe-125", - "cwe-top-25-2025:cwe-125", - "cwe-vulnerabilities:cwe-787", - "cwe-top-25-2025:cwe-787", - "cwe-vulnerabilities:cwe-120", - "cwe-top-25-2025:cwe-120", - "owasp-top-10-2025:owasp-A06-2025", - "sei-cert-c:str31-c", - "sei-cert-cpp:str31-c", + "rule:cwe-119", + "rule:cwe-125", + "rule:cwe-787", + "rule:cwe-676", + "rule:cwe-120", + "rule:owasp-A06-2025", + "rule:str31-c", "severity:MEDIUM" ], "security.insecureAPI.mkstemp": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#security-insecureapi-mkstemp-c", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "security.insecureAPI.mktemp": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#security-insecureapi-mktemp-c", - "guideline:owasp-top-10-2021", - "guideline:owasp-top-10-2025", - "guideline:cwe-vulnerabilities", "profile:default", - "profile:extreme", - "profile:sensitive", - "cwe-vulnerabilities:cwe-377", - "owasp-top-10-2021:owasp-A01-2021", - "owasp-top-10-2025:owasp-A01-2025", + "rule:cwe-377", + "rule:owasp-A01-2021", + "rule:owasp-A01-2025", "severity:MEDIUM" ], "security.insecureAPI.rand": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#security-insecureapi-rand-c", - "guideline:owasp-top-10-2021", - "guideline:owasp-top-10-2025", - "guideline:cwe-vulnerabilities", "profile:default", - "profile:extreme", - "profile:sensitive", - "cwe-vulnerabilities:cwe-338", - "owasp-top-10-2021:owasp-A02-2021", - "owasp-top-10-2025:owasp-A04-2025", + "rule:cwe-338", + "rule:owasp-A02-2021", + "rule:owasp-A04-2025", "severity:MEDIUM" ], "security.insecureAPI.strcpy": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#security-insecureapi-strcpy-c", - "guideline:cwe-top-25-2024", - "guideline:owasp-top-10-2025", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", - "profile:extreme", - "profile:security", "profile:sensitive", - "cwe-top-25-2024:cwe-119", - "cwe-top-25-2024:cwe-125", - "cwe-top-25-2024:cwe-787", - "owasp-top-10-2025:owasp-A06-2025", - "sei-cert-c:str31-c", - "sei-cert-cpp:str31-c", - "cwe-vulnerabilities:cwe-119", - "cwe-vulnerabilities:cwe-125", - "cwe-top-25-2025:cwe-125", - "cwe-vulnerabilities:cwe-787", - "cwe-top-25-2025:cwe-787", - "cwe-vulnerabilities:cwe-120", - "cwe-top-25-2025:cwe-120", + "profile:security", + "rule:cwe-119", + "rule:cwe-125", + "rule:cwe-787", + "rule:owasp-A06-2025", + "rule:str31-c", + "rule:cwe-120", "severity:MEDIUM" ], "security.insecureAPI.vfork": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#security-insecureapi-vfork-c", - "guideline:sei-cert-c", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:pos33-c", "severity:MEDIUM" ], "unix.API": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#unix-api-c", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:exp37-c", - "sei-cert-cpp:exp37-c", + "rule:exp37-c", "severity:MEDIUM" ], "unix.BlockInCriticalSection": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#unix-blockincriticalsection-c-c", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:LOW" ], "unix.Chroot": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#unix-chroot-c", "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "unix.DynamicMemoryModeling": [ - "profile:default", - "profile:extreme", - "profile:sensitive" + "profile:default" ], "unix.Errno": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#unix-errno-c", - "guideline:owasp-top-10-2025", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "profile:extreme", - "profile:security", "profile:sensitive", - "owasp-top-10-2025:owasp-A10-2025", - "sei-cert-c:err30-c", - "sei-cert-cpp:err30-c", + "profile:security", + "rule:owasp-A10-2025", + "rule:err30-c", "severity:HIGH" ], "unix.Malloc": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#unix-malloc-c", - "guideline:cwe-top-25-2024", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-top-25-2024:cwe-20", - "cwe-top-25-2024:cwe-400", - "cwe-top-25-2024:cwe-416", - "sei-cert-c:mem30-c", - "sei-cert-c:mem31-c", - "sei-cert-c:mem34-c", - "sei-cert-c:mem35-c", - "sei-cert-c:mem36-c", - "sei-cert-cpp:mem30-c", - "sei-cert-cpp:mem31-c", - "sei-cert-cpp:mem34-c", - "sei-cert-cpp:mem35-c", - "sei-cert-cpp:mem36-c", - "memory-safety:cwe-401", - "memory-safety:cwe-415", - "memory-safety:cwe-416", - "memory-safety:cwe-590", - "cwe-vulnerabilities:cwe-20", - "cwe-top-25-2025:cwe-20", - "cwe-vulnerabilities:cwe-400", - "cwe-vulnerabilities:cwe-401", - "cwe-vulnerabilities:cwe-415", - "cwe-vulnerabilities:cwe-416", - "cwe-top-25-2025:cwe-416", - "cwe-vulnerabilities:cwe-590", + "rule:cwe-20", + "rule:cwe-400", + "rule:cwe-416", + "rule:mem30-c", + "rule:mem31-c", + "rule:mem34-c", + "rule:mem35-c", + "rule:mem36-c", + "rule:cwe-401", + "rule:cwe-415", + "rule:cwe-590", "severity:MEDIUM" ], "unix.MallocSizeof": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#unix-mallocsizeof-c", - "guideline:cwe-top-25-2024", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "guideline:cwe-vulnerabilities", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-top-25-2024:cwe-190", - "sei-cert-c:mem35-c", - "sei-cert-cpp:mem35-c", - "cwe-vulnerabilities:cwe-190", + "rule:cwe-190", + "rule:mem35-c", "severity:MEDIUM" ], "unix.MismatchedDeallocator": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#unix-mismatcheddeallocator-c-c", - "guideline:sei-cert-cpp", - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-cpp:mem51-cpp", - "memory-safety:cwe-762", - "cwe-vulnerabilities:cwe-762", + "rule:mem51-cpp", + "rule:cwe-762", "severity:MEDIUM" ], "unix.StdCLibraryFunctions": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#unix-stdclibraryfunctions-c", - "guideline:cwe-top-25-2024", - "guideline:memory-safety", - "guideline:sei-cert-c", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-top-25-2024:cwe-119", - "cwe-top-25-2024:cwe-125", - "cwe-top-25-2024:cwe-476", - "cwe-top-25-2024:cwe-787", - "memory-safety:cwe-476", - "sei-cert-c:arr38-c", - "sei-cert-c:err33-c", - "sei-cert-c:pos52-c", - "cwe-vulnerabilities:cwe-119", - "cwe-vulnerabilities:cwe-125", - "cwe-top-25-2025:cwe-125", - "cwe-vulnerabilities:cwe-476", - "cwe-top-25-2025:cwe-476", - "cwe-vulnerabilities:cwe-787", - "cwe-top-25-2025:cwe-787", + "rule:cwe-119", + "rule:cwe-125", + "rule:cwe-476", + "rule:cwe-787", + "rule:arr38-c", + "rule:err33-c", + "rule:pos52-c", "severity:HIGH" ], "unix.Stream": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#unix-stream-c", - "guideline:cwe-top-25-2024", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "guideline:cwe-vulnerabilities", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-top-25-2024:cwe-400", - "sei-cert-c:fio42-c", - "sei-cert-cpp:fio42-c", - "cwe-vulnerabilities:cwe-400", + "rule:cwe-400", + "rule:fio42-c", "severity:MEDIUM" ], "unix.Vfork": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#unix-vfork-c", - "guideline:sei-cert-c", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:pos33-c", "severity:MEDIUM" ], "unix.cstring.BadSizeArg": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#unix-cstring-badsizearg-c", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-vulnerabilities:cwe-120", - "cwe-top-25-2025:cwe-120", - "sei-cert-c:str31-c", - "sei-cert-cpp:str31-c", + "rule:cwe-120", + "rule:str31-c", "severity:MEDIUM" ], "unix.cstring.CStringModeling": [ - "profile:default", - "profile:extreme", - "profile:sensitive" + "profile:default" ], "unix.cstring.NotNullTerminated": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#unix-cstring-notnullterminated-c", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", "profile:default", - "profile:extreme", - "profile:sensitive", - "cwe-vulnerabilities:cwe-120", - "cwe-top-25-2025:cwe-120", - "sei-cert-c:str31-c", - "sei-cert-cpp:str31-c", + "rule:cwe-120", + "rule:str31-c", "severity:HIGH" ], "unix.cstring.NullArg": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#unix-cstring-nullarg-c", - "guideline:cwe-top-25-2024", - "guideline:memory-safety", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "guideline:cwe-vulnerabilities", - "guideline:cwe-top-25-2025", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "cwe-top-25-2024:cwe-476", - "memory-safety:cwe-476", - "sei-cert-c:exp34-c", - "sei-cert-cpp:exp34-c", - "cwe-vulnerabilities:cwe-476", - "cwe-top-25-2025:cwe-476", + "rule:cwe-476", + "rule:exp34-c", "severity:HIGH" ], "unix.cstring.UninitializedRead": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#unix-cstring-uninitializedread-c", - "guideline:sei-cert-c", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "sei-cert-c:exp33-c", + "rule:exp33-c", "severity:HIGH" ], "valist.CopyToSelf": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "valist.Uninitialized": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "valist.Unterminated": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "valist.ValistBase": [ - "profile:default", - "profile:extreme", - "profile:sensitive" + "profile:default" ], "webkit.NoUncountedMemberChecker": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#webkit-nouncountedmemberchecker", diff --git a/config/labels/analyzers/cppcheck.json b/config/labels/analyzers/cppcheck.json index 560e0fd06b..0ae8854831 100644 --- a/config/labels/analyzers/cppcheck.json +++ b/config/labels/analyzers/cppcheck.json @@ -18,71 +18,47 @@ "severity:LOW" ], "cppcheck-IOWithoutPositioning": [ - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "severity:HIGH", - "sei-cert-c:fio39-c" + "rule:fio39-c", + "severity:HIGH" ], "cppcheck-StlMissingComparison": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-UnionZeroInit": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-accessForwarded": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-accessMoved": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-algorithmOutOfBounds": [ - "guideline:sei-cert-cpp", - "sei-cert-cpp:ctr50-cpp", + "rule:ctr50-cpp", "severity:HIGH" ], "cppcheck-argumentSize": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-arithOperationsOnVoidPointer": [ "severity:LOW" ], "cppcheck-arrayIndexOutOfBounds": [ - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "memory-safety:cwe-121", - "memory-safety:cwe-122", - "memory-safety:cwe-126", - "cwe-vulnerabilities:cwe-121", - "cwe-vulnerabilities:cwe-122", - "cwe-vulnerabilities:cwe-126", - "severity:HIGH", - "sei-cert-c:arr30-c" + "rule:cwe-121", + "rule:cwe-122", + "rule:cwe-126", + "rule:arr30-c", + "severity:HIGH" ], "cppcheck-arrayIndexOutOfBoundsCond": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-arrayIndexThenCheck": [ @@ -90,8 +66,6 @@ ], "cppcheck-assertWithSideEffect": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-assignBoolToFloat": [ @@ -99,8 +73,6 @@ ], "cppcheck-assignBoolToPointer": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-assignIfError": [ @@ -108,37 +80,24 @@ ], "cppcheck-assignmentInAssert": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-assignmentInCondition": [ "severity:STYLE" ], "cppcheck-autoVariables": [ - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "severity:HIGH", - "sei-cert-c:dcl30-c" + "rule:dcl30-c", + "severity:HIGH" ], "cppcheck-autovarInvalidDeallocation": [ - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "memory-safety:cwe-590", - "cwe-vulnerabilities:cwe-590", - "severity:HIGH", - "sei-cert-c:mem34-c" + "rule:cwe-590", + "rule:mem34-c", + "severity:HIGH" ], "cppcheck-badBitmaskCheck": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-bitwiseOnBoolean": [ @@ -146,43 +105,28 @@ ], "cppcheck-boostForeachError": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-bufferAccessOutOfBounds": [ - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "memory-safety:cwe-121", - "memory-safety:cwe-122", - "cwe-vulnerabilities:cwe-121", - "cwe-vulnerabilities:cwe-122", - "severity:HIGH", - "sei-cert-c:arr30-c" + "rule:cwe-121", + "rule:cwe-122", + "rule:arr30-c", + "severity:HIGH" ], "cppcheck-catchExceptionByValue": [ "severity:STYLE" ], "cppcheck-charBitOp": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-charLiteralWithCharPtrCompare": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-checkCastIntToCharAndBack": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-checkLevelNormal": [ @@ -196,8 +140,6 @@ ], "cppcheck-clarifyStatement": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-class_X_Y": [ @@ -208,20 +150,15 @@ ], "cppcheck-compareBoolExpressionWithInt": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-comparePointers": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-subtractPointers": [ - "guideline:sei-cert-c", - "severity:HIGH", - "sei-cert-c:arr36-c" + "rule:arr36-c", + "severity:HIGH" ], "cppcheck-compareValueOutOfTypeRangeError": [ "severity:STYLE" @@ -231,8 +168,6 @@ ], "cppcheck-comparisonFunctionIsAlwaysTrueOrFalse": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-comparisonOfBoolWithBoolError": [ @@ -240,8 +175,6 @@ ], "cppcheck-comparisonOfBoolWithInvalidComparator": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-comparisonOfFuncReturningBoolError": [ @@ -264,8 +197,6 @@ ], "cppcheck-constStatement": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-constVariable": [ @@ -278,36 +209,25 @@ "severity:STYLE" ], "cppcheck-containerOutOfBounds": [ - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "severity:HIGH", - "sei-cert-c:ctr50-cpp", - "sei-cert-c:str53-cpp" + "rule:ctr50-cpp", + "rule:str53-cpp", + "severity:HIGH" ], "cppcheck-containerOutOfBoundsIndexExpression": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-copyCtorAndEqOperator": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-copyCtorPointerCopying": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-coutCerrMisusage": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-cppcheckLimit": [ @@ -317,104 +237,64 @@ "severity:STYLE" ], "cppcheck-ctunullpointer": [ - "cwe-top-25-2024:cwe-476", - "guideline:cwe-top-25-2024", - "guideline:memory-safety", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "guideline:cwe-vulnerabilities", - "memory-safety:cwe-476", "profile:security", - "sei-cert-c:exp34-c", - "sei-cert-cpp:exp34-c", - "cwe-vulnerabilities:cwe-476", + "rule:cwe-476", + "rule:exp34-c", "severity:HIGH" ], "cppcheck-dangerousTypeCast": [ "severity:MEDIUM" ], "cppcheck-danglingLifetime": [ - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "severity:HIGH", - "sei-cert-c:dcl30-c" + "rule:dcl30-c", + "severity:HIGH" ], "cppcheck-danglingReference": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-danglingTempReference": [ "severity:HIGH" ], "cppcheck-danglingTemporaryLifetime": [ - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "severity:HIGH", - "sei-cert-c:exp54-cpp", - "sei-cert-c:mem50-cpp" + "rule:exp54-cpp", + "rule:mem50-cpp", + "severity:HIGH" ], "cppcheck-deallocDealloc": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-deallocret": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-deallocuse": [ - "guideline:cwe-top-25-2024", - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "cwe-top-25-2024:cwe-416", - "memory-safety:cwe-416", - "cwe-vulnerabilities:cwe-416", - "severity:HIGH", - "sei-cert-c:mem30-c", - "sei-cert-c:mem50-cpp" + "rule:cwe-416", + "rule:mem30-c", + "rule:mem50-cpp", + "severity:HIGH" ], "cppcheck-derefInvalidIterator": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-divideSizeof": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-doubleFree": [ - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "memory-safety:cwe-415", - "cwe-vulnerabilities:cwe-415", - "severity:HIGH", - "sei-cert-c:mem36-c", - "sei-cert-c:mem56-cpp" + "rule:cwe-415", + "rule:mem36-c", + "rule:mem56-cpp", + "severity:HIGH" ], "cppcheck-duplInheritedMember": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-duplicateAssignExpression": [ @@ -443,8 +323,6 @@ ], "cppcheck-eraseDereference": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-eraseIteratorOutOfBounds": [ @@ -455,8 +333,6 @@ ], "cppcheck-exceptDeallocThrow": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-exceptRethrowCopy": [ @@ -464,19 +340,14 @@ ], "cppcheck-exceptThrowInDestructor": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-throwInEntryPoint": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-fcloseInLoopCondition": [ - "guideline:sei-cert-c", - "sei-cert-c:fio46-c", + "rule:fio46-c", "severity:HIGH" ], "cppcheck-fflushOnInputStream": [ @@ -484,8 +355,6 @@ ], "cppcheck-floatConversionOverflow": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-funcArgNamesDifferent": [ @@ -493,8 +362,6 @@ ], "cppcheck-funcArgOrderDifferent": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-functionConst": [ @@ -508,26 +375,18 @@ ], "cppcheck-identicalConditionAfterEarlyExit": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-identicalInnerCondition": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-ignoredReturnErrorCode": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-ignoredReturnValue": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-includeNestedTooDeeply": [ @@ -535,38 +394,26 @@ ], "cppcheck-incompatibleFileOpen": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-incompleteArrayFill": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-incorrectCharBooleanError": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-incorrectLogicOperator": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-incorrectStringBooleanError": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-incorrectStringCompare": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-incrementboolean": [ @@ -582,12 +429,9 @@ "severity:LOW" ], "cppcheck-integerOverflow": [ - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "severity:HIGH", - "sei-cert-c:int32-c" + "rule:int32-c", + "severity:HIGH" ], "cppcheck-internalAstError": [ "severity:CRITICAL" @@ -599,139 +443,93 @@ "severity:LOW" ], "cppcheck-invalidContainer": [ - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "severity:HIGH", - "sei-cert-c:str52-cpp" + "rule:str52-cpp", + "severity:HIGH" ], "cppcheck-invalidContainerLoop": [ "severity:HIGH" ], "cppcheck-invalidContainerReference": [ - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", "profile:default", - "profile:extreme", - "profile:sensitive", - "memory-safety:cwe-664", - "cwe-vulnerabilities:cwe-664", + "rule:cwe-664", "severity:HIGH" ], "cppcheck-invalidFree": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-invalidFunctionArg": [ - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "severity:HIGH", - "sei-cert-c:flp32-c" + "rule:flp32-c", + "severity:HIGH" ], "cppcheck-invalidFunctionArgBool": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-invalidFunctionArgStr": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-invalidIterator1": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-invalidLengthModifierError": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-invalidLifetime": [ - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "severity:HIGH", - "sei-cert-c:mem50-cpp" + "rule:mem50-cpp", + "severity:HIGH" ], "cppcheck-invalidPointerCast": [ "severity:MEDIUM" ], "cppcheck-invalidPrintfArgType_float": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-invalidPrintfArgType_n": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-invalidPrintfArgType_p": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-invalidPrintfArgType_s": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-invalidPrintfArgType_sint": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-invalidPrintfArgType_uint": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-invalidScanfArgType_float": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-invalidScanfArgType_int": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-invalidScanfArgType_s": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-invalidScanfFormatWidth": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-invalidScanfFormatWidth_smaller": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-invalidSuppression": [ @@ -739,44 +537,30 @@ ], "cppcheck-invalidTestForOverflow": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-invalidscanf": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-iterators1": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-iterators2": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-iterators3": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-iteratorsCmp1": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-iteratorsCmp2": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-knownArgument": [ @@ -796,33 +580,24 @@ ], "cppcheck-leakNoVarFunctionCall": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-leakReturnValNotUsed": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-leakUnsafeArgAlloc": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-legacyUninitvar": [ - "guideline:sei-cert-c", "profile:security", - "severity:HIGH", - "sei-cert-c:exp33-c", - "sei-cert-c:exp53-cpp" + "rule:exp33-c", + "rule:exp53-cpp", + "severity:HIGH" ], "cppcheck-literalWithCharPtrCompare": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-localMutex": [ @@ -833,47 +608,32 @@ ], "cppcheck-mallocOnClassError": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-mallocOnClassWarning": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-memleak": [ - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "severity:HIGH", - "sei-cert-c:mem31-c" + "rule:mem31-c", + "severity:HIGH" ], "cppcheck-memleakOnRealloc": [ - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "severity:HIGH", - "sei-cert-c:err33-c" + "rule:err33-c", + "severity:HIGH" ], "cppcheck-memsetClass": [ - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "severity:HIGH", - "sei-cert-c:exp62-cpp" + "rule:exp62-cpp", + "severity:HIGH" ], "cppcheck-memsetClassFloat": [ "severity:LOW" ], "cppcheck-memsetClassReference": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-memsetFloat": [ @@ -881,32 +641,20 @@ ], "cppcheck-memsetValueOutOfRange": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-memsetZeroBytes": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-mismatchAllocDealloc": [ - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "memory-safety:cwe-762", - "cwe-vulnerabilities:cwe-762", - "severity:HIGH", - "sei-cert-c:mem51-cpp" + "rule:cwe-762", + "rule:mem51-cpp", + "severity:HIGH" ], "cppcheck-mismatchSize": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-mismatchingBitAnd": [ @@ -914,8 +662,6 @@ ], "cppcheck-mismatchingContainerExpression": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-mismatchingContainerIterator": [ @@ -923,8 +669,6 @@ ], "cppcheck-mismatchingContainers": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-missingFile": [ @@ -941,26 +685,19 @@ ], "cppcheck-missingMemberCopy": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-missingOverride": [ "severity:STYLE" ], "cppcheck-missingReturn": [ - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "severity:HIGH", - "sei-cert-c:msc37-c", - "sei-cert-c:msc52-cpp" + "rule:msc37-c", + "rule:msc52-cpp", + "severity:HIGH" ], "cppcheck-moduloAlwaysTrueFalse": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-moduloofone": [ @@ -971,8 +708,6 @@ ], "cppcheck-multiplySizeof": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-nanInArithmeticExpression": [ @@ -980,34 +715,21 @@ ], "cppcheck-negativeArraySize": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-negativeContainerIndex": [ - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "severity:MEDIUM", - "sei-cert-c:ctr50-cpp" + "rule:ctr50-cpp", + "severity:MEDIUM" ], "cppcheck-negativeIndex": [ - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", "profile:default", - "profile:extreme", - "profile:sensitive", - "memory-safety:cwe-124", - "memory-safety:cwe-127", - "cwe-vulnerabilities:cwe-124", - "cwe-vulnerabilities:cwe-127", + "rule:cwe-124", + "rule:cwe-127", "severity:HIGH" ], "cppcheck-negativeMemoryAllocationSize": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-noConstructor": [ @@ -1015,14 +737,10 @@ ], "cppcheck-noCopyConstructor": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-noDestructor": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-noExplicitConstructor": [ @@ -1030,84 +748,55 @@ ], "cppcheck-noOperatorEq": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-nonStandardCharLiteral": [ "severity:LOW" ], "cppcheck-nullPointer": [ - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "severity:HIGH", - "sei-cert-c:exp34-c" + "rule:exp34-c", + "severity:HIGH" ], "cppcheck-nullPointerArithmetic": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-nullPointerArithmeticRedundantCheck": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-nullPointerDefaultArg": [ - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "severity:MEDIUM", - "sei-cert-c:err33-c" + "rule:err33-c", + "severity:MEDIUM" ], "cppcheck-nullPointerArithmeticOutOfMemory": [ - "guideline:sei-cert-c", - "severity:MEDIUM", - "sei-cert-c:err33-c" + "rule:err33-c", + "severity:MEDIUM" ], "cppcheck-nullPointerOutOfMemory": [ - "guideline:sei-cert-c", - "profile:extreme", "profile:sensitive", - "severity:MEDIUM", - "sei-cert-c:err33-c", - "sei-cert-c:exp34-c", - "sei-cert-c:mem52-cpp" + "rule:err33-c", + "rule:exp34-c", + "rule:mem52-cpp", + "severity:MEDIUM" ], "cppcheck-nullPointerOutOfResources": [ - "guideline:sei-cert-c", - "profile:extreme", "profile:sensitive", - "severity:MEDIUM", - "sei-cert-c:err33-c", - "sei-cert-c:exp34-c", - "guideline:sei-cert-c" + "rule:err33-c", + "severity:MEDIUM" ], "cppcheck-nullPointerRedundantCheck": [ "profile:default", - "profile:extreme", - "profile:sensitive", - "severity:MEDIUM", - "sei-cert-c:exp34-c", - "sei-cert-cpp:exp34-c", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp" + "severity:MEDIUM" ], "cppcheck-objectIndex": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-operatorEqMissingReturnStatement": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-operatorEqRetRefThis": [ @@ -1118,14 +807,10 @@ ], "cppcheck-operatorEqToSelf": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-operatorEqVarError": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-oppositeExpression": [ @@ -1133,32 +818,22 @@ ], "cppcheck-oppositeInnerCondition": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-overlappingInnerCondition": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-overlappingStrcmp": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-overlappingWriteFunction": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-overlappingWriteUnion": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-passedByValue": [ @@ -1166,14 +841,10 @@ ], "cppcheck-pointerAdditionResultNotNull": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-pointerArithBool": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-pointerLessThanZero": [ @@ -1190,8 +861,6 @@ ], "cppcheck-pointerSize": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-postfixOperator": [ @@ -1202,14 +871,10 @@ ], "cppcheck-publicAllocationError": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-pureVirtualCall": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-purgedConfiguration": [ @@ -1217,14 +882,10 @@ ], "cppcheck-raceAfterInterlockedDecrement": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-readWriteOnlyFile": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-reademptycontainer": [ @@ -1232,8 +893,6 @@ ], "cppcheck-redundantAssignInSwitch": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:STYLE" ], "cppcheck-redundantAssignment": [ @@ -1241,8 +900,6 @@ ], "cppcheck-redundantBitwiseOperationInSwitch": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:STYLE" ], "cppcheck-redundantCondition": [ @@ -1250,8 +907,6 @@ ], "cppcheck-redundantContinue": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:LOW" ], "cppcheck-redundantCopy": [ @@ -1259,8 +914,6 @@ ], "cppcheck-redundantCopyInSwitch": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:STYLE" ], "cppcheck-redundantCopyLocalConst": [ @@ -1276,52 +929,35 @@ "severity:STYLE" ], "cppcheck-resourceLeak": [ - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "severity:HIGH", - "sei-cert-c:fio42-c" + "rule:fio42-c", + "severity:HIGH" ], "cppcheck-rethrowNoCurrentException": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-returnAddressOfAutoVariable": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-returnAddressOfFunctionParameter": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-returnByReference": [ "severity:LOW" ], "cppcheck-returnDanglingLifetime": [ - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "memory-safety:cwe-562", - "cwe-vulnerabilities:cwe-562", - "severity:HIGH", - "sei-cert-c:dcl30-c", - "sei-cert-c:exp54-cpp", - "sei-cert-c:exp61-cpp" + "rule:cwe-562", + "rule:dcl30-c", + "rule:exp54-cpp", + "rule:exp61-cpp", + "severity:HIGH" ], "cppcheck-returnLocalVariable": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-returnNonBoolInBooleanFunction": [ @@ -1329,8 +965,6 @@ ], "cppcheck-returnReference": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-returnStdMoveLocal": [ @@ -1338,8 +972,6 @@ ], "cppcheck-returnTempReference": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-sameIteratorExpression": [ @@ -1347,20 +979,14 @@ ], "cppcheck-seekOnAppendedFile": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-selfAssignment": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-selfInitialization": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-shadowArgument": [ @@ -1376,46 +1002,32 @@ "severity:STYLE" ], "cppcheck-shiftNegative": [ - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "severity:HIGH", - "sei-cert-c:int34-c" + "rule:int34-c", + "severity:HIGH" ], "cppcheck-shiftNegativeLHS": [ "severity:MEDIUM" ], "cppcheck-shiftTooManyBits": [ - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "severity:HIGH", - "sei-cert-c:int34-c" + "rule:int34-c", + "severity:HIGH" ], "cppcheck-shiftTooManyBitsSigned": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-signConversion": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-signedCharArrayIndex": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-sizeofCalculation": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-sizeofDereferencedVoidPointer": [ @@ -1423,14 +1035,10 @@ ], "cppcheck-sizeofDivisionMemfunc": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-sizeofFunctionCall": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-sizeofVoid": [ @@ -1438,26 +1046,18 @@ ], "cppcheck-sizeofsizeof": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-sizeofwithnumericparameter": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-sizeofwithsilentarraypointer": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-sprintfOverlappingData": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-staticFunction": [ @@ -1465,14 +1065,10 @@ ], "cppcheck-staticStringCompare": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-stlBoundaries": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-stlFindInsert": [ @@ -1480,8 +1076,6 @@ ], "cppcheck-stlIfFind": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-stlIfStrFind": [ @@ -1489,8 +1083,6 @@ ], "cppcheck-stlOutOfBounds": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-stlSize": [ @@ -1498,26 +1090,18 @@ ], "cppcheck-stlcstr": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-stlcstrAssignment": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-stlcstrConcat": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-stlcstrConstructor": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-stlcstrParam": [ @@ -1528,40 +1112,27 @@ ], "cppcheck-stlcstrStream": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-stlcstrthrow": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-strPlusChar": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-stringCompare": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-stringLiteralWrite": [ - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "severity:HIGH", - "sei-cert-c:str30-c" + "rule:str30-c", + "severity:HIGH" ], "cppcheck-suspiciousCase": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-suspiciousFloatingPointCast": [ @@ -1569,34 +1140,21 @@ ], "cppcheck-suspiciousSemicolon": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-syntaxError": [ - "guideline:sei-cert-c", - "severity:CRITICAL", - "sei-cert-c:pre32-c" + "rule:pre32-c", + "severity:CRITICAL" ], "cppcheck-terminateStrncpy": [ - "guideline:memory-safety", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp", - "guideline:cwe-vulnerabilities", "profile:default", - "profile:extreme", "profile:security", - "profile:sensitive", - "memory-safety:cwe-170", - "sei-cert-c:str32-c", - "sei-cert-cpp:str32-c", - "cwe-vulnerabilities:cwe-170", + "rule:cwe-170", + "rule:str32-c", "severity:HIGH" ], "cppcheck-thisSubtraction": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-thisUseAfterFree": [ @@ -1604,8 +1162,6 @@ ], "cppcheck-throwInNoexceptFunction": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-toomanyconfigs": [ @@ -1628,69 +1184,45 @@ ], "cppcheck-uninitDerivedMemberVar": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-uninitDerivedMemberVarPrivate": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-uninitMemberVar": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-uninitMemberVarPrivate": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-uninitStructMember": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-uninitdata": [ - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "severity:HIGH", - "sei-cert-c:exp53-cpp", - "sei-cert-c:mem53-cpp" + "rule:exp53-cpp", + "rule:mem53-cpp", + "severity:HIGH" ], "cppcheck-uninitstring": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-uninitvar": [ - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "memory-safety:cwe-457", - "cwe-vulnerabilities:cwe-457", - "severity:HIGH", - "sei-cert-c:exp33-c" + "rule:cwe-457", + "rule:exp33-c", + "severity:HIGH" ], "cppcheck-unknownEvaluationOrder": [ - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "severity:HIGH", - "sei-cert-c:exp30-c", - "sei-cert-c:exp50-cpp" + "rule:exp30-c", + "rule:exp50-cpp", + "severity:HIGH" ], "cppcheck-unknownMacro": [ "severity:CRITICAL" @@ -1712,8 +1244,6 @@ ], "cppcheck-unsafeClassRefMember": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-unsignedLessThanZero": [ @@ -1736,8 +1266,6 @@ ], "cppcheck-unusedLabelSwitch": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-unusedLabelSwitchConfiguration": [ @@ -1757,8 +1285,6 @@ ], "cppcheck-useClosedFile": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-useInitializationList": [ @@ -1775,32 +1301,22 @@ ], "cppcheck-uselessAssignmentPtrArg": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-uselessCallsCompare": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-uselessCallsConstructor": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-uselessCallsEmpty": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-uselessCallsRemove": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-uselessCallsSubstr": [ @@ -1814,34 +1330,23 @@ ], "cppcheck-va_end_missing": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-va_list_usedBeforeStarted": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-va_start_referencePassed": [ - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "severity:HIGH", - "sei-cert-c:exp58-cpp" + "rule:exp58-cpp", + "severity:HIGH" ], "cppcheck-va_start_subsequentCalls": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-va_start_wrongParameter": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-varFuncNullUB": [ @@ -1852,40 +1357,27 @@ ], "cppcheck-virtualCallInConstructor": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:STYLE" ], "cppcheck-virtualDestructor": [ - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "severity:HIGH", - "sei-cert-c:oop52-cpp" + "rule:oop52-cpp", + "severity:HIGH" ], "cppcheck-writeReadOnlyFile": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-wrongPipeParameterSize": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-wrongPrintfScanfArgNum": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:HIGH" ], "cppcheck-wrongPrintfScanfParameterPositionError": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-wrongfeofUsage": [ @@ -1893,22 +1385,15 @@ ], "cppcheck-wrongmathcall": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ], "cppcheck-zerodiv": [ - "guideline:sei-cert-c", "profile:default", - "profile:extreme", - "profile:sensitive", - "severity:HIGH", - "sei-cert-c:int33-c" + "rule:int33-c", + "severity:HIGH" ], "cppcheck-zerodivcond": [ "profile:default", - "profile:extreme", - "profile:sensitive", "severity:MEDIUM" ] } diff --git a/config/labels/analyzers/gcc.json b/config/labels/analyzers/gcc.json index 440a978d6e..1da9d95861 100644 --- a/config/labels/analyzers/gcc.json +++ b/config/labels/analyzers/gcc.json @@ -3,39 +3,30 @@ "labels": { "gcc-analyzer-allocation-size": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-allocation-size", - "guideline:sei-cert-c", "profile:extreme", - "severity:HIGH", - "sei-cert-c:exp36-c", - "sei-cert-c:mem35-c", - "sei-cert-c:mem54-cpp" + "rule:exp36-c", + "rule:mem35-c", + "rule:mem54-cpp", + "severity:HIGH" ], "gcc-analyzer-deref-before-check": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-deref-before-check", - "guideline:sei-cert-c", "profile:extreme", - "severity:MEDIUM", - "sei-cert-c:exp34-c", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp" + "rule:exp34-c", + "severity:MEDIUM" ], "gcc-analyzer-double-fclose": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-double-fclose", - "guideline:sei-cert-c", "profile:extreme", - "severity:HIGH", - "sei-cert-c:fio42-c" + "rule:fio42-c", + "severity:HIGH" ], "gcc-analyzer-double-free": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-double-free", - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "guideline:sei-cert-c", "profile:extreme", - "memory-safety:cwe-415", - "cwe-vulnerabilities:cwe-415", - "severity:HIGH", - "sei-cert-c:mem30-c" + "rule:cwe-415", + "rule:mem30-c", + "severity:HIGH" ], "gcc-analyzer-exposure-through-output-file": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-exposure-through-output-file", @@ -59,11 +50,10 @@ ], "gcc-analyzer-fd-leak": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-fd-leak", - "guideline:sei-cert-c", "profile:extreme", - "severity:HIGH", - "sei-cert-c:pos35-c", - "sei-cert-c:pos38-c" + "rule:pos35-c", + "rule:pos38-c", + "severity:HIGH" ], "gcc-analyzer-fd-phase-mismatch": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-fd-phase-mismatch", @@ -77,37 +67,30 @@ ], "gcc-analyzer-fd-use-after-close": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-fd-use-after-close", - "guideline:sei-cert-c", "profile:extreme", - "severity:HIGH", - "sei-cert-c:pos35-c" + "rule:pos35-c", + "severity:HIGH" ], "gcc-analyzer-fd-use-without-check": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-fd-use-without-check", - "guideline:sei-cert-c", "profile:extreme", - "severity:MEDIUM", - "sei-cert-c:pos35-c", - "sei-cert-c:pos38-c" + "rule:pos35-c", + "rule:pos38-c", + "severity:MEDIUM" ], "gcc-analyzer-file-leak": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-file-leak", - "guideline:sei-cert-c", "profile:extreme", - "severity:HIGH", - "sei-cert-c:fio42-c" + "rule:fio42-c", + "severity:HIGH" ], "gcc-analyzer-free-of-non-heap": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-free-of-non-heap", - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "guideline:sei-cert-c", "profile:extreme", - "memory-safety:cwe-590", - "cwe-vulnerabilities:cwe-590", - "severity:HIGH", - "sei-cert-c:mem34-c", - "sei-cert-c:mem51-cpp" + "rule:cwe-590", + "rule:mem34-c", + "rule:mem51-cpp", + "severity:HIGH" ], "gcc-analyzer-imprecise-fp-arithmetic": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-imprecise-fp-arithmetic", @@ -121,133 +104,94 @@ ], "gcc-analyzer-jump-through-null": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-jump-through-null", - "guideline:sei-cert-c", "profile:extreme", - "severity:HIGH", - "sei-cert-c:oop55-cpp" + "rule:oop55-cpp", + "severity:HIGH" ], "gcc-analyzer-malloc-leak": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-malloc-leak", - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "guideline:sei-cert-c", - "profile:extreme", - "memory-safety:cwe-401", - "memory-safety:cwe-761", - "cwe-vulnerabilities:cwe-401", - "cwe-vulnerabilities:cwe-761", - "severity:HIGH", - "sei-cert-c:err57-cpp", - "sei-cert-c:fio42-c", - "sei-cert-c:mem31-c" + "profile:extreme", + "rule:cwe-401", + "rule:cwe-761", + "rule:err57-cpp", + "rule:fio42-c", + "rule:mem31-c", + "severity:HIGH" ], "gcc-analyzer-mismatching-deallocation": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-mismatching-deallocation", - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "guideline:sei-cert-c", "profile:extreme", - "memory-safety:cwe-762", - "cwe-vulnerabilities:cwe-762", - "severity:HIGH", - "sei-cert-c:exp51-cpp", - "sei-cert-c:mem51-cpp", - "sei-cert-c:mem57-cpp" + "rule:cwe-762", + "rule:exp51-cpp", + "rule:mem51-cpp", + "rule:mem57-cpp", + "severity:HIGH" ], "gcc-analyzer-null-argument": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-null-argument", - "guideline:sei-cert-c", "profile:extreme", - "severity:HIGH", - "sei-cert-c:err33-c", - "sei-cert-c:exp34-c", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp" + "rule:err33-c", + "rule:exp34-c", + "severity:HIGH" ], "gcc-analyzer-null-dereference": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-null-dereference", - "guideline:cwe-top-25-2024", - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "guideline:sei-cert-c", - "profile:extreme", - "cwe-top-25-2024:cwe-476", - "memory-safety:cwe-476", - "cwe-vulnerabilities:cwe-476", - "severity:HIGH", - "sei-cert-c:exp34-c", - "sei-cert-cpp:exp34-c", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp" + "profile:extreme", + "rule:cwe-476", + "rule:exp34-c", + "severity:HIGH" ], "gcc-analyzer-out-of-bounds": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-out-of-bounds", - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "guideline:sei-cert-c", - "profile:extreme", - "memory-safety:cwe-121", - "memory-safety:cwe-122", - "memory-safety:cwe-124", - "memory-safety:cwe-126", - "memory-safety:cwe-127", - "memory-safety:cwe-843", - "cwe-vulnerabilities:cwe-121", - "cwe-vulnerabilities:cwe-122", - "cwe-vulnerabilities:cwe-124", - "cwe-vulnerabilities:cwe-126", - "cwe-vulnerabilities:cwe-127", - "cwe-vulnerabilities:cwe-843", - "severity:HIGH", - "sei-cert-c:arr30-c", - "sei-cert-c:arr38-c", - "sei-cert-c:arr39-c", - "sei-cert-c:exp36-c", - "sei-cert-c:int10-c", - "sei-cert-c:mem33-c", - "sei-cert-c:mem35-c", - "sei-cert-c:mem54-cpp", - "sei-cert-c:oop55-cpp" + "profile:extreme", + "rule:cwe-121", + "rule:cwe-122", + "rule:cwe-124", + "rule:cwe-126", + "rule:cwe-127", + "rule:cwe-843", + "rule:arr30-c", + "rule:arr38-c", + "rule:arr39-c", + "rule:exp36-c", + "rule:int10-c", + "rule:mem33-c", + "rule:mem35-c", + "rule:mem54-cpp", + "rule:oop55-cpp", + "severity:HIGH" ], "gcc-analyzer-possible-null-argument": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-possible-null-argument", - "guideline:sei-cert-c", "profile:extreme", - "severity:MEDIUM", - "sei-cert-c:pos54-c", - "sei-cert-c:err33-c" + "rule:pos54-c", + "rule:err33-c", + "severity:MEDIUM" ], "gcc-analyzer-possible-null-dereference": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-possible-null-dereference", - "guideline:sei-cert-c", "profile:extreme", - "severity:MEDIUM", - "sei-cert-c:exp34-c", - "sei-cert-cpp:exp34-c", - "sei-cert-c:err33-c", - "guideline:sei-cert-c", - "guideline:sei-cert-cpp" + "rule:exp34-c", + "rule:err33-c", + "severity:MEDIUM" ], "gcc-analyzer-putenv-of-auto-var": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-putenv-of-auto-var", - "guideline:sei-cert-c", "profile:extreme", - "severity:HIGH", - "sei-cert-c:pos34-c" + "rule:pos34-c", + "severity:HIGH" ], "gcc-analyzer-shift-count-negative": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-shift-count-negative", - "guideline:sei-cert-c", "profile:extreme", - "severity:HIGH", - "sei-cert-c:int34-c" + "rule:int34-c", + "severity:HIGH" ], "gcc-analyzer-shift-count-overflow": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-shift-count-overflow", - "guideline:sei-cert-c", "profile:extreme", - "severity:HIGH", - "sei-cert-c:int34-c" + "rule:int34-c", + "severity:HIGH" ], "gcc-analyzer-stale-setjmp-buffer": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-stale-setjmp-buffer", @@ -286,66 +230,54 @@ ], "gcc-analyzer-unsafe-call-within-signal-handler": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-unsafe-call-within-signal-handler", - "guideline:sei-cert-c", "profile:extreme", - "severity:HIGH", - "sei-cert-c:sig30-c" + "rule:sig30-c", + "severity:HIGH" ], "gcc-analyzer-use-after-free": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-use-after-free", - "guideline:cwe-top-25-2024", - "guideline:memory-safety", - "guideline:cwe-vulnerabilities", - "guideline:sei-cert-c", "profile:extreme", - "cwe-top-25-2024:cwe-416", - "memory-safety:cwe-416", - "cwe-vulnerabilities:cwe-416", - "severity:HIGH", - "sei-cert-c:mem30-c" + "rule:cwe-416", + "rule:mem30-c", + "severity:HIGH" ], "gcc-analyzer-use-of-pointer-in-stale-stack-frame": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-use-of-pointer-in-stale-stack-frame", - "guideline:sei-cert-c", "profile:extreme", - "severity:HIGH", - "sei-cert-c:dcl30-c", - "sei-cert-c:exp61-cpp" + "rule:dcl30-c", + "rule:exp61-cpp", + "severity:HIGH" ], "gcc-analyzer-use-of-uninitialized-value": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-use-of-uninitialized-value", - "guideline:sei-cert-c", "profile:extreme", - "severity:HIGH", - "sei-cert-c:arr38-c", - "sei-cert-c:dcl41-c", - "sei-cert-c:err56-cpp", - "sei-cert-c:exp33-c", - "sei-cert-c:exp53-cpp", - "sei-cert-c:oop53-cpp", - "sei-cert-c:oop54-cpp" + "rule:arr38-c", + "rule:dcl41-c", + "rule:err56-cpp", + "rule:exp33-c", + "rule:exp53-cpp", + "rule:oop53-cpp", + "rule:oop54-cpp", + "severity:HIGH" ], "gcc-analyzer-va-arg-type-mismatch": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-va-arg-type-mismatch", - "guideline:sei-cert-c", "profile:extreme", - "severity:HIGH", - "sei-cert-c:msc39-c" + "rule:msc39-c", + "severity:HIGH" ], "gcc-analyzer-va-list-exhausted": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-va-list-exhausted", - "guideline:sei-cert-c", "profile:extreme", - "severity:HIGH", - "sei-cert-c:dcl50-cpp", - "sei-cert-c:exp47-c" + "rule:dcl50-cpp", + "rule:exp47-c", + "severity:HIGH" ], "gcc-analyzer-va-list-leak": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-va-list-leak", - "guideline:sei-cert-c", "profile:extreme", - "severity:HIGH", - "sei-cert-c:exp58-cpp" + "rule:exp58-cpp", + "severity:HIGH" ], "gcc-analyzer-va-list-use-after-va-end": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-va-list-use-after-va-end", @@ -354,31 +286,27 @@ ], "gcc-analyzer-write-to-const": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-write-to-const", - "guideline:sei-cert-c", "profile:extreme", - "severity:HIGH", - "sei-cert-c:str30-c" + "rule:str30-c", + "severity:HIGH" ], "gcc-analyzer-write-to-string-literal": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-write-to-string-literal", - "guideline:sei-cert-c", "profile:extreme", - "severity:HIGH", - "sei-cert-c:str30-c" + "rule:str30-c", + "severity:HIGH" ], "gcc-analyzer-infinite-loop": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-infinite-loop", - "guideline:sei-cert-c", "profile:extreme", - "severity:HIGH", - "sei-cert-c:exp45-c" + "rule:exp45-c", + "severity:HIGH" ], "gcc-analyzer-overlapping-buffers": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-overlapping-buffers", - "guideline:sei-cert-c", "profile:extreme", - "severity:HIGH", - "sei-cert-c:exp43-c" + "rule:exp43-c", + "severity:HIGH" ], "gcc-analyzer-symbol-too-complex": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-symbol-too-complex", @@ -387,10 +315,9 @@ ], "gcc-analyzer-throw-of-unexpected-type": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-throw-of-unexpected-type", - "guideline:sei-cert-c", "profile:extreme", - "severity:HIGH", - "sei-cert-c:err55-cpp" + "rule:err55-cpp", + "severity:HIGH" ], "gcc-analyzer-too-complex": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-too-complex", @@ -399,407 +326,506 @@ ], "gcc-analyzer-undefined-behavior-ptrdiff": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-undefined-behavior-ptrdiff", - "guideline:sei-cert-c", "profile:extreme", - "severity:HIGH", - "sei-cert-c:arr36-c" + "rule:arr36-c", + "severity:HIGH" ], "gcc-analyzer-undefined-behavior-strtok": [ "doc_url:https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html#index-Wanalyzer-undefined-behavior-strtok", "profile:extreme", "severity:HIGH" ], - "gcc-NSObject-attribute": [ ], - "gcc-abi": [ "blacklist:true" ], - "gcc-abi-tag": [ "blacklist:true" ], - "gcc-abi=": [ ], - "gcc-absolute-value": [ ], - "gcc-address": [ ], - "gcc-address-of-packed-member": [ ], - "gcc-aggregate-return": [ ], - "gcc-aggressive-loop-optimizations": [ ], - "gcc-aliasing": [ ], - "gcc-align-commons": [ ], - "gcc-aligned-new=[none|global|all]": [ ], - "gcc-all": [ "blacklist:true" ], - "gcc-alloc-size": [ ], - "gcc-alloc-size-larger-than": [ "blacklist:true" ], - "gcc-alloc-zero": [ ], - "gcc-alloca": [ ], - "gcc-alloca-larger-than=": [ "blacklist:true" ], - "gcc-ampersand": [ ], - "gcc-arith-conversion": [ ], - "gcc-array-bounds": [ "blacklist:true" ], - "gcc-array-bounds=<0,2>": [ "blacklist:true" ], - "gcc-array-compare": [ ], - "gcc-array-parameter": [ "blacklist:true" ], - "gcc-array-parameter=<0,2>": [ "blacklist:true" ], - "gcc-array-temporaries": [ ], - "gcc-assign-intercept": [ ], - "gcc-attribute-alias": [ "blacklist:true" ], - "gcc-attribute-alias=<0,2>": [ "blacklist:true"], - "gcc-attribute-warning": [ ], - "gcc-attributes": [ ], - "gcc-bad-function-cast": [ ], - "gcc-bidi-chars": [ "blacklist:true" ], - "gcc-bidi-chars=": [ "blacklist:true" ], - "gcc-bool-compare": [ ], - "gcc-bool-operation": [ ], - "gcc-builtin-declaration-mismatch": [ ], - "gcc-builtin-macro-redefined": [ ], - "gcc-c++-compat": [ ], - "gcc-c++0x-compat": [ "blacklist:true" ], - "gcc-c++11-compat": [ ], - "gcc-c++11-extensions": [ ], - "gcc-c++14-compat": [ ], - "gcc-c++14-extensions": [ ], - "gcc-c++17-compat": [ ], - "gcc-c++17-extensions": [ ], - "gcc-c++1z-compat": [ "blacklist:true" ], - "gcc-c++20-compat": [ ], - "gcc-c++20-extensions": [ ], - "gcc-c++23-extensions": [ ], - "gcc-c++26-extensions": [ ], - "gcc-c++2a-compat": [ "blacklist:true" ], - "gcc-c-binding-type": [ ], - "gcc-c11-c23-compat": [ ], - "gcc-c90-c99-compat": [ ], - "gcc-c99-c11-compat": [ ], - "gcc-calloc-transposed-args": [ ], - "gcc-cannot-profile": [ ], - "gcc-cast-align": [ ], - "gcc-cast-align=strict": [ ], - "gcc-cast-function-type": [ ], - "gcc-cast-qual": [ ], - "gcc-cast-result": [ ], - "gcc-cast-user-defined": [ ], - "gcc-catch-value": [ ], - "gcc-catch-value=<0,3>": [ ], - "gcc-changes-meaning": [ ], - "gcc-char-subscripts": [ ], - "gcc-character-truncation": [ ], - "gcc-chkp": [ "blacklist:true" ], - "gcc-class-conversion": [ ], - "gcc-class-memaccess": [ ], - "gcc-clobbered": [ ], - "gcc-comma-subscript": [ ], - "gcc-comment": [ ], - "gcc-comments": [ "blacklist:true" ], - "gcc-compare-distinct-pointer-types": [ ], - "gcc-compare-reals": [ ], - "gcc-complain-wrong-lang": [ ], - "gcc-conditionally-supported": [ ], - "gcc-conversion": [ ], - "gcc-conversion-extra": [ ], - "gcc-conversion-null": [ ], - "gcc-coverage-invalid-line-number": [ ], - "gcc-coverage-mismatch": [ ], - "gcc-coverage-too-many-conditions": [ ], - "gcc-cpp": [ ], - "gcc-ctad-maybe-unsupported": [ ], - "gcc-ctor-dtor-privacy": [ ], - "gcc-dangling-else": [ ], - "gcc-dangling-pointer": [ "blacklist:true" ], - "gcc-dangling-pointer=<0,2>": [ "blacklist:true" ], - "gcc-dangling-reference": [ ], - "gcc-date-time": [ ], - "gcc-declaration-after-statement": [ ], - "gcc-declaration-missing-parameter-type": [ ], - "gcc-delete-incomplete": [ ], - "gcc-delete-non-virtual-dtor": [ ], - "gcc-deprecated": [ ], - "gcc-deprecated-copy": [ ], - "gcc-deprecated-copy-dtor": [ ], - "gcc-deprecated-declarations": [ ], - "gcc-deprecated-enum-enum-conversion": [ ], - "gcc-deprecated-enum-float-conversion": [ ], - "gcc-designated-init": [ ], - "gcc-disabled-optimization": [ ], - "gcc-discarded-array-qualifiers": [ ], - "gcc-discarded-qualifiers": [ ], - "gcc-div-by-zero": [ ], - "gcc-do-subscript": [ ], - "gcc-double-promotion": [ ], - "gcc-duplicate-decl-specifier": [ ], - "gcc-duplicated-branches": [ ], - "gcc-duplicated-cond": [ ], - "gcc-effc++": [ ], - "gcc-elaborated-enum-base": [ ], - "gcc-empty-body": [ ], - "gcc-endif-labels": [ ], - "gcc-enum-compare": [ ], - "gcc-enum-conversion": [ ], - "gcc-enum-int-mismatch": [ ], - "gcc-error-implicit-function-declaration": [ "blacklist:true" ], - "gcc-exceptions": [ ], - "gcc-expansion-to-defined": [ ], - "gcc-extra": [ ], - "gcc-extra-semi": [ ], - "gcc-flex-array-member-not-at-end": [ ], - "gcc-float-conversion": [ ], - "gcc-float-equal": [ ], - "gcc-format": [ "blacklist:true" ], - "gcc-format-contains-nul": [ ], - "gcc-format-diag": [ ], - "gcc-format-extra-args": [ ], - "gcc-format-nonliteral": [ ], - "gcc-format-overflow<0,2>": [ "blacklist:true" ], - "gcc-format-overflow=<0,2>": [ "blacklist:true" ], - "gcc-format-security": [ ], - "gcc-format-signedness": [ ], - "gcc-format-truncation": [ "blacklist:true" ], - "gcc-format-truncation=<0,2>": [ "blacklist:true" ], - "gcc-format-y2k": [ ], - "gcc-format-zero-length": [ ], - "gcc-format=<0,2>": [ "blacklist:true" ], - "gcc-frame-address": [ ], - "gcc-frame-larger-than=": [ "blacklist:true" ], - "gcc-free-nonheap-object": [ ], - "gcc-function-elimination": [ ], - "gcc-global-module": [ ], - "gcc-hardened": [ ], - "gcc-hsa": [ ], - "gcc-if-not-aligned": [ ], - "gcc-ignored-attributes": [ ], - "gcc-ignored-qualifiers": [ ], - "gcc-implicit": [ ], - "gcc-implicit-fallthrough": [ ], - "gcc-implicit-fallthrough=<0,5>": [ "blacklist:true" ], - "gcc-implicit-function-declaration": [ ], - "gcc-implicit-int": [ ], - "gcc-implicit-interface": [ ], - "gcc-implicit-procedure": [ ], - "gcc-inaccessible-base": [ ], - "gcc-incompatible-pointer-types": [ ], - "gcc-inherited-variadic-ctor": [ ], - "gcc-init-list-lifetime": [ ], - "gcc-init-self": [ ], - "gcc-inline": [ ], - "gcc-int-conversion": [ ], - "gcc-int-in-bool-context": [ ], - "gcc-int-to-pointer-cast": [ ], - "gcc-integer-division": [ ], - "gcc-interference-size": [ ], - "gcc-intrinsic-shadow": [ ], - "gcc-intrinsics-std": [ ], - "gcc-invalid-constexpr": [ ], - "gcc-invalid-imported-macros": [ ], - "gcc-invalid-memory-model": [ ], - "gcc-invalid-offsetof": [ ], - "gcc-invalid-pch": [ ], - "gcc-invalid-utf8": [ ], - "gcc-jump-misses-init": [ ], - "gcc-larger-than-": [ "blacklist:true" ], - "gcc-larger-than=": [ "blacklist:true" ], - "gcc-line-truncation": [ ], - "gcc-literal-suffix": [ ], - "gcc-logical-not-parentheses": [ ], - "gcc-logical-op": [ ], - "gcc-long-long": [ "blacklist:true" ], - "gcc-lto-type-mismatch": [ ], - "gcc-main": [ ], - "gcc-maybe-uninitialized": [ ], - "gcc-memset-elt-size": [ ], - "gcc-memset-transposed-args": [ ], - "gcc-misleading-indentation": [ ], - "gcc-mismatched-dealloc": [ ], - "gcc-mismatched-new-delete": [ ], - "gcc-mismatched-special-enum": [ ], - "gcc-mismatched-tags": [ ], - "gcc-missing-attributes": [ ], - "gcc-missing-braces": [ ], - "gcc-missing-declarations": [ ], - "gcc-missing-field-initializers": [ ], - "gcc-missing-format-attribute": [ ], - "gcc-missing-include-dirs": [ ], - "gcc-missing-noreturn": [ ], - "gcc-missing-parameter-type": [ ], - "gcc-missing-profile": [ ], - "gcc-missing-prototypes": [ ], - "gcc-missing-requires": [ ], - "gcc-missing-template-keyword": [ ], - "gcc-missing-variable-declarations": [ ], - "gcc-multichar": [ ], - "gcc-multiple-inheritance": [ ], - "gcc-multistatement-macros": [ ], - "gcc-namespaces": [ ], - "gcc-narrowing": [ ], - "gcc-nested-externs": [ ], - "gcc-no-alloc-size-larger-than": [ "blacklist:true" ], - "gcc-no-alloca-larger-than": [ "blacklist:true" ], - "gcc-no-frame-larger-than": [ "blacklist:true" ], - "gcc-no-larger-than": [ "blacklist:true" ], - "gcc-no-stack-usage": [ "blacklist:true" ], - "gcc-no-vla-larger-than": [ "blacklist:true" ], - "gcc-noexcept": [ ], - "gcc-noexcept-type": [ ], - "gcc-non-template-friend": [ ], - "gcc-non-virtual-dtor": [ ], - "gcc-nonnull": [ ], - "gcc-nonnull-compare": [ ], - "gcc-normalized": [ ], - "gcc-normalized=[none|id|nfc|nfkc]": [ "blacklist:true" ], - "gcc-nrvo": [ ], - "gcc-objc-root-class": [ ], - "gcc-odr": [ ], - "gcc-old-style-cast": [ ], - "gcc-old-style-declaration": [ ], - "gcc-old-style-definition": [ ], - "gcc-openacc-parallelism": [ ], - "gcc-openmp": [ ], - "gcc-openmp-simd": [ ], - "gcc-overflow": [ ], - "gcc-overlength-strings": [ ], - "gcc-overloaded-virtual": [ ], - "gcc-overloaded-virtual=<0,2>": [ ], - "gcc-override-init": [ ], - "gcc-override-init-side-effects": [ ], - "gcc-overwrite-recursive": [ ], - "gcc-packed": [ ], - "gcc-packed-bitfield-compat": [ ], - "gcc-packed-not-aligned": [ ], - "gcc-padded": [ ], - "gcc-parentheses": [ ], - "gcc-pedantic": [ "blacklist:true" ], - "gcc-pessimizing-move": [ ], - "gcc-placement-new": [ ], - "gcc-placement-new=<0,2>": [ "blacklist:true" ], - "gcc-pmf-conversions": [ ], - "gcc-pointer-arith": [ ], - "gcc-pointer-compare": [ ], - "gcc-pointer-sign": [ ], - "gcc-pointer-to-int-cast": [ ], - "gcc-pragmas": [ ], - "gcc-prio-ctor-dtor": [ ], - "gcc-property-assign-default": [ ], - "gcc-protocol": [ ], - "gcc-psabi": [ ], - "gcc-range-loop-construct": [ ], - "gcc-real-q-constant": [ ], - "gcc-realloc-lhs": [ ], - "gcc-realloc-lhs-all": [ ], - "gcc-redundant-decls": [ ], - "gcc-redundant-move": [ ], - "gcc-redundant-tags": [ ], - "gcc-register": [ ], - "gcc-reorder": [ ], - "gcc-restrict": [ ], - "gcc-return-local-addr": [ ], - "gcc-return-mismatch": [ ], - "gcc-return-type": [ ], - "gcc-scalar-storage-order": [ ], - "gcc-selector": [ ], - "gcc-self-move": [ ], - "gcc-sequence-point": [ ], - "gcc-shadow": [ "blacklist:true" ], - "gcc-shadow-compatible-local": [ ], - "gcc-shadow-ivar": [ ], - "gcc-shadow-local": [ ], - "gcc-shadow=compatible-local": [ "blacklist:true" ], - "gcc-shadow=global": [ "blacklist:true" ], - "gcc-shadow=local": [ ], - "gcc-shift-negative-value": [ ], - "gcc-shift-overflow": [ ], - "gcc-shift-overflow=<0,2>": [ "blacklist:true" ], - "gcc-sign-compare": [ ], - "gcc-sign-conversion": [ ], - "gcc-sign-promo": [ ], - "gcc-sized-deallocation": [ ], - "gcc-sizeof-array-argument": [ ], - "gcc-sizeof-array-div": [ ], - "gcc-sizeof-pointer-div": [ ], - "gcc-sizeof-pointer-memaccess": [ ], - "gcc-stack-protector": [ ], - "gcc-stack-usage=": [ ], - "gcc-strict-aliasing": [ ], - "gcc-strict-aliasing=<0,3>": [ ], - "gcc-strict-flex-arrays": [ ], - "gcc-strict-null-sentinel": [ ], - "gcc-strict-overflow": [ ], - "gcc-strict-overflow=<0,5>": [ ], - "gcc-strict-prototypes": [ ], - "gcc-strict-selector-match": [ ], - "gcc-string-compare": [ ], - "gcc-stringop-overflow": [ ], - "gcc-stringop-overflow=<0,4>": [ ], - "gcc-stringop-overread": [ ], - "gcc-stringop-truncation": [ ], - "gcc-subobject-linkage": [ ], - "gcc-suggest-attribute=cold": [ ], - "gcc-suggest-attribute=const": [ ], - "gcc-suggest-attribute=format": [ ], - "gcc-suggest-attribute=malloc": [ ], - "gcc-suggest-attribute=noreturn": [ ], - "gcc-suggest-attribute=pure": [ ], - "gcc-suggest-attribute=returns_nonnull": [ ], - "gcc-suggest-final-methods": [ ], - "gcc-suggest-final-types": [ ], - "gcc-suggest-override": [ ], - "gcc-surprising": [ ], - "gcc-switch": [ ], - "gcc-switch-bool": [ ], - "gcc-switch-default": [ ], - "gcc-switch-enum": [ ], - "gcc-switch-outside-range": [ ], - "gcc-switch-unreachable": [ ], - "gcc-sync-nand": [ ], - "gcc-synth": [ ], - "gcc-system-headers": [ ], - "gcc-tabs": [ ], - "gcc-target-lifetime": [ ], - "gcc-tautological-compare": [ ], - "gcc-template-id-cdtor": [ ], - "gcc-templates": [ ], - "gcc-terminate": [ ], - "gcc-traditional": [ ], - "gcc-traditional-conversion": [ ], - "gcc-trampolines": [ ], - "gcc-trigraphs": [ ], - "gcc-trivial-auto-var-init": [ ], - "gcc-tsan": [ ], - "gcc-type-limits": [ ], - "gcc-undeclared-selector": [ ], - "gcc-undef": [ ], - "gcc-undefined-do-loop": [ ], - "gcc-underflow": [ ], - "gcc-unicode": [ ], - "gcc-uninitialized": [ ], - "gcc-unknown-pragmas": [ ], - "gcc-unreachable-code": [ ], - "gcc-unsafe-loop-optimizations": [ ], - "gcc-unsuffixed-float-constants": [ ], - "gcc-unused": [ "blacklist:true"], - "gcc-unused-but-set-parameter": [ ], - "gcc-unused-but-set-variable": [ ], - "gcc-unused-const-variable": [ ], - "gcc-unused-const-variable=<0,2>": [ "blacklist:true" ], - "gcc-unused-dummy-argument": [ ], - "gcc-unused-function": [ ], - "gcc-unused-label": [ ], - "gcc-unused-local-typedefs": [ ], - "gcc-unused-macros": [ ], - "gcc-unused-parameter": [ ], - "gcc-unused-result": [ ], - "gcc-unused-value": [ ], - "gcc-unused-variable": [ ], - "gcc-use-after-free=<0,3>": [ ], - "gcc-use-without-only": [ ], - "gcc-useless-cast": [ ], - "gcc-varargs": [ ], - "gcc-variadic-macros": [ ], - "gcc-vector-operation-performance": [ ], - "gcc-vexing-parse": [ ], - "gcc-virtual-inheritance": [ ], - "gcc-virtual-move-assign": [ ], - "gcc-vla": [ "blacklist:true" ], - "gcc-vla-larger-than=": [ "blacklist:true" ], - "gcc-vla-parameter": [ ], - "gcc-volatile": [ "blacklist:true" ], - "gcc-volatile-register-var": [ ], - "gcc-write-strings": [ ], - "gcc-xor-used-as-pow": [ ], - "gcc-zero-as-null-pointer-constant": [ ], - "gcc-zero-length-bounds": [ ], - "gcc-zerotrip": [ ] + "gcc-NSObject-attribute": [], + "gcc-abi": [ + "blacklist:true" + ], + "gcc-abi-tag": [ + "blacklist:true" + ], + "gcc-abi=": [], + "gcc-absolute-value": [], + "gcc-address": [], + "gcc-address-of-packed-member": [], + "gcc-aggregate-return": [], + "gcc-aggressive-loop-optimizations": [], + "gcc-aliasing": [], + "gcc-align-commons": [], + "gcc-aligned-new=[none|global|all]": [], + "gcc-all": [ + "blacklist:true" + ], + "gcc-alloc-size": [], + "gcc-alloc-size-larger-than": [ + "blacklist:true" + ], + "gcc-alloc-zero": [], + "gcc-alloca": [], + "gcc-alloca-larger-than=": [ + "blacklist:true" + ], + "gcc-ampersand": [], + "gcc-arith-conversion": [], + "gcc-array-bounds": [ + "blacklist:true" + ], + "gcc-array-bounds=<0,2>": [ + "blacklist:true" + ], + "gcc-array-compare": [], + "gcc-array-parameter": [ + "blacklist:true" + ], + "gcc-array-parameter=<0,2>": [ + "blacklist:true" + ], + "gcc-array-temporaries": [], + "gcc-assign-intercept": [], + "gcc-attribute-alias": [ + "blacklist:true" + ], + "gcc-attribute-alias=<0,2>": [ + "blacklist:true" + ], + "gcc-attribute-warning": [], + "gcc-attributes": [], + "gcc-bad-function-cast": [], + "gcc-bidi-chars": [ + "blacklist:true" + ], + "gcc-bidi-chars=": [ + "blacklist:true" + ], + "gcc-bool-compare": [], + "gcc-bool-operation": [], + "gcc-builtin-declaration-mismatch": [], + "gcc-builtin-macro-redefined": [], + "gcc-c++-compat": [], + "gcc-c++0x-compat": [ + "blacklist:true" + ], + "gcc-c++11-compat": [], + "gcc-c++11-extensions": [], + "gcc-c++14-compat": [], + "gcc-c++14-extensions": [], + "gcc-c++17-compat": [], + "gcc-c++17-extensions": [], + "gcc-c++1z-compat": [ + "blacklist:true" + ], + "gcc-c++20-compat": [], + "gcc-c++20-extensions": [], + "gcc-c++23-extensions": [], + "gcc-c++26-extensions": [], + "gcc-c++2a-compat": [ + "blacklist:true" + ], + "gcc-c-binding-type": [], + "gcc-c11-c23-compat": [], + "gcc-c90-c99-compat": [], + "gcc-c99-c11-compat": [], + "gcc-calloc-transposed-args": [], + "gcc-cannot-profile": [], + "gcc-cast-align": [], + "gcc-cast-align=strict": [], + "gcc-cast-function-type": [], + "gcc-cast-qual": [], + "gcc-cast-result": [], + "gcc-cast-user-defined": [], + "gcc-catch-value": [], + "gcc-catch-value=<0,3>": [], + "gcc-changes-meaning": [], + "gcc-char-subscripts": [], + "gcc-character-truncation": [], + "gcc-chkp": [ + "blacklist:true" + ], + "gcc-class-conversion": [], + "gcc-class-memaccess": [], + "gcc-clobbered": [], + "gcc-comma-subscript": [], + "gcc-comment": [], + "gcc-comments": [ + "blacklist:true" + ], + "gcc-compare-distinct-pointer-types": [], + "gcc-compare-reals": [], + "gcc-complain-wrong-lang": [], + "gcc-conditionally-supported": [], + "gcc-conversion": [], + "gcc-conversion-extra": [], + "gcc-conversion-null": [], + "gcc-coverage-invalid-line-number": [], + "gcc-coverage-mismatch": [], + "gcc-coverage-too-many-conditions": [], + "gcc-cpp": [], + "gcc-ctad-maybe-unsupported": [], + "gcc-ctor-dtor-privacy": [], + "gcc-dangling-else": [], + "gcc-dangling-pointer": [ + "blacklist:true" + ], + "gcc-dangling-pointer=<0,2>": [ + "blacklist:true" + ], + "gcc-dangling-reference": [], + "gcc-date-time": [], + "gcc-declaration-after-statement": [], + "gcc-declaration-missing-parameter-type": [], + "gcc-delete-incomplete": [], + "gcc-delete-non-virtual-dtor": [], + "gcc-deprecated": [], + "gcc-deprecated-copy": [], + "gcc-deprecated-copy-dtor": [], + "gcc-deprecated-declarations": [], + "gcc-deprecated-enum-enum-conversion": [], + "gcc-deprecated-enum-float-conversion": [], + "gcc-designated-init": [], + "gcc-disabled-optimization": [], + "gcc-discarded-array-qualifiers": [], + "gcc-discarded-qualifiers": [], + "gcc-div-by-zero": [], + "gcc-do-subscript": [], + "gcc-double-promotion": [], + "gcc-duplicate-decl-specifier": [], + "gcc-duplicated-branches": [], + "gcc-duplicated-cond": [], + "gcc-effc++": [], + "gcc-elaborated-enum-base": [], + "gcc-empty-body": [], + "gcc-endif-labels": [], + "gcc-enum-compare": [], + "gcc-enum-conversion": [], + "gcc-enum-int-mismatch": [], + "gcc-error-implicit-function-declaration": [ + "blacklist:true" + ], + "gcc-exceptions": [], + "gcc-expansion-to-defined": [], + "gcc-extra": [], + "gcc-extra-semi": [], + "gcc-flex-array-member-not-at-end": [], + "gcc-float-conversion": [], + "gcc-float-equal": [], + "gcc-format": [ + "blacklist:true" + ], + "gcc-format-contains-nul": [], + "gcc-format-diag": [], + "gcc-format-extra-args": [], + "gcc-format-nonliteral": [], + "gcc-format-overflow<0,2>": [ + "blacklist:true" + ], + "gcc-format-overflow=<0,2>": [ + "blacklist:true" + ], + "gcc-format-security": [], + "gcc-format-signedness": [], + "gcc-format-truncation": [ + "blacklist:true" + ], + "gcc-format-truncation=<0,2>": [ + "blacklist:true" + ], + "gcc-format-y2k": [], + "gcc-format-zero-length": [], + "gcc-format=<0,2>": [ + "blacklist:true" + ], + "gcc-frame-address": [], + "gcc-frame-larger-than=": [ + "blacklist:true" + ], + "gcc-free-nonheap-object": [], + "gcc-function-elimination": [], + "gcc-global-module": [], + "gcc-hardened": [], + "gcc-hsa": [], + "gcc-if-not-aligned": [], + "gcc-ignored-attributes": [], + "gcc-ignored-qualifiers": [], + "gcc-implicit": [], + "gcc-implicit-fallthrough": [], + "gcc-implicit-fallthrough=<0,5>": [ + "blacklist:true" + ], + "gcc-implicit-function-declaration": [], + "gcc-implicit-int": [], + "gcc-implicit-interface": [], + "gcc-implicit-procedure": [], + "gcc-inaccessible-base": [], + "gcc-incompatible-pointer-types": [], + "gcc-inherited-variadic-ctor": [], + "gcc-init-list-lifetime": [], + "gcc-init-self": [], + "gcc-inline": [], + "gcc-int-conversion": [], + "gcc-int-in-bool-context": [], + "gcc-int-to-pointer-cast": [], + "gcc-integer-division": [], + "gcc-interference-size": [], + "gcc-intrinsic-shadow": [], + "gcc-intrinsics-std": [], + "gcc-invalid-constexpr": [], + "gcc-invalid-imported-macros": [], + "gcc-invalid-memory-model": [], + "gcc-invalid-offsetof": [], + "gcc-invalid-pch": [], + "gcc-invalid-utf8": [], + "gcc-jump-misses-init": [], + "gcc-larger-than-": [ + "blacklist:true" + ], + "gcc-larger-than=": [ + "blacklist:true" + ], + "gcc-line-truncation": [], + "gcc-literal-suffix": [], + "gcc-logical-not-parentheses": [], + "gcc-logical-op": [], + "gcc-long-long": [ + "blacklist:true" + ], + "gcc-lto-type-mismatch": [], + "gcc-main": [], + "gcc-maybe-uninitialized": [], + "gcc-memset-elt-size": [], + "gcc-memset-transposed-args": [], + "gcc-misleading-indentation": [], + "gcc-mismatched-dealloc": [], + "gcc-mismatched-new-delete": [], + "gcc-mismatched-special-enum": [], + "gcc-mismatched-tags": [], + "gcc-missing-attributes": [], + "gcc-missing-braces": [], + "gcc-missing-declarations": [], + "gcc-missing-field-initializers": [], + "gcc-missing-format-attribute": [], + "gcc-missing-include-dirs": [], + "gcc-missing-noreturn": [], + "gcc-missing-parameter-type": [], + "gcc-missing-profile": [], + "gcc-missing-prototypes": [], + "gcc-missing-requires": [], + "gcc-missing-template-keyword": [], + "gcc-missing-variable-declarations": [], + "gcc-multichar": [], + "gcc-multiple-inheritance": [], + "gcc-multistatement-macros": [], + "gcc-namespaces": [], + "gcc-narrowing": [], + "gcc-nested-externs": [], + "gcc-no-alloc-size-larger-than": [ + "blacklist:true" + ], + "gcc-no-alloca-larger-than": [ + "blacklist:true" + ], + "gcc-no-frame-larger-than": [ + "blacklist:true" + ], + "gcc-no-larger-than": [ + "blacklist:true" + ], + "gcc-no-stack-usage": [ + "blacklist:true" + ], + "gcc-no-vla-larger-than": [ + "blacklist:true" + ], + "gcc-noexcept": [], + "gcc-noexcept-type": [], + "gcc-non-template-friend": [], + "gcc-non-virtual-dtor": [], + "gcc-nonnull": [], + "gcc-nonnull-compare": [], + "gcc-normalized": [], + "gcc-normalized=[none|id|nfc|nfkc]": [ + "blacklist:true" + ], + "gcc-nrvo": [], + "gcc-objc-root-class": [], + "gcc-odr": [], + "gcc-old-style-cast": [], + "gcc-old-style-declaration": [], + "gcc-old-style-definition": [], + "gcc-openacc-parallelism": [], + "gcc-openmp": [], + "gcc-openmp-simd": [], + "gcc-overflow": [], + "gcc-overlength-strings": [], + "gcc-overloaded-virtual": [], + "gcc-overloaded-virtual=<0,2>": [], + "gcc-override-init": [], + "gcc-override-init-side-effects": [], + "gcc-overwrite-recursive": [], + "gcc-packed": [], + "gcc-packed-bitfield-compat": [], + "gcc-packed-not-aligned": [], + "gcc-padded": [], + "gcc-parentheses": [], + "gcc-pedantic": [ + "blacklist:true" + ], + "gcc-pessimizing-move": [], + "gcc-placement-new": [], + "gcc-placement-new=<0,2>": [ + "blacklist:true" + ], + "gcc-pmf-conversions": [], + "gcc-pointer-arith": [], + "gcc-pointer-compare": [], + "gcc-pointer-sign": [], + "gcc-pointer-to-int-cast": [], + "gcc-pragmas": [], + "gcc-prio-ctor-dtor": [], + "gcc-property-assign-default": [], + "gcc-protocol": [], + "gcc-psabi": [], + "gcc-range-loop-construct": [], + "gcc-real-q-constant": [], + "gcc-realloc-lhs": [], + "gcc-realloc-lhs-all": [], + "gcc-redundant-decls": [], + "gcc-redundant-move": [], + "gcc-redundant-tags": [], + "gcc-register": [], + "gcc-reorder": [], + "gcc-restrict": [], + "gcc-return-local-addr": [], + "gcc-return-mismatch": [], + "gcc-return-type": [], + "gcc-scalar-storage-order": [], + "gcc-selector": [], + "gcc-self-move": [], + "gcc-sequence-point": [], + "gcc-shadow": [ + "blacklist:true" + ], + "gcc-shadow-compatible-local": [], + "gcc-shadow-ivar": [], + "gcc-shadow-local": [], + "gcc-shadow=compatible-local": [ + "blacklist:true" + ], + "gcc-shadow=global": [ + "blacklist:true" + ], + "gcc-shadow=local": [], + "gcc-shift-negative-value": [], + "gcc-shift-overflow": [], + "gcc-shift-overflow=<0,2>": [ + "blacklist:true" + ], + "gcc-sign-compare": [], + "gcc-sign-conversion": [], + "gcc-sign-promo": [], + "gcc-sized-deallocation": [], + "gcc-sizeof-array-argument": [], + "gcc-sizeof-array-div": [], + "gcc-sizeof-pointer-div": [], + "gcc-sizeof-pointer-memaccess": [], + "gcc-stack-protector": [], + "gcc-stack-usage=": [], + "gcc-strict-aliasing": [], + "gcc-strict-aliasing=<0,3>": [], + "gcc-strict-flex-arrays": [], + "gcc-strict-null-sentinel": [], + "gcc-strict-overflow": [], + "gcc-strict-overflow=<0,5>": [], + "gcc-strict-prototypes": [], + "gcc-strict-selector-match": [], + "gcc-string-compare": [], + "gcc-stringop-overflow": [], + "gcc-stringop-overflow=<0,4>": [], + "gcc-stringop-overread": [], + "gcc-stringop-truncation": [], + "gcc-subobject-linkage": [], + "gcc-suggest-attribute=cold": [], + "gcc-suggest-attribute=const": [], + "gcc-suggest-attribute=format": [], + "gcc-suggest-attribute=malloc": [], + "gcc-suggest-attribute=noreturn": [], + "gcc-suggest-attribute=pure": [], + "gcc-suggest-attribute=returns_nonnull": [], + "gcc-suggest-final-methods": [], + "gcc-suggest-final-types": [], + "gcc-suggest-override": [], + "gcc-surprising": [], + "gcc-switch": [], + "gcc-switch-bool": [], + "gcc-switch-default": [], + "gcc-switch-enum": [], + "gcc-switch-outside-range": [], + "gcc-switch-unreachable": [], + "gcc-sync-nand": [], + "gcc-synth": [], + "gcc-system-headers": [], + "gcc-tabs": [], + "gcc-target-lifetime": [], + "gcc-tautological-compare": [], + "gcc-template-id-cdtor": [], + "gcc-templates": [], + "gcc-terminate": [], + "gcc-traditional": [], + "gcc-traditional-conversion": [], + "gcc-trampolines": [], + "gcc-trigraphs": [], + "gcc-trivial-auto-var-init": [], + "gcc-tsan": [], + "gcc-type-limits": [], + "gcc-undeclared-selector": [], + "gcc-undef": [], + "gcc-undefined-do-loop": [], + "gcc-underflow": [], + "gcc-unicode": [], + "gcc-uninitialized": [], + "gcc-unknown-pragmas": [], + "gcc-unreachable-code": [], + "gcc-unsafe-loop-optimizations": [], + "gcc-unsuffixed-float-constants": [], + "gcc-unused": [ + "blacklist:true" + ], + "gcc-unused-but-set-parameter": [], + "gcc-unused-but-set-variable": [], + "gcc-unused-const-variable": [], + "gcc-unused-const-variable=<0,2>": [ + "blacklist:true" + ], + "gcc-unused-dummy-argument": [], + "gcc-unused-function": [], + "gcc-unused-label": [], + "gcc-unused-local-typedefs": [], + "gcc-unused-macros": [], + "gcc-unused-parameter": [], + "gcc-unused-result": [], + "gcc-unused-value": [], + "gcc-unused-variable": [], + "gcc-use-after-free=<0,3>": [], + "gcc-use-without-only": [], + "gcc-useless-cast": [], + "gcc-varargs": [], + "gcc-variadic-macros": [], + "gcc-vector-operation-performance": [], + "gcc-vexing-parse": [], + "gcc-virtual-inheritance": [], + "gcc-virtual-move-assign": [], + "gcc-vla": [ + "blacklist:true" + ], + "gcc-vla-larger-than=": [ + "blacklist:true" + ], + "gcc-vla-parameter": [], + "gcc-volatile": [ + "blacklist:true" + ], + "gcc-volatile-register-var": [], + "gcc-write-strings": [], + "gcc-xor-used-as-pow": [], + "gcc-zero-as-null-pointer-constant": [], + "gcc-zero-length-bounds": [], + "gcc-zerotrip": [] } } diff --git a/config/labels/analyzers/infer.json b/config/labels/analyzers/infer.json index f321161f1b..e96debb90a 100644 --- a/config/labels/analyzers/infer.json +++ b/config/labels/analyzers/infer.json @@ -1,1401 +1,1401 @@ { - "analyzer": "infer", - "labels": { - "infer-arbitrary-code-execution-under-lock": [ - "description:A call that may execute arbitrary code (such as registered, or chained, callbacks) is made while holding a lock. This code may deadlock whenever the callbacks obtain locks themselves, so it is an unsafe pattern.", - "doc_url:https://fbinfer.com/docs/all-issue-types#arbitrary_code_execution_under_lock", - "profile:unknown", - "severity:HIGH" - ], - "infer-array-out-of-bounds-l1": [ - "doc_url:https://fbinfer.com/docs/all-issue-types", - "profile:unknown", - "severity:HIGH" - ], - "infer-array-out-of-bounds-l2": [ - "doc_url:https://fbinfer.com/docs/all-issue-types", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-array-out-of-bounds-l3": [ - "doc_url:https://fbinfer.com/docs/all-issue-types", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-abduction-case-not-implemented": [ - "doc_url:https://fbinfer.com/docs/all-issue-types", - "profile:unknown", - "severity:HIGH" - ], - "infer-array-of-pointsto": [ - "doc_url:https://fbinfer.com/docs/all-issue-types", - "profile:unknown", - "severity:HIGH" - ], - "infer-assert-failure": [ - "doc_url:https://fbinfer.com/docs/all-issue-types", - "profile:unknown", - "severity:HIGH" - ], - "infer-bad-arg": [ - "description:Bad arg in Erlang: Reports an error when the type of an argument is wrong or the argument is badly formed. Corresponds to the badarg error in the Erlang runtime.", - "doc_url:https://fbinfer.com/docs/all-issue-types#bad_arg", - "profile:unknown", - "severity:HIGH" - ], - "infer-bad-arg-latent": [ - "description:A latent BAD_ARG. See the documentation on Pulse latent issues.", - "doc_url:https://fbinfer.com/docs/all-issue-types#bad_arg_latent", - "profile:unknown", - "severity:HIGH" - ], - "infer-bad-generator": [ - "description:Bad generator in Erlang: Reports an error when a wrong type is used in a generator. Corresponds to the bad_generator error in the Erlang runtime.", - "doc_url:https://fbinfer.com/docs/all-issue-types#bad_generator", - "profile:unknown", - "severity:HIGH" - ], - "infer-bad-generator-latent": [ - "description:A latent BAD_GENERATOR. See the documentation on Pulse latent issues.", - "doc_url:https://fbinfer.com/docs/all-issue-types#bad_generator_latent", - "profile:unknown", - "severity:HIGH" - ], - "infer-bad-key": [ - "description:Bad key in Erlang: Reports an error when trying to access or update a non-existing key in a map. Corresponds to the {badkey,K} error in the Erlang runtime.", - "doc_url:https://fbinfer.com/docs/all-issue-types#bad_key", - "profile:unknown", - "severity:HIGH" - ], - "infer-bad-key-latent": [ - "description:A latent BAD_KEY. See the documentation on Pulse latent issues.", - "doc_url:https://fbinfer.com/docs/all-issue-types#bad_key_latent", - "profile:unknown", - "severity:HIGH" - ], - "infer-bad-map": [ - "description:Bad map in Erlang: Reports an error when trying to access or update a key for a term that is not a map. Corresponds to the {badmap,...} error in the Erlang runtime.", - "doc_url:https://fbinfer.com/docs/all-issue-types#bad_map", - "profile:unknown", - "severity:HIGH" - ], - "infer-bad-map-latent": [ - "description:A latent BAD_MAP. See the documentation on Pulse latent issues.", - "doc_url:https://fbinfer.com/docs/all-issue-types#bad_map_latent", - "profile:unknown", - "severity:HIGH" - ], - "infer-bad-record": [ - "description:Bad record in Erlang: Reports an error when trying to access or update a record with the wrong name. Corresponds to the {badrecord,Name} error in the Erlang runtime.", - "doc_url:https://fbinfer.com/docs/all-issue-types#bad_record", - "profile:unknown", - "severity:HIGH" - ], - "infer-bad-record-latent": [ - "description:A latent BAD_RECORD. See the documentation on Pulse latent issues.", - "doc_url:https://fbinfer.com/docs/all-issue-types#bad_record_latent", - "profile:unknown", - "severity:HIGH" - ], - "infer-bad-return": [ - "description:Bad return in Erlang: The dynamic type of a returned value disagrees with the static type given in the spec.", - "doc_url:https://fbinfer.com/docs/all-issue-types#bad_return", - "profile:unknown", - "severity:HIGH" - ], - "infer-bad-return-latent": [ - "description:A latent BAD_RETURN. See the documentation on Pulse latent issues.", - "doc_url:https://fbinfer.com/docs/all-issue-types#bad_return_latent", - "profile:unknown", - "severity:HIGH" - ], - "infer-biabduction-analysis-stops": [ - "doc_url:https://fbinfer.com/docs/all-issue-types", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-biabduction-memory-leak": [ - "description:See MEMORY_LEAK_C.", - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#biabduction_memory_leak", - "profile:unknown", - "severity:HIGH" - ], - "infer-biabduction-retain-cycle": [ - "description:See RETAIN_CYCLE.", - "doc_url:https://fbinfer.com/docs/all-issue-types#biabduction_retain_cycle", - "profile:unknown", - "severity:HIGH" - ], - "infer-block-parameter-not-null-checked": [ - "description:This error type is reported only in Objective-C/Objective-C++. It happens when a method has a block as a parameter, and the block is executed in the method's body without checking it for nil first. If a nil block is passed to the method, then this will cause a crash. For example:", - "doc_url:https://fbinfer.com/docs/all-issue-types#block_parameter_not_null_checked", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-buffer-overrun-l1": [ - "description:This is reported when outside of buffer bound is accessed. It can corrupt memory and may introduce security issues in C/C++.", - "doc_url:https://fbinfer.com/docs/all-issue-types#buffer_overrun_l1", - "profile:unknown", - "severity:HIGH" - ], - "infer-buffer-overrun-l2": [ - "description:See BUFFER_OVERRUN_L1", - "doc_url:https://fbinfer.com/docs/all-issue-types#buffer_overrun_l2", - "profile:unknown", - "severity:HIGH" - ], - "infer-buffer-overrun-l3": [ - "description:See BUFFER_OVERRUN_L1", - "doc_url:https://fbinfer.com/docs/all-issue-types#buffer_overrun_l3", - "profile:unknown", - "severity:HIGH" - ], - "infer-buffer-overrun-l4": [ - "description:See BUFFER_OVERRUN_L1", - "doc_url:https://fbinfer.com/docs/all-issue-types#buffer_overrun_l4", - "profile:unknown", - "severity:HIGH" - ], - "infer-buffer-overrun-l5": [ - "description:See BUFFER_OVERRUN_L1", - "doc_url:https://fbinfer.com/docs/all-issue-types#buffer_overrun_l5", - "profile:unknown", - "severity:HIGH" - ], - "infer-buffer-overrun-s2": [ - "description:See BUFFER_OVERRUN_L1", - "doc_url:https://fbinfer.com/docs/all-issue-types#buffer_overrun_s2", - "profile:unknown", - "severity:HIGH" - ], - "infer-buffer-overrun-u5": [ - "description:See BUFFER_OVERRUN_L1", - "doc_url:https://fbinfer.com/docs/all-issue-types#buffer_overrun_u5", - "profile:unknown", - "severity:HIGH" - ], - "infer-bad-footprint": [ - "doc_url:https://fbinfer.com/docs/all-issue-types", - "profile:unknown", - "severity:HIGH" - ], - "infer-captured-strong-self": [ - "description:This check is about when a strong pointer to self is captured in a block. This could lead to retain cycles or unexpected behavior since to avoid retain cycles one usually uses a local strong pointer or a captured weak pointer instead.", - "doc_url:https://fbinfer.com/docs/all-issue-types#captured_strong_self", - "profile:unknown", - "severity:HIGH" - ], - "infer-checkers-allocates-memory": [ - "description:A method annotated with @NoAllocation transitively calls new.", - "doc_url:https://fbinfer.com/docs/all-issue-types#checkers_allocates_memory", - "profile:unknown", - "severity:HIGH" - ], - "infer-checkers-annotation-reachability-error": [ - "description:A method annotated with an annotation @A transitively calls a method annotated @B where the combination of annotations is forbidden (for example, @UiThread calling @WorkerThread).", - "doc_url:https://fbinfer.com/docs/all-issue-types#checkers_annotation_reachability_error", - "profile:unknown", - "severity:HIGH" - ], - "infer-checkers-calls-expensive-method": [ - "description:A method annotated with @PerformanceCritical transitively calls a method annotated @Expensive.", - "doc_url:https://fbinfer.com/docs/all-issue-types#checkers_calls_expensive_method", - "profile:unknown", - "severity:HIGH" - ], - "infer-checkers-expensive-overrides-unannotated": [ - "description:A method annotated with @Expensive overrides an un-annotated method.", - "doc_url:https://fbinfer.com/docs/all-issue-types#checkers_expensive_overrides_unannotated", - "profile:unknown", - "severity:HIGH" - ], - "infer-checkers-fragment-retains-view": [ - "description:This error type is Android-specific. It fires when a Fragment type fails to nullify one or more of its declared View fields in onDestroyView. In performance-sensitive applications, a Fragment should initialize all View's in onCreateView and nullify them in onDestroyView. If a Fragment is placed on the back stack and fails to nullify a View in onDestroyView, it will retain a useless reference to that View that will not be cleaned up until the Fragment is resumed or destroyed.", - "doc_url:https://fbinfer.com/docs/all-issue-types#checkers_fragment_retains_view", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-checkers-printf-args": [ - "description:This error is reported when the argument types to a printf method do not match the format string.", - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#checkers_printf_args", - "profile:unknown", - "severity:HIGH" - ], - "infer-class-cast-exception": [ - "doc_url:https://fbinfer.com/docs/all-issue-types", - "profile:unknown", - "severity:HIGH" - ], - "infer-condition-always-false": [ - "doc_url:https://fbinfer.com/docs/all-issue-types", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-condition-always-true": [ - "doc_url:https://fbinfer.com/docs/all-issue-types", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-config-impact": [ - "description:Infer reports this issue when an expensive function is called without a config check. The config is usually a boolean value that enables experimental new features and it is defined per application/codebase, e.g. gatekeepers. To determine whether a function is expensive or not, the checker relies on modeled functions that are assumed to be expensive, e.g. string operations, regular expression match, or DB accesses.", - "doc_url:https://fbinfer.com/docs/all-issue-types#config_impact", - "profile:unknown", - "severity:STYLE" - ], - "infer-config-impact-strict": [ - "description:This is similar to CONFIG_IMPACT issue but the analysis reports all ungated codes irrespective of whether they are expensive or not.", - "doc_url:https://fbinfer.com/docs/all-issue-types#config_impact_strict", - "profile:unknown", - "severity:STYLE" - ], - "infer-config-usage": [ - "description:Infer reports this issue when a config value is used as branch condition in a function. The config is usually a boolean value that enables experimental new features and it is defined per application/codebase, e.g. gatekeepers.", - "doc_url:https://fbinfer.com/docs/all-issue-types#config_usage", - "profile:unknown", - "severity:LOW" - ], - "infer-constant-address-dereference": [ - "description:This is reported when an address at an absolute location, e.g. 1234, is dereferenced. It is a more general version of the NULLPTR_DEREFERENCE error type that is reported when the address is a constant other than zero.", - "doc_url:https://fbinfer.com/docs/all-issue-types#constant_address_dereference", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-constant-address-dereference-latent": [ - "description:A latent CONSTANT_ADDRESS_DEREFERENCE. See the documentation on Pulse latent issues.", - "doc_url:https://fbinfer.com/docs/all-issue-types#constant_address_dereference_latent", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-create-intent-from-uri": [ - "description:Create an intent/start a component using a (possibly user-controlled) URI. may or may not be an issue depending on where the URI comes from.", - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#create_intent_from_uri", - "profile:unknown", - "severity:HIGH" - ], - "infer-cross-site-scripting": [ - "description:Untrusted data flows into HTML; XSS risk.", - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#cross_site_scripting", - "profile:unknown", - "severity:HIGH" - ], - "infer-cxx-ref-captured-in-block": [ - "description:This check flags when a C++ reference is captured in an escaping block. This means that the block will be leaving the current scope, i.e. it is not annotated with __attribute__((noescape)).", - "doc_url:https://fbinfer.com/docs/all-issue-types#cxx_ref_captured_in_block", - "profile:unknown", - "severity:HIGH" - ], - "infer-cannot-star": [ - "doc_url:https://fbinfer.com/docs/all-issue-types", - "profile:unknown", - "severity:HIGH" - ], - "infer-dangling-pointer-dereference": [ - "description:DATALOG_FACT", - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#dangling_pointer_dereference", - "profile:unknown", - "severity:HIGH" - ], - "infer-dangling-pointer-dereference-maybe": [ - "doc_url:https://fbinfer.com/docs/all-issue-types", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-datalog-fact": [ - "description:Datalog fact used as input for a datalog solver.", - "doc_url:https://fbinfer.com/docs/all-issue-types#datalog_fact", - "profile:unknown", - "severity:LOW" - ], - "infer-data-flow-to-sink": [ - "description:A flow of data was detected to a sink.", - "doc_url:https://fbinfer.com/docs/all-issue-types#data_flow_to_sink", - "profile:unknown", - "severity:STYLE" - ], - "infer-deadlock": [ - "description:This error is currently reported in Java. A deadlock occurs when two distinct threads try to acquire two locks in reverse orders. The following code illustrates a textbook example. Of course, in real deadlocks, the lock acquisitions may be separated by deeply nested call chains.", - "doc_url:https://fbinfer.com/docs/all-issue-types#deadlock", - "profile:unknown", - "severity:HIGH" - ], - "infer-dead-store": [ - "description:This error is reported in C++. It fires when the value assigned to a variables is never used (e.g., int i = 1; i = 2; return i;).", - "doc_url:https://fbinfer.com/docs/all-issue-types#dead_store", - "profile:unknown", - "severity:HIGH" - ], - "infer-divide-by-zero": [ - "description:EMPTY_VECTOR_ACCESS", - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#divide_by_zero", - "profile:unknown", - "severity:HIGH" - ], - "infer-do-not-report": [ - "doc_url:https://fbinfer.com/docs/all-issue-types", - "profile:unknown", - "severity:HIGH" - ], - "infer-empty-vector-access": [ - "description:This error type is reported only in C++, in versions >= C++11.", - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#empty_vector_access", - "profile:unknown", - "severity:HIGH" - ], - "infer-execution-time-complexity-increase": [ - "description:Infer reports this issue when the execution time complexity of a program increases in degree: e.g. from constant to linear or from logarithmic to quadratic. This issue type is only reported in differential mode: i.e when we are comparing the cost analysis results of two runs of infer on a file. Check out examples in here.", - "doc_url:https://fbinfer.com/docs/all-issue-types#execution_time_complexity_increase", - "profile:unknown", - "severity:HIGH" - ], - "infer-execution-time-complexity-increase-ui-thread": [ - "description:Infer reports this issue when the execution time complexity of the procedure increases in degree and the procedure runs on the UI (main) thread.", - "doc_url:https://fbinfer.com/docs/all-issue-types#execution_time_complexity_increase_ui_thread", - "profile:unknown", - "severity:HIGH" - ], - "infer-execution-time-unreachable-at-exit": [ - "description:This issue type indicates that the program's execution doesn't reach the exit node (where our analysis computes the final cost of the procedure). Hence, we cannot compute a static bound for the procedure.", - "doc_url:https://fbinfer.com/docs/all-issue-types#execution_time_unreachable_at_exit", - "profile:unknown", - "severity:HIGH" - ], - "infer-expensive-execution-time": [ - "description:[EXPERIMENTAL] This warning indicates that the procedure has non-constant and non-top execution cost. By default, this issue type is disabled. To enable it, set enabled=true in costKind.ml.", - "doc_url:https://fbinfer.com/docs/all-issue-types#expensive_execution_time", - "profile:unknown", - "severity:HIGH" - ], - "infer-expensive-loop-invariant-call": [ - "description:We report this issue type when a function is loop-invariant and also expensive (i.e. at least has linear complexity as determined by the cost analysis).", - "doc_url:https://fbinfer.com/docs/all-issue-types#expensive_loop_invariant_call", - "profile:unknown", - "severity:HIGH" - ], - "infer-exposed-insecure-intent-handling": [ - "description:Undocumented.", - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#exposed_insecure_intent_handling", - "profile:unknown", - "severity:HIGH" - ], - "infer-failure-exe": [ - "doc_url:https://fbinfer.com/docs/all-issue-types", - "profile:unknown", - "severity:LOW" - ], - "infer-guardedby-violation": [ - "description:A field annotated with @GuardedBy is being accessed by a call-chain that starts at a non-private method without synchronization.", - "doc_url:https://fbinfer.com/docs/all-issue-types#guardedby_violation", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-impure-function": [ - "description:This issue type indicates impure functions. For instance, below functions would be marked as impure:", - "doc_url:https://fbinfer.com/docs/all-issue-types#impure_function", - "profile:unknown", - "severity:HIGH" - ], - "infer-inefficient-keyset-iterator": [ - "description:This issue is raised when", - "doc_url:https://fbinfer.com/docs/all-issue-types#inefficient_keyset_iterator", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-inferbo-alloc-is-big": [ - "description:malloc is passed a large constant value (>=10^6). For example, int n = 1000000; malloc(n); generates INFERBO_ALLOC_IS_BIG on malloc(n).", - "doc_url:https://fbinfer.com/docs/all-issue-types#inferbo_alloc_is_big", - "profile:unknown", - "severity:HIGH" - ], - "infer-inferbo-alloc-is-negative": [ - "description:malloc is called with a negative size. For example, int n = 3 - 5; malloc(n); generates INFERBO_ALLOC_IS_NEGATIVE on malloc(n).", - "doc_url:https://fbinfer.com/docs/all-issue-types#inferbo_alloc_is_negative", - "profile:unknown", - "severity:HIGH" - ], - "infer-inferbo-alloc-is-zero": [ - "description:malloc is called with a zero size. For example, int n = 3 - 3; malloc(n); generates INFERBO_ALLOC_IS_ZERO on malloc(n).", - "doc_url:https://fbinfer.com/docs/all-issue-types#inferbo_alloc_is_zero", - "profile:unknown", - "severity:HIGH" - ], - "infer-inferbo-alloc-may-be-big": [ - "description:malloc may be called with a large value. For example, int n = b ? 3 : 1000000; malloc(n); generates INFERBO_ALLOC_MAY_BE_BIG on malloc(n).", - "doc_url:https://fbinfer.com/docs/all-issue-types#inferbo_alloc_may_be_big", - "profile:unknown", - "severity:HIGH" - ], - "infer-inferbo-alloc-may-be-negative": [ - "description:malloc may be called with a negative value. For example, int n = b ? 3 : -5; malloc(n); generates INFERBO_ALLOC_MAY_BE_NEGATIVE on malloc(n).", - "doc_url:https://fbinfer.com/docs/all-issue-types#inferbo_alloc_may_be_negative", - "profile:unknown", - "severity:HIGH" - ], - "infer-infinite-execution-time": [ - "description:This warning indicates that Infer was not able to determine a static upper bound on the execution cost of the procedure. By default, this issue type is disabled.", - "doc_url:https://fbinfer.com/docs/all-issue-types#infinite_execution_time", - "profile:unknown", - "severity:HIGH" - ], - "infer-inherently-dangerous-function": [ - "doc_url:https://fbinfer.com/docs/all-issue-types", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-insecure-intent-handling": [ - "description:Undocumented.", - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#insecure_intent_handling", - "profile:unknown", - "severity:HIGH" - ], - "infer-integer-overflow-l1": [ - "description:This is reported when integer overflow occurred by integer operations such as addition, subtraction, and multiplication. For example, int n = INT_MAX; int m = n + 3; generates a INTEGER_OVERFLOW_L1 on n + 3.", - "doc_url:https://fbinfer.com/docs/all-issue-types#integer_overflow_l1", - "profile:unknown", - "severity:HIGH" - ], - "infer-integer-overflow-l2": [ - "description:See INTEGER_OVERFLOW_L1", - "doc_url:https://fbinfer.com/docs/all-issue-types#integer_overflow_l2", - "profile:unknown", - "severity:HIGH" - ], - "infer-integer-overflow-l5": [ - "description:See INTEGER_OVERFLOW_L1", - "doc_url:https://fbinfer.com/docs/all-issue-types#integer_overflow_l5", - "profile:unknown", - "severity:HIGH" - ], - "infer-integer-overflow-u5": [ - "description:See INTEGER_OVERFLOW_L1", - "doc_url:https://fbinfer.com/docs/all-issue-types#integer_overflow_u5", - "profile:unknown", - "severity:HIGH" - ], - "infer-interface-not-thread-safe": [ - "description:This error indicates that you have invoked an interface method not annotated with @ThreadSafe from a thread-safe context (e.g., code that uses locks or is marked @ThreadSafe). The fix is to add the @ThreadSafe annotation to the interface or to the interface method. For background on why these annotations are needed, see the detailed explanation here.", - "doc_url:https://fbinfer.com/docs/all-issue-types#interface_not_thread_safe", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-invalid-sil": [ - "description:The SIL instruction does not conform to the expected subset of instructions expected for the front-end of the language for the analyzed code.", - "doc_url:https://fbinfer.com/docs/all-issue-types#invalid_sil", - "profile:unknown", - "severity:HIGH" - ], - "infer-invariant-call": [ - "description:We report this issue type when a function call is loop-invariant and hoistable, i.e.", - "doc_url:https://fbinfer.com/docs/all-issue-types#invariant_call", - "profile:unknown", - "severity:HIGH" - ], - "infer-ipc-on-ui-thread": [ - "description:A blocking Binder IPC call occurs on the UI thread.", - "doc_url:https://fbinfer.com/docs/all-issue-types#ipc_on_ui_thread", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-internal-error": [ - "doc_url:https://fbinfer.com/docs/all-issue-types", - "profile:unknown", - "severity:HIGH" - ], - "infer-javascript-injection": [ - "description:Untrusted data flows into JavaScript.", - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#javascript_injection", - "profile:unknown", - "severity:HIGH" - ], - "infer-lab-resource-leak": [ - "description:Toy issue.", - "doc_url:https://fbinfer.com/docs/all-issue-types#lab_resource_leak", - "profile:unknown", - "severity:HIGH" - ], - "infer-lockless-violation": [ - "description:A method implements an interface signature annotated with @Lockless but which transitively acquires a lock.", - "doc_url:https://fbinfer.com/docs/all-issue-types#lockless_violation", - "profile:unknown", - "severity:HIGH" - ], - "infer-lock-consistency-violation": [ - "description:This is an error reported on C++ and Objective C classes whenever:", - "doc_url:https://fbinfer.com/docs/all-issue-types#lock_consistency_violation", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-logging-private-data": [ - "description:Undocumented.", - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#logging_private_data", - "profile:unknown", - "severity:HIGH" - ], - "infer-leak-after-array-abstraction": [ - "doc_url:https://fbinfer.com/docs/all-issue-types", - "profile:unknown", - "severity:HIGH" - ], - "infer-leak-in-footprint": [ - "doc_url:https://fbinfer.com/docs/all-issue-types", - "profile:unknown", - "severity:HIGH" - ], - "infer-leak-unknown-origin": [ - "doc_url:https://fbinfer.com/docs/all-issue-types", - "profile:unknown", - "severity:HIGH" - ], - "infer-memory-leak-c": [ - "description:Memory leak in C", - "doc_url:https://fbinfer.com/docs/all-issue-types#memory_leak_c", - "profile:unknown", - "severity:HIGH" - ], - "infer-memory-leak-cpp": [ - "description:See MEMORY_LEAK_C", - "doc_url:https://fbinfer.com/docs/all-issue-types#memory_leak_cpp", - "profile:unknown", - "severity:HIGH" - ], - "infer-missing-required-prop": [ - "description:This issues is reported when a required @Prop is missing.", - "doc_url:https://fbinfer.com/docs/all-issue-types#missing_required_prop", - "profile:unknown", - "severity:HIGH" - ], - "infer-mixed-self-weakself": [ - "description:This check reports an issue when an Objective-C block captures both self and weakSelf, a weak pointer to self. Possibly the developer meant to capture only weakSelf to avoid a retain cycle, but made a typo and used self instead of strongSelf. In this case, this could cause a retain cycle.", - "doc_url:https://fbinfer.com/docs/all-issue-types#mixed_self_weakself", - "profile:unknown", - "severity:HIGH" - ], - "infer-modifies-immutable": [ - "description:This issue type indicates modifications to fields marked as @Immutable. For instance, below function mutateArray would be marked as modifying immutable field testArray:", - "doc_url:https://fbinfer.com/docs/all-issue-types#modifies_immutable", - "profile:unknown", - "severity:HIGH" - ], - "infer-multiple-weakself": [ - "description:This check reports when an Objective-C block uses weakSelf (a weak pointer to self) more than once. This could lead to unexpected behaviour. Even if weakSelf is not nil in the first use, it could be nil in the following uses since the object that weakSelf points to could be freed anytime.", - "doc_url:https://fbinfer.com/docs/all-issue-types#multiple_weakself", - "profile:unknown", - "severity:HIGH" - ], - "infer-mutual-recursion-cycle": [ - "description:A recursive call or mutually recursive call has been detected. This does not mean that the program won't terminate, just that the code is recursive. You should double-check if the recursion is intended and if it can lead to non-termination or a stack overflow.", - "doc_url:https://fbinfer.com/docs/all-issue-types#mutual_recursion_cycle", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-missing-fld": [ - "doc_url:https://fbinfer.com/docs/all-issue-types", - "profile:unknown", - "severity:HIGH" - ], - "infer-nil-block-call": [ - "description:This check reports when one tries to call an Objective-C block that is nil. This causes a crash.", - "doc_url:https://fbinfer.com/docs/all-issue-types#nil_block_call", - "profile:unknown", - "severity:HIGH" - ], - "infer-nil-block-call-latent": [ - "description:A latent NIL_BLOCK_CALL. See the documentation on Pulse latent issues.", - "doc_url:https://fbinfer.com/docs/all-issue-types#nil_block_call_latent", - "profile:unknown", - "severity:HIGH" - ], - "infer-nil-insertion-into-collection": [ - "description:This checks reports when nil is passed to collections in Objective-C such as arrays and dictionaries. This causes a crash.", - "doc_url:https://fbinfer.com/docs/all-issue-types#nil_insertion_into_collection", - "profile:unknown", - "severity:HIGH" - ], - "infer-nil-insertion-into-collection-latent": [ - "description:A latent NIL_INSERTION_INTO_COLLECTION. See the documentation on Pulse latent issues.", - "doc_url:https://fbinfer.com/docs/all-issue-types#nil_insertion_into_collection_latent", - "profile:unknown", - "severity:HIGH" - ], - "infer-nil-messaging-to-non-pod": [ - "description:In Objective-C, calling a method on nil (or in Objective-C terms, sending a message to nil) does not crash, it simply returns a falsy value (nil/0/false). However, sending a message that returns a non-POD C++ type (POD being \"Plain Old Data\", essentially anything that cannot be compiled as a C-style struct) to nil causes undefined behaviour.", - "doc_url:https://fbinfer.com/docs/all-issue-types#nil_messaging_to_non_pod", - "profile:unknown", - "severity:HIGH" - ], - "infer-nil-messaging-to-non-pod-latent": [ - "description:A latent NIL_MESSAGING_TO_NON_POD. See the documentation on Pulse latent issues.", - "doc_url:https://fbinfer.com/docs/all-issue-types#nil_messaging_to_non_pod_latent", - "profile:unknown", - "severity:HIGH" - ], - "infer-no-matching-branch-in-try": [ - "description:No matching branch is found when evaluating the of section of a try expression. Corresponds to the {try_clause,V} error in the Erlang runtime.", - "doc_url:https://fbinfer.com/docs/all-issue-types#no_matching_branch_in_try", - "profile:unknown", - "severity:HIGH" - ], - "infer-no-matching-branch-in-try-latent": [ - "description:A latent NO_MATCHING_BRANCH_IN_TRY. See the documentation on Pulse latent issues.", - "doc_url:https://fbinfer.com/docs/all-issue-types#no_matching_branch_in_try_latent", - "profile:unknown", - "severity:HIGH" - ], - "infer-no-matching-case-clause": [ - "description:No matching case clause in Erlang: Reports an error when none of the clauses of a case match the expression. Corresponds to the {case_clause,V} error in the Erlang runtime.", - "doc_url:https://fbinfer.com/docs/all-issue-types#no_matching_case_clause", - "profile:unknown", - "severity:HIGH" - ], - "infer-no-matching-case-clause-latent": [ - "description:A latent NO_MATCHING_CASE_CLAUSE. See the documentation on Pulse latent issues.", - "doc_url:https://fbinfer.com/docs/all-issue-types#no_matching_case_clause_latent", - "profile:unknown", - "severity:HIGH" - ], - "infer-no-matching-else-clause": [ - "description:No matching else clause in Erlang: Reports an error when none of the clauses of an else match the short-circuit result from maybe body. Corresponds to the {else_clause,V} error in the Erlang runtime.", - "doc_url:https://fbinfer.com/docs/all-issue-types#no_matching_else_clause", - "profile:unknown", - "severity:HIGH" - ], - "infer-no-matching-else-clause-latent": [ - "description:A latent NO_MATCHING_ELSE_CLAUSE. See the documentation on Pulse latent issues.", - "doc_url:https://fbinfer.com/docs/all-issue-types#no_matching_else_clause_latent", - "profile:unknown", - "severity:HIGH" - ], - "infer-no-matching-function-clause": [ - "description:No matching function clause in Erlang: Reports an error when none of the clauses of a function match the arguments of a call. Corresponds to the function_clause error in the Erlang runtime.", - "doc_url:https://fbinfer.com/docs/all-issue-types#no_matching_function_clause", - "profile:unknown", - "severity:HIGH" - ], - "infer-no-matching-function-clause-latent": [ - "description:A latent NO_MATCHING_FUNCTION_CLAUSE. See the documentation on Pulse latent issues.", - "doc_url:https://fbinfer.com/docs/all-issue-types#no_matching_function_clause_latent", - "profile:unknown", - "severity:HIGH" - ], - "infer-no-match-of-rhs": [ - "description:No match of right hand side value in Erlang: Reports an error when the right hand side value of a match expression does not match the pattern on the left hand side. Corresponds to the {badmatch,V} error in the Erlang runtime.", - "doc_url:https://fbinfer.com/docs/all-issue-types#no_match_of_rhs", - "profile:unknown", - "severity:HIGH" - ], - "infer-no-match-of-rhs-latent": [ - "description:A latent NO_MATCH_OF_RHS. See the documentation on Pulse latent issues.", - "doc_url:https://fbinfer.com/docs/all-issue-types#no_match_of_rhs_latent", - "profile:unknown", - "severity:HIGH" - ], - "infer-no-true-branch-in-if": [ - "description:No true branch when evaluating an if expression in Erlang: Reports an error when none of the branches of an if expression evaluate to true. Corresponds to the if_clause error in the Erlang runtime.", - "doc_url:https://fbinfer.com/docs/all-issue-types#no_true_branch_in_if", - "profile:unknown", - "severity:HIGH" - ], - "infer-no-true-branch-in-if-latent": [ - "description:A latent NO_TRUE_BRANCH_IN_IF. See the documentation on Pulse latent issues.", - "doc_url:https://fbinfer.com/docs/all-issue-types#no_true_branch_in_if_latent", - "profile:unknown", - "severity:HIGH" - ], - "infer-nullptr-dereference": [ - "description:Infer reports null dereference bugs in Java, C, C++, and Objective-C when it is possible that the null pointer is dereferenced, leading to a crash.", - "doc_url:https://fbinfer.com/docs/all-issue-types#nullptr_dereference", - "profile:unknown", - "severity:HIGH" - ], - "infer-nullptr-dereference-in-nullsafe-class": [ - "description:Infer reports null dereference bugs in Java, C, C++, and Objective-C when it is possible that the null pointer is dereferenced, leading to a crash.", - "doc_url:https://fbinfer.com/docs/all-issue-types#nullptr_dereference_in_nullsafe_class", - "profile:unknown", - "severity:HIGH" - ], - "infer-nullptr-dereference-in-nullsafe-class-latent": [ - "description:A latent NULLPTR_DEREFERENCE_IN_NULLSAFE_CLASS. See the documentation on Pulse latent issues.", - "doc_url:https://fbinfer.com/docs/all-issue-types#nullptr_dereference_in_nullsafe_class_latent", - "profile:unknown", - "severity:HIGH" - ], - "infer-nullptr-dereference-latent": [ - "description:A latent NULLPTR_DEREFERENCE. See the documentation on Pulse latent issues.", - "doc_url:https://fbinfer.com/docs/all-issue-types#nullptr_dereference_latent", - "profile:unknown", - "severity:HIGH" - ], - "infer-null-argument": [ - "description:This issue type indicates `nil` being passed as argument where a non-nil value expected.", - "doc_url:https://fbinfer.com/docs/all-issue-types#null_argument", - "profile:unknown", - "severity:HIGH" - ], - "infer-null-argument-latent": [ - "description:A latent NULL_ARGUMENT. See the documentation on Pulse latent issues.", - "doc_url:https://fbinfer.com/docs/all-issue-types#null_argument_latent", - "profile:unknown", - "severity:HIGH" - ], - "infer-null-dereference": [ - "description:See NULLPTR_DEREFERENCE.", - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#null_dereference", - "profile:unknown", - "severity:HIGH" - ], - "infer-optional-empty-access": [ - "description:Optional Empty Access warnings are reported when we try to retrieve the value of a folly::Optional when it is empty (i.e. folly::none).", - "doc_url:https://fbinfer.com/docs/all-issue-types#optional_empty_access", - "profile:unknown", - "severity:HIGH" - ], - "infer-optional-empty-access-latent": [ - "description:A latent OPTIONAL_EMPTY_ACCESS. See the documentation on Pulse latent issues.", - "doc_url:https://fbinfer.com/docs/all-issue-types#optional_empty_access_latent", - "profile:unknown", - "severity:HIGH" - ], - "infer-precondition-not-found": [ - "doc_url:https://fbinfer.com/docs/all-issue-types", - "profile:unknown", - "severity:HIGH" - ], - "infer-precondition-not-met": [ - "doc_url:https://fbinfer.com/docs/all-issue-types", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-premature-nil-termination-argument": [ - "description:This error type is reported in C and Objective-C. In many variadic methods, nil is used to signify the end of the list of input objects. This is similar to nil-termination of C strings. If one of the arguments that is not the last argument to the method is nil as well, Infer reports an error because that may lead to unexpected behavior.", - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#premature_nil_termination_argument", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-pulse-cannot-instantiate-abstract-class": [ - "description:Instantiating an abstract class will lead to Cannot instantiate abstract class error.", - "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_cannot_instantiate_abstract_class", - "profile:unknown", - "severity:HIGH" - ], - "infer-pulse-const-refable": [ - "description:This issue is reported when a function parameter is a) passed by value and b) is not modified inside the function. Instead, parameter can be passed by const reference, i.e. converted to a const& so that no unnecessary copy is created at the callsite of the function.", - "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_const_refable", - "profile:unknown", - "severity:HIGH" - ], - "infer-pulse-dict-missing-key": [ - "description:This issue is similar to PULSE_UNINITIALIZED_VALUE, but it is to warn reading a missing key of dictionary in Hack.", - "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_dict_missing_key", - "profile:unknown", - "severity:HIGH" - ], - "infer-pulse-dynamic-type-mismatch": [ - "description:This error is reported in Hack. It fires when we detect an operation that is incompatible with the dynamic type of its arguments.", - "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_dynamic_type_mismatch", - "profile:unknown", - "severity:HIGH" - ], - "infer-pulse-readonly-shared-ptr-param": [ - "description:This issue is reported when a shared pointer parameter is a) passed by value and b) is used only for reading, rather than lifetime extension. At the callsite, this might cause a potentially expensive unnecessary copy of the shared pointer, especially when many number of threads are sharing it. To avoid this, consider 1) passing the raw pointer instead and 2) use std::shared_ptr::get at callsites.", - "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_readonly_shared_ptr_param", - "profile:unknown", - "severity:HIGH" - ], - "infer-pulse-reference-stability": [ - "description:The family of maps folly::F14ValueMap, folly::F14VectorMap, and by extension folly::F14FastMap differs slightly from std::unordered_map as it does not provide reference stability. When the map resizes such as when reserve is called or new elements are added, all existing references become invalid and should not be used.", - "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_reference_stability", - "profile:unknown", - "severity:HIGH" - ], - "infer-pulse-resource-leak": [ - "description:See RESOURCE_LEAK", - "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_resource_leak", - "profile:unknown", - "severity:HIGH" - ], - "infer-pulse-transitive-access": [ - "description:This issue tracks spurious accesses that are reachable from specific entry functions.", - "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_transitive_access", - "profile:unknown", - "severity:HIGH" - ], - "infer-pulse-unawaited-awaitable": [ - "description:Awaitable values created by calls to asynchronous methods should eventually be awaited along all codepaths (even if their value is unused). Hence the following is not OK", - "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_unawaited_awaitable", - "profile:unknown", - "severity:HIGH" - ], - "infer-pulse-uninitialized-const": [ - "description:This issue is similar to PULSE_UNINITIALIZED_VALUE, but it is to detect the uninitialized abstract const value in Hack.", - "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_uninitialized_const", - "profile:unknown", - "severity:HIGH" - ], - "infer-pulse-uninitialized-value": [ - "description:The code uses a variable that has not been initialized, leading to unpredictable or unintended results.", - "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_uninitialized_value", - "profile:unknown", - "severity:HIGH" - ], - "infer-pulse-unnecessary-copy": [ - "description:This is reported when Infer detects an unnecessary copy of an object via copy constructor where neither the source nor the copied variable are modified before the variable goes out of scope. Rather than the copy, a reference to the source object could be used to save memory.", - "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_unnecessary_copy", - "profile:unknown", - "severity:HIGH" - ], - "infer-pulse-unnecessary-copy-assignment": [ - "description:See PULSE_UNNECESSARY_COPY.", - "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_unnecessary_copy_assignment", - "profile:unknown", - "severity:HIGH" - ], - "infer-pulse-unnecessary-copy-assignment-const": [ - "description:See PULSE_UNNECESSARY_COPY.", - "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_unnecessary_copy_assignment_const", - "profile:unknown", - "severity:HIGH" - ], - "infer-pulse-unnecessary-copy-assignment-movable": [ - "description:See PULSE_UNNECESSARY_COPY_MOVABLE.", - "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_unnecessary_copy_assignment_movable", - "profile:unknown", - "severity:HIGH" - ], - "infer-pulse-unnecessary-copy-intermediate": [ - "description:This is reported when Infer detects an unnecessary temporary copy of an intermediate object where copy is created to be passed down to a function unnecessarily. Instead, the intermediate object should either be moved into the callee or the type of the callee's parameter should be made const &.", - "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_unnecessary_copy_intermediate", - "profile:unknown", - "severity:HIGH" - ], - "infer-pulse-unnecessary-copy-intermediate-const": [ - "description:See PULSE_UNNECESSARY_COPY.", - "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_unnecessary_copy_intermediate_const", - "profile:unknown", - "severity:HIGH" - ], - "infer-pulse-unnecessary-copy-movable": [ - "description:This is reported when Infer detects an unnecessary copy into a field where", - "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_unnecessary_copy_movable", - "profile:unknown", - "severity:HIGH" - ], - "infer-pulse-unnecessary-copy-optional": [ - "description:This is reported when Infer detects an unnecessary copy of an object via optional value construction where the source is not modified before it goes out of scope. To avoid the copy, we can move the source object or change the callee's type.", - "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_unnecessary_copy_optional", - "profile:unknown", - "severity:HIGH" - ], - "infer-pulse-unnecessary-copy-optional-const": [ - "description:See PULSE_UNNECESSARY_COPY_OPTIONAL.", - "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_unnecessary_copy_optional_const", - "profile:unknown", - "severity:HIGH" - ], - "infer-pulse-unnecessary-copy-return": [ - "description:This is similar to PULSE_UNNECESSARY_COPY, but reported when a callee returns a copied value and it is not modified in its caller. We may be able to return const-ref typed value or try std::move to avoid the copy.", - "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_unnecessary_copy_return", - "profile:unknown", - "severity:HIGH" - ], - "infer-pure-function": [ - "description:This issue type indicates pure functions. For instance, below functions would be marked as pure:", - "doc_url:https://fbinfer.com/docs/all-issue-types#pure_function", - "profile:unknown", - "severity:HIGH" - ], - "infer-quandary-taint-error": [ - "description:Generic taint error when nothing else fits.", - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#quandary_taint_error", - "profile:unknown", - "severity:HIGH" - ], - "infer-regex-op-on-ui-thread": [ - "description:A potentially costly operation on a regular expression occurs on the UI thread.", - "doc_url:https://fbinfer.com/docs/all-issue-types#regex_op_on_ui_thread", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-resource-leak": [ - "description:Infer reports resource leaks in C, Objective-C and Java. In general, resources are entities such as files, sockets, connections, etc, that need to be closed after being used.", - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#resource_leak", - "profile:unknown", - "severity:HIGH" - ], - "infer-retain-cycle": [ - "description:A retain cycle is a situation when object A retains object B, and object B retains object A at the same time. Here is an example:", - "doc_url:https://fbinfer.com/docs/all-issue-types#retain_cycle", - "profile:unknown", - "severity:HIGH" - ], - "infer-retain-cycle-no-weak-info": [ - "description:A retain cycle is a situation when object A retains object B, and object B retains object A at the same time. Here is an example:", - "doc_url:https://fbinfer.com/docs/all-issue-types#retain_cycle_no_weak_info", - "profile:unknown", - "severity:HIGH" - ], - "infer-scope-leakage": [ - "description:This issue type indicates that a class with scope annotation A stores a field with whose (dynamic) type (or one of its super types) is annotated with scope B such that a scope nesting restriction is violated. By \"stores\", we mean either directly or transitively.", - "doc_url:https://fbinfer.com/docs/all-issue-types#scope_leakage", - "profile:unknown", - "severity:HIGH" - ], - "infer-sensitive-data-flow": [ - "description:A flow of sensitive data was detected from a source.", - "doc_url:https://fbinfer.com/docs/all-issue-types#sensitive_data_flow", - "profile:unknown", - "severity:STYLE" - ], - "infer-shell-injection": [ - "description:Environment variable or file data flowing to shell.", - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#shell_injection", - "profile:unknown", - "severity:HIGH" - ], - "infer-shell-injection-risk": [ - "description:Code injection if the caller of the endpoint doesn't sanitize on its end.", - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#shell_injection_risk", - "profile:unknown", - "severity:HIGH" - ], - "infer-skip-function": [ - "doc_url:https://fbinfer.com/docs/all-issue-types", - "profile:unknown", - "severity:LOW" - ], - "infer-sql-injection": [ - "description:Untrusted and unescaped data flows to SQL.", - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#sql_injection", - "profile:unknown", - "severity:HIGH" - ], - "infer-sql-injection-risk": [ - "description:Untrusted and unescaped data flows to SQL.", - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#sql_injection_risk", - "profile:unknown", - "severity:HIGH" - ], - "infer-stack-variable-address-escape": [ - "description:Reported when an address pointing into the stack of the current function will escape to its calling context. Such addresses will become invalid by the time the function actually returns so are potentially dangerous.", - "doc_url:https://fbinfer.com/docs/all-issue-types#stack_variable_address_escape", - "profile:unknown", - "severity:HIGH" - ], - "infer-starvation": [ - "description:This error is reported in Java, and specifically on Android. These reports are triggered when a method that runs on the UI thread may block, thus potentially leading to an Application Not Responding error.", - "doc_url:https://fbinfer.com/docs/all-issue-types#starvation", - "profile:unknown", - "severity:HIGH" - ], - "infer-static-initialization-order-fiasco": [ - "description:This error is reported in C++. It fires when the initialization of a static variable A, accesses a static variable B from another translation unit (usually another .cpp file). There are no guarantees whether B has been already initialized or not at that point.", - "doc_url:https://fbinfer.com/docs/all-issue-types#static_initialization_order_fiasco", - "profile:unknown", - "severity:HIGH" - ], - "infer-strict-mode-violation": [ - "description:Android has a feature called strict mode, which if enabled, will flag the occasions where the main thread makes a call that results in disk I/O, waiting on a network socket, etc. The analysis catching starvation errors and deadlocks (the --starvation analysis) has the ability to statically detect such violations.", - "doc_url:https://fbinfer.com/docs/all-issue-types#strict_mode_violation", - "profile:unknown", - "severity:HIGH" - ], - "infer-strong-self-not-checked": [ - "description:This checks reports a potential issue when a block captures weakSelf (a weak pointer to self), then one assigns this pointer to a local variable strongSelf inside the block and uses this variable without checking first whether it is nil. The problem here is that the weak pointer could be nil at the time when the block is executed. So, the correct usage is to first check whether strongSelf is a valid pointer, and then use it.", - "doc_url:https://fbinfer.com/docs/all-issue-types#strong_self_not_checked", - "profile:unknown", - "severity:HIGH" - ], - "infer-symexec-memory-error": [ - "doc_url:https://fbinfer.com/docs/all-issue-types", - "profile:unknown", - "severity:HIGH" - ], - "infer-taint-error": [ - "description:A taint flow was detected from a source to a sink", - "doc_url:https://fbinfer.com/docs/all-issue-types#taint_error", - "profile:unknown", - "severity:HIGH" - ], - "infer-thread-safety-violation": [ - "description:This warning indicates a potential data race in Java. The analyser is called RacerD and this section gives brief but a mostly complete description of its features. See the RacerD page for more in-depth information and examples.", - "doc_url:https://fbinfer.com/docs/all-issue-types#thread_safety_violation", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-topl-error": [ - "description:A violation of a Topl property (user-specified). There is an execution path in the code that drives a Topl property from a start state to an error state.", - "doc_url:https://fbinfer.com/docs/all-issue-types#topl_error", - "profile:unknown", - "severity:HIGH" - ], - "infer-topl-error-latent": [ - "description:A latent TOPL_ERROR. See the documentation on Pulse latent issues.", - "doc_url:https://fbinfer.com/docs/all-issue-types#topl_error_latent", - "profile:unknown", - "severity:HIGH" - ], - "infer-unreachable-code": [ - "doc_url:https://fbinfer.com/docs/all-issue-types", - "profile:unknown", - "severity:HIGH" - ], - "infer-untrusted-buffer-access": [ - "description:Untrusted data of any kind flowing to buffer.", - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#untrusted_buffer_access", - "profile:unknown", - "severity:HIGH" - ], - "infer-untrusted-deserialization": [ - "description:User-controlled deserialization.", - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#untrusted_deserialization", - "profile:unknown", - "severity:HIGH" - ], - "infer-untrusted-deserialization-risk": [ - "description:User-controlled deserialization", - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#untrusted_deserialization_risk", - "profile:unknown", - "severity:HIGH" - ], - "infer-untrusted-environment-change-risk": [ - "description:User-controlled environment mutation.", - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#untrusted_environment_change_risk", - "profile:unknown", - "severity:HIGH" - ], - "infer-untrusted-file": [ - "description:User-controlled file creation; may be vulnerable to path traversal and more.", - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#untrusted_file", - "profile:unknown", - "severity:HIGH" - ], - "infer-untrusted-file-risk": [ - "description:User-controlled file creation; may be vulnerable to path traversal and more.", - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#untrusted_file_risk", - "profile:unknown", - "severity:HIGH" - ], - "infer-untrusted-heap-allocation": [ - "description:Untrusted data of any kind flowing to heap allocation. this can cause crashes or DOS.", - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#untrusted_heap_allocation", - "profile:unknown", - "severity:HIGH" - ], - "infer-untrusted-intent-creation": [ - "description:Creating an Intent from user-controlled data.", - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#untrusted_intent_creation", - "profile:unknown", - "severity:HIGH" - ], - "infer-untrusted-url-risk": [ - "description:Untrusted flag, environment variable, or file data flowing to URL.", - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#untrusted_url_risk", - "profile:unknown", - "severity:HIGH" - ], - "infer-untrusted-variable-length-array": [ - "description:Untrusted data of any kind flowing to stack buffer allocation. Trying to allocate a stack buffer that's too large will cause a stack overflow.", - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#untrusted_variable_length_array", - "profile:unknown", - "severity:HIGH" - ], - "infer-user-controlled-sql-risk": [ - "description:Untrusted data flows to SQL (no injection risk).", - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#user_controlled_sql_risk", - "profile:unknown", - "severity:HIGH" - ], - "infer-use-after-delete": [ - "description:An address that was invalidated by a call to delete in C++ is dereferenced.", - "doc_url:https://fbinfer.com/docs/all-issue-types#use_after_delete", - "profile:unknown", - "severity:HIGH" - ], - "infer-use-after-delete-latent": [ - "description:A latent USE_AFTER_DELETE. See the documentation on Pulse latent issues.", - "doc_url:https://fbinfer.com/docs/all-issue-types#use_after_delete_latent", - "profile:unknown", - "severity:HIGH" - ], - "infer-use-after-free": [ - "description:An address that was invalidated by a call to free in C is dereferenced.", - "doc_url:https://fbinfer.com/docs/all-issue-types#use_after_free", - "profile:unknown", - "severity:HIGH" - ], - "infer-use-after-free-latent": [ - "description:A latent USE_AFTER_FREE. See the documentation on Pulse latent issues.", - "doc_url:https://fbinfer.com/docs/all-issue-types#use_after_free_latent", - "profile:unknown", - "severity:HIGH" - ], - "infer-use-after-lifetime": [ - "description:The lifetime of an object has ended but that object is being accessed. For example, the address of a variable holding a C++ object is accessed after the variable has gone out of scope:", - "doc_url:https://fbinfer.com/docs/all-issue-types#use_after_lifetime", - "profile:unknown", - "severity:HIGH" - ], - "infer-use-after-lifetime-latent": [ - "description:A latent USE_AFTER_LIFETIME. See the documentation on Pulse latent issues.", - "doc_url:https://fbinfer.com/docs/all-issue-types#use_after_lifetime_latent", - "profile:unknown", - "severity:HIGH" - ], - "infer-vector-invalidation": [ - "description:An address pointing into a C++ std::vector might have become invalid. This can happen when an address is taken into a vector, then the vector is mutated in a way that might invalidate the address, for example by adding elements to the vector, which might trigger a re-allocation of the entire vector contents (thereby invalidating the pointers into the previous location of the contents).", - "doc_url:https://fbinfer.com/docs/all-issue-types#vector_invalidation", - "profile:unknown", - "severity:HIGH" - ], - "infer-vector-invalidation-latent": [ - "description:A latent VECTOR_INVALIDATION. See the documentation on Pulse latent issues.", - "doc_url:https://fbinfer.com/docs/all-issue-types#vector_invalidation_latent", - "profile:unknown", - "severity:HIGH" - ], - "infer-weak-self-in-no-escape-block": [ - "description:This check reports when weakSelf (a weak pointer to self) is used in a block, and this block is passed to a \"no escaping\" method. This means that the block passed to that method won't be leaving the current scope, this is marked with the annotation NS_NOESCAPE.", - "doc_url:https://fbinfer.com/docs/all-issue-types#weak_self_in_no_escape_block", - "profile:unknown", - "severity:HIGH" - ], - "infer-wrong-argument-number": [ - "doc_url:https://fbinfer.com/docs/all-issue-types", - "profile:unknown", - "severity:HIGH" - ], - "infer-assign-pointer-MEDIUM": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#assign_pointer_warning", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-autoreleasepool-size-complexity-increase": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#autoreleasepool_size_complexity_increase", - "profile:unknown", - "severity:HIGH" - ], - "infer-autoreleasepool-size-complexity-increase-ui-thread": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#autoreleasepool_size_complexity_increase_ui_thread", - "profile:unknown", - "severity:HIGH" - ], - "infer-autoreleasepool-size-unreachable-at-exit": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#autoreleasepool_size_unreachable_at_exit", - "profile:unknown", - "severity:HIGH" - ], - "infer-bad-pointer-comparison": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#bad_pointer_comparison", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-checkers-annotation-reachability-HIGH": [ - "doc_url:https://fbinfer.com/docs/all-issue-types#checkers_annotation_reachability_error", - "profile:unknown", - "severity:HIGH" - ], - "infer-checkers-immutable-cast": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#checkers_immutable_cast", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-component-with-multiple-factory-methods": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#component_with_multiple_factory_methods", - "profile:unknown", - "severity:LOW" - ], - "infer-config-checks-between-markers": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#config_checks_between_markers", - "profile:unknown", - "severity:LOW" - ], - "infer-cxx-reference-captured-in-objc-block": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#cxx_reference_captured_in_objc_block", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-direct-atomic-property-access": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#direct_atomic_property_access", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-discouraged-weak-property-custom-setter": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#discouraged_weak_property_custom_setter", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-dotnet-resource-leak": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#dotnet_resource_leak", - "profile:unknown", - "severity:HIGH" - ], - "infer-eradicate-annotation-graph": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_annotation_graph", - "profile:unknown", - "severity:STYLE" - ], - "infer-eradicate-bad-nested-class-annotation": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_bad_nested_class_annotation", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-eradicate-condition-redundant": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_condition_redundant", - "profile:unknown", - "severity:LOW" - ], - "infer-eradicate-field-not-initialized": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_field_not_initialized", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-eradicate-field-not-nullable": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_field_not_nullable", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-eradicate-field-over-annotated": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_field_over_annotated", - "profile:unknown", - "severity:LOW" - ], - "infer-eradicate-inconsistent-subclass-parameter-annotation": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_inconsistent_subclass_parameter_annotation", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-eradicate-inconsistent-subclass-return-annotation": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_inconsistent_subclass_return_annotation", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-eradicate-meta-class-can-be-nullsafe": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_meta_class_can_be_nullsafe", - "profile:unknown", - "severity:LOW" - ], - "infer-eradicate-meta-class-is-nullsafe": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_meta_class_is_nullsafe", - "profile:unknown", - "severity:STYLE" - ], - "infer-eradicate-meta-class-needs-improvement": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_meta_class_needs_improvement", - "profile:unknown", - "severity:STYLE" - ], - "infer-eradicate-nullable-dereference": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_nullable_dereference", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-eradicate-parameter-not-nullable": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_parameter_not_nullable", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-eradicate-redundant-nested-class-annotation": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_redundant_nested_class_annotation", - "profile:unknown", - "severity:LOW" - ], - "infer-eradicate-return-not-nullable": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_return_not_nullable", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-eradicate-return-over-annotated": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_return_over_annotated", - "profile:unknown", - "severity:LOW" - ], - "infer-eradicate-unchecked-usage-in-nullsafe": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_unchecked_usage_in_nullsafe", - "profile:unknown", - "severity:UNSPECIFIED" - ], - "infer-eradicate-unvetted-third-party-in-nullsafe": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_unvetted_third_party_in_nullsafe", - "profile:unknown", - "severity:UNSPECIFIED" - ], - "infer-expensive-autoreleasepool-size": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#expensive_autoreleasepool_size", - "profile:unknown", - "severity:HIGH" - ], - "infer-global-variable-initialized-with-function-or-method-call": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#global_variable_initialized_with_function_or_method_call", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-guardedby-violation-nullsafe": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#guardedby_violation_nullsafe", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-infinite-autoreleasepool-size": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#infinite_autoreleasepool_size", - "profile:unknown", - "severity:HIGH" - ], - "infer-ivar-not-null-checked": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#ivar_not_null_checked", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-memory-leak": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#memory_leak", - "profile:unknown", - "severity:HIGH" - ], - "infer-mutable-local-variable-in-component-file": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#mutable_local_variable_in_component_file", - "profile:unknown", - "severity:LOW" - ], - "infer-parameter-not-null-checked": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#parameter_not_null_checked", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-pointer-to-const-objc-class": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#pointer_to_const_objc_class", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-quandary-taint-HIGH": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#quandary_taint_error", - "profile:unknown", - "severity:HIGH" - ], - "infer-strong-delegate-MEDIUM": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#strong_delegate_warning", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-thread-safety-violation-nullsafe": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#thread_safety_violation_nullsafe", - "profile:unknown", - "severity:MEDIUM" - ], - "infer-topl-HIGH": [ - "doc_url:https://fbinfer.com/docs/all-issue-types#topl_error", - "profile:unknown", - "severity:HIGH" - ], - "infer-uninitialized-value": [ - "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#uninitialized_value", - "profile:unknown", - "severity:HIGH" - ], - "infer-internal-HIGH": [ - "doc_url:https://fbinfer.com/docs/all-issue-types", - "profile:unknown", - "severity:HIGH" - ], - "infer-symexec-memory-HIGH": [ - "doc_url:https://fbinfer.com/docs/all-issue-types", - "profile:unknown", - "severity:HIGH" - ] - } + "analyzer": "infer", + "labels": { + "infer-arbitrary-code-execution-under-lock": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#arbitrary_code_execution_under_lock", + "description:A call that may execute arbitrary code (such as registered, or chained, callbacks) is made while holding a lock. This code may deadlock whenever the callbacks obtain locks themselves, so it is an unsafe pattern.", + "profile:unknown", + "severity:HIGH" + ], + "infer-array-out-of-bounds-l1": [ + "doc_url:https://fbinfer.com/docs/all-issue-types", + "profile:unknown", + "severity:HIGH" + ], + "infer-array-out-of-bounds-l2": [ + "doc_url:https://fbinfer.com/docs/all-issue-types", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-array-out-of-bounds-l3": [ + "doc_url:https://fbinfer.com/docs/all-issue-types", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-abduction-case-not-implemented": [ + "doc_url:https://fbinfer.com/docs/all-issue-types", + "profile:unknown", + "severity:HIGH" + ], + "infer-array-of-pointsto": [ + "doc_url:https://fbinfer.com/docs/all-issue-types", + "profile:unknown", + "severity:HIGH" + ], + "infer-assert-failure": [ + "doc_url:https://fbinfer.com/docs/all-issue-types", + "profile:unknown", + "severity:HIGH" + ], + "infer-bad-arg": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#bad_arg", + "description:Bad arg in Erlang: Reports an error when the type of an argument is wrong or the argument is badly formed. Corresponds to the badarg error in the Erlang runtime.", + "profile:unknown", + "severity:HIGH" + ], + "infer-bad-arg-latent": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#bad_arg_latent", + "description:A latent BAD_ARG. See the documentation on Pulse latent issues.", + "profile:unknown", + "severity:HIGH" + ], + "infer-bad-generator": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#bad_generator", + "description:Bad generator in Erlang: Reports an error when a wrong type is used in a generator. Corresponds to the bad_generator error in the Erlang runtime.", + "profile:unknown", + "severity:HIGH" + ], + "infer-bad-generator-latent": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#bad_generator_latent", + "description:A latent BAD_GENERATOR. See the documentation on Pulse latent issues.", + "profile:unknown", + "severity:HIGH" + ], + "infer-bad-key": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#bad_key", + "description:Bad key in Erlang: Reports an error when trying to access or update a non-existing key in a map. Corresponds to the {badkey,K} error in the Erlang runtime.", + "profile:unknown", + "severity:HIGH" + ], + "infer-bad-key-latent": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#bad_key_latent", + "description:A latent BAD_KEY. See the documentation on Pulse latent issues.", + "profile:unknown", + "severity:HIGH" + ], + "infer-bad-map": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#bad_map", + "description:Bad map in Erlang: Reports an error when trying to access or update a key for a term that is not a map. Corresponds to the {badmap,...} error in the Erlang runtime.", + "profile:unknown", + "severity:HIGH" + ], + "infer-bad-map-latent": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#bad_map_latent", + "description:A latent BAD_MAP. See the documentation on Pulse latent issues.", + "profile:unknown", + "severity:HIGH" + ], + "infer-bad-record": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#bad_record", + "description:Bad record in Erlang: Reports an error when trying to access or update a record with the wrong name. Corresponds to the {badrecord,Name} error in the Erlang runtime.", + "profile:unknown", + "severity:HIGH" + ], + "infer-bad-record-latent": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#bad_record_latent", + "description:A latent BAD_RECORD. See the documentation on Pulse latent issues.", + "profile:unknown", + "severity:HIGH" + ], + "infer-bad-return": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#bad_return", + "description:Bad return in Erlang: The dynamic type of a returned value disagrees with the static type given in the spec.", + "profile:unknown", + "severity:HIGH" + ], + "infer-bad-return-latent": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#bad_return_latent", + "description:A latent BAD_RETURN. See the documentation on Pulse latent issues.", + "profile:unknown", + "severity:HIGH" + ], + "infer-biabduction-analysis-stops": [ + "doc_url:https://fbinfer.com/docs/all-issue-types", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-biabduction-memory-leak": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#biabduction_memory_leak", + "description:See MEMORY_LEAK_C.", + "profile:unknown", + "severity:HIGH" + ], + "infer-biabduction-retain-cycle": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#biabduction_retain_cycle", + "description:See RETAIN_CYCLE.", + "profile:unknown", + "severity:HIGH" + ], + "infer-block-parameter-not-null-checked": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#block_parameter_not_null_checked", + "description:This error type is reported only in Objective-C/Objective-C++. It happens when a method has a block as a parameter, and the block is executed in the method's body without checking it for nil first. If a nil block is passed to the method, then this will cause a crash. For example:", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-buffer-overrun-l1": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#buffer_overrun_l1", + "description:This is reported when outside of buffer bound is accessed. It can corrupt memory and may introduce security issues in C/C++.", + "profile:unknown", + "severity:HIGH" + ], + "infer-buffer-overrun-l2": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#buffer_overrun_l2", + "description:See BUFFER_OVERRUN_L1", + "profile:unknown", + "severity:HIGH" + ], + "infer-buffer-overrun-l3": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#buffer_overrun_l3", + "description:See BUFFER_OVERRUN_L1", + "profile:unknown", + "severity:HIGH" + ], + "infer-buffer-overrun-l4": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#buffer_overrun_l4", + "description:See BUFFER_OVERRUN_L1", + "profile:unknown", + "severity:HIGH" + ], + "infer-buffer-overrun-l5": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#buffer_overrun_l5", + "description:See BUFFER_OVERRUN_L1", + "profile:unknown", + "severity:HIGH" + ], + "infer-buffer-overrun-s2": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#buffer_overrun_s2", + "description:See BUFFER_OVERRUN_L1", + "profile:unknown", + "severity:HIGH" + ], + "infer-buffer-overrun-u5": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#buffer_overrun_u5", + "description:See BUFFER_OVERRUN_L1", + "profile:unknown", + "severity:HIGH" + ], + "infer-bad-footprint": [ + "doc_url:https://fbinfer.com/docs/all-issue-types", + "profile:unknown", + "severity:HIGH" + ], + "infer-captured-strong-self": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#captured_strong_self", + "description:This check is about when a strong pointer to self is captured in a block. This could lead to retain cycles or unexpected behavior since to avoid retain cycles one usually uses a local strong pointer or a captured weak pointer instead.", + "profile:unknown", + "severity:HIGH" + ], + "infer-checkers-allocates-memory": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#checkers_allocates_memory", + "description:A method annotated with @NoAllocation transitively calls new.", + "profile:unknown", + "severity:HIGH" + ], + "infer-checkers-annotation-reachability-error": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#checkers_annotation_reachability_error", + "description:A method annotated with an annotation @A transitively calls a method annotated @B where the combination of annotations is forbidden (for example, @UiThread calling @WorkerThread).", + "profile:unknown", + "severity:HIGH" + ], + "infer-checkers-calls-expensive-method": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#checkers_calls_expensive_method", + "description:A method annotated with @PerformanceCritical transitively calls a method annotated @Expensive.", + "profile:unknown", + "severity:HIGH" + ], + "infer-checkers-expensive-overrides-unannotated": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#checkers_expensive_overrides_unannotated", + "description:A method annotated with @Expensive overrides an un-annotated method.", + "profile:unknown", + "severity:HIGH" + ], + "infer-checkers-fragment-retains-view": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#checkers_fragment_retains_view", + "description:This error type is Android-specific. It fires when a Fragment type fails to nullify one or more of its declared View fields in onDestroyView. In performance-sensitive applications, a Fragment should initialize all View's in onCreateView and nullify them in onDestroyView. If a Fragment is placed on the back stack and fails to nullify a View in onDestroyView, it will retain a useless reference to that View that will not be cleaned up until the Fragment is resumed or destroyed.", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-checkers-printf-args": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#checkers_printf_args", + "description:This error is reported when the argument types to a printf method do not match the format string.", + "profile:unknown", + "severity:HIGH" + ], + "infer-class-cast-exception": [ + "doc_url:https://fbinfer.com/docs/all-issue-types", + "profile:unknown", + "severity:HIGH" + ], + "infer-condition-always-false": [ + "doc_url:https://fbinfer.com/docs/all-issue-types", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-condition-always-true": [ + "doc_url:https://fbinfer.com/docs/all-issue-types", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-config-impact": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#config_impact", + "description:Infer reports this issue when an expensive function is called without a config check. The config is usually a boolean value that enables experimental new features and it is defined per application/codebase, e.g. gatekeepers. To determine whether a function is expensive or not, the checker relies on modeled functions that are assumed to be expensive, e.g. string operations, regular expression match, or DB accesses.", + "profile:unknown", + "severity:STYLE" + ], + "infer-config-impact-strict": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#config_impact_strict", + "description:This is similar to CONFIG_IMPACT issue but the analysis reports all ungated codes irrespective of whether they are expensive or not.", + "profile:unknown", + "severity:STYLE" + ], + "infer-config-usage": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#config_usage", + "description:Infer reports this issue when a config value is used as branch condition in a function. The config is usually a boolean value that enables experimental new features and it is defined per application/codebase, e.g. gatekeepers.", + "profile:unknown", + "severity:LOW" + ], + "infer-constant-address-dereference": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#constant_address_dereference", + "description:This is reported when an address at an absolute location, e.g. 1234, is dereferenced. It is a more general version of the NULLPTR_DEREFERENCE error type that is reported when the address is a constant other than zero.", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-constant-address-dereference-latent": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#constant_address_dereference_latent", + "description:A latent CONSTANT_ADDRESS_DEREFERENCE. See the documentation on Pulse latent issues.", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-create-intent-from-uri": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#create_intent_from_uri", + "description:Create an intent/start a component using a (possibly user-controlled) URI. may or may not be an issue depending on where the URI comes from.", + "profile:unknown", + "severity:HIGH" + ], + "infer-cross-site-scripting": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#cross_site_scripting", + "description:Untrusted data flows into HTML; XSS risk.", + "profile:unknown", + "severity:HIGH" + ], + "infer-cxx-ref-captured-in-block": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#cxx_ref_captured_in_block", + "description:This check flags when a C++ reference is captured in an escaping block. This means that the block will be leaving the current scope, i.e. it is not annotated with __attribute__((noescape)).", + "profile:unknown", + "severity:HIGH" + ], + "infer-cannot-star": [ + "doc_url:https://fbinfer.com/docs/all-issue-types", + "profile:unknown", + "severity:HIGH" + ], + "infer-dangling-pointer-dereference": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#dangling_pointer_dereference", + "description:DATALOG_FACT", + "profile:unknown", + "severity:HIGH" + ], + "infer-dangling-pointer-dereference-maybe": [ + "doc_url:https://fbinfer.com/docs/all-issue-types", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-datalog-fact": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#datalog_fact", + "description:Datalog fact used as input for a datalog solver.", + "profile:unknown", + "severity:LOW" + ], + "infer-data-flow-to-sink": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#data_flow_to_sink", + "description:A flow of data was detected to a sink.", + "profile:unknown", + "severity:STYLE" + ], + "infer-deadlock": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#deadlock", + "description:This error is currently reported in Java. A deadlock occurs when two distinct threads try to acquire two locks in reverse orders. The following code illustrates a textbook example. Of course, in real deadlocks, the lock acquisitions may be separated by deeply nested call chains.", + "profile:unknown", + "severity:HIGH" + ], + "infer-dead-store": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#dead_store", + "description:This error is reported in C++. It fires when the value assigned to a variables is never used (e.g., int i = 1; i = 2; return i;).", + "profile:unknown", + "severity:HIGH" + ], + "infer-divide-by-zero": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#divide_by_zero", + "description:EMPTY_VECTOR_ACCESS", + "profile:unknown", + "severity:HIGH" + ], + "infer-do-not-report": [ + "doc_url:https://fbinfer.com/docs/all-issue-types", + "profile:unknown", + "severity:HIGH" + ], + "infer-empty-vector-access": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#empty_vector_access", + "description:This error type is reported only in C++, in versions >= C++11.", + "profile:unknown", + "severity:HIGH" + ], + "infer-execution-time-complexity-increase": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#execution_time_complexity_increase", + "description:Infer reports this issue when the execution time complexity of a program increases in degree: e.g. from constant to linear or from logarithmic to quadratic. This issue type is only reported in differential mode: i.e when we are comparing the cost analysis results of two runs of infer on a file. Check out examples in here.", + "profile:unknown", + "severity:HIGH" + ], + "infer-execution-time-complexity-increase-ui-thread": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#execution_time_complexity_increase_ui_thread", + "description:Infer reports this issue when the execution time complexity of the procedure increases in degree and the procedure runs on the UI (main) thread.", + "profile:unknown", + "severity:HIGH" + ], + "infer-execution-time-unreachable-at-exit": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#execution_time_unreachable_at_exit", + "description:This issue type indicates that the program's execution doesn't reach the exit node (where our analysis computes the final cost of the procedure). Hence, we cannot compute a static bound for the procedure.", + "profile:unknown", + "severity:HIGH" + ], + "infer-expensive-execution-time": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#expensive_execution_time", + "description:[EXPERIMENTAL] This warning indicates that the procedure has non-constant and non-top execution cost. By default, this issue type is disabled. To enable it, set enabled=true in costKind.ml.", + "profile:unknown", + "severity:HIGH" + ], + "infer-expensive-loop-invariant-call": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#expensive_loop_invariant_call", + "description:We report this issue type when a function is loop-invariant and also expensive (i.e. at least has linear complexity as determined by the cost analysis).", + "profile:unknown", + "severity:HIGH" + ], + "infer-exposed-insecure-intent-handling": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#exposed_insecure_intent_handling", + "description:Undocumented.", + "profile:unknown", + "severity:HIGH" + ], + "infer-failure-exe": [ + "doc_url:https://fbinfer.com/docs/all-issue-types", + "profile:unknown", + "severity:LOW" + ], + "infer-guardedby-violation": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#guardedby_violation", + "description:A field annotated with @GuardedBy is being accessed by a call-chain that starts at a non-private method without synchronization.", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-impure-function": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#impure_function", + "description:This issue type indicates impure functions. For instance, below functions would be marked as impure:", + "profile:unknown", + "severity:HIGH" + ], + "infer-inefficient-keyset-iterator": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#inefficient_keyset_iterator", + "description:This issue is raised when", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-inferbo-alloc-is-big": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#inferbo_alloc_is_big", + "description:malloc is passed a large constant value (>=10^6). For example, int n = 1000000; malloc(n); generates INFERBO_ALLOC_IS_BIG on malloc(n).", + "profile:unknown", + "severity:HIGH" + ], + "infer-inferbo-alloc-is-negative": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#inferbo_alloc_is_negative", + "description:malloc is called with a negative size. For example, int n = 3 - 5; malloc(n); generates INFERBO_ALLOC_IS_NEGATIVE on malloc(n).", + "profile:unknown", + "severity:HIGH" + ], + "infer-inferbo-alloc-is-zero": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#inferbo_alloc_is_zero", + "description:malloc is called with a zero size. For example, int n = 3 - 3; malloc(n); generates INFERBO_ALLOC_IS_ZERO on malloc(n).", + "profile:unknown", + "severity:HIGH" + ], + "infer-inferbo-alloc-may-be-big": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#inferbo_alloc_may_be_big", + "description:malloc may be called with a large value. For example, int n = b ? 3 : 1000000; malloc(n); generates INFERBO_ALLOC_MAY_BE_BIG on malloc(n).", + "profile:unknown", + "severity:HIGH" + ], + "infer-inferbo-alloc-may-be-negative": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#inferbo_alloc_may_be_negative", + "description:malloc may be called with a negative value. For example, int n = b ? 3 : -5; malloc(n); generates INFERBO_ALLOC_MAY_BE_NEGATIVE on malloc(n).", + "profile:unknown", + "severity:HIGH" + ], + "infer-infinite-execution-time": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#infinite_execution_time", + "description:This warning indicates that Infer was not able to determine a static upper bound on the execution cost of the procedure. By default, this issue type is disabled.", + "profile:unknown", + "severity:HIGH" + ], + "infer-inherently-dangerous-function": [ + "doc_url:https://fbinfer.com/docs/all-issue-types", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-insecure-intent-handling": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#insecure_intent_handling", + "description:Undocumented.", + "profile:unknown", + "severity:HIGH" + ], + "infer-integer-overflow-l1": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#integer_overflow_l1", + "description:This is reported when integer overflow occurred by integer operations such as addition, subtraction, and multiplication. For example, int n = INT_MAX; int m = n + 3; generates a INTEGER_OVERFLOW_L1 on n + 3.", + "profile:unknown", + "severity:HIGH" + ], + "infer-integer-overflow-l2": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#integer_overflow_l2", + "description:See INTEGER_OVERFLOW_L1", + "profile:unknown", + "severity:HIGH" + ], + "infer-integer-overflow-l5": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#integer_overflow_l5", + "description:See INTEGER_OVERFLOW_L1", + "profile:unknown", + "severity:HIGH" + ], + "infer-integer-overflow-u5": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#integer_overflow_u5", + "description:See INTEGER_OVERFLOW_L1", + "profile:unknown", + "severity:HIGH" + ], + "infer-interface-not-thread-safe": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#interface_not_thread_safe", + "description:This error indicates that you have invoked an interface method not annotated with @ThreadSafe from a thread-safe context (e.g., code that uses locks or is marked @ThreadSafe). The fix is to add the @ThreadSafe annotation to the interface or to the interface method. For background on why these annotations are needed, see the detailed explanation here.", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-invalid-sil": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#invalid_sil", + "description:The SIL instruction does not conform to the expected subset of instructions expected for the front-end of the language for the analyzed code.", + "profile:unknown", + "severity:HIGH" + ], + "infer-invariant-call": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#invariant_call", + "description:We report this issue type when a function call is loop-invariant and hoistable, i.e.", + "profile:unknown", + "severity:HIGH" + ], + "infer-ipc-on-ui-thread": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#ipc_on_ui_thread", + "description:A blocking Binder IPC call occurs on the UI thread.", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-internal-error": [ + "doc_url:https://fbinfer.com/docs/all-issue-types", + "profile:unknown", + "severity:HIGH" + ], + "infer-javascript-injection": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#javascript_injection", + "description:Untrusted data flows into JavaScript.", + "profile:unknown", + "severity:HIGH" + ], + "infer-lab-resource-leak": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#lab_resource_leak", + "description:Toy issue.", + "profile:unknown", + "severity:HIGH" + ], + "infer-lockless-violation": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#lockless_violation", + "description:A method implements an interface signature annotated with @Lockless but which transitively acquires a lock.", + "profile:unknown", + "severity:HIGH" + ], + "infer-lock-consistency-violation": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#lock_consistency_violation", + "description:This is an error reported on C++ and Objective C classes whenever:", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-logging-private-data": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#logging_private_data", + "description:Undocumented.", + "profile:unknown", + "severity:HIGH" + ], + "infer-leak-after-array-abstraction": [ + "doc_url:https://fbinfer.com/docs/all-issue-types", + "profile:unknown", + "severity:HIGH" + ], + "infer-leak-in-footprint": [ + "doc_url:https://fbinfer.com/docs/all-issue-types", + "profile:unknown", + "severity:HIGH" + ], + "infer-leak-unknown-origin": [ + "doc_url:https://fbinfer.com/docs/all-issue-types", + "profile:unknown", + "severity:HIGH" + ], + "infer-memory-leak-c": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#memory_leak_c", + "description:Memory leak in C", + "profile:unknown", + "severity:HIGH" + ], + "infer-memory-leak-cpp": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#memory_leak_cpp", + "description:See MEMORY_LEAK_C", + "profile:unknown", + "severity:HIGH" + ], + "infer-missing-required-prop": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#missing_required_prop", + "description:This issues is reported when a required @Prop is missing.", + "profile:unknown", + "severity:HIGH" + ], + "infer-mixed-self-weakself": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#mixed_self_weakself", + "description:This check reports an issue when an Objective-C block captures both self and weakSelf, a weak pointer to self. Possibly the developer meant to capture only weakSelf to avoid a retain cycle, but made a typo and used self instead of strongSelf. In this case, this could cause a retain cycle.", + "profile:unknown", + "severity:HIGH" + ], + "infer-modifies-immutable": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#modifies_immutable", + "description:This issue type indicates modifications to fields marked as @Immutable. For instance, below function mutateArray would be marked as modifying immutable field testArray:", + "profile:unknown", + "severity:HIGH" + ], + "infer-multiple-weakself": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#multiple_weakself", + "description:This check reports when an Objective-C block uses weakSelf (a weak pointer to self) more than once. This could lead to unexpected behaviour. Even if weakSelf is not nil in the first use, it could be nil in the following uses since the object that weakSelf points to could be freed anytime.", + "profile:unknown", + "severity:HIGH" + ], + "infer-mutual-recursion-cycle": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#mutual_recursion_cycle", + "description:A recursive call or mutually recursive call has been detected. This does not mean that the program won't terminate, just that the code is recursive. You should double-check if the recursion is intended and if it can lead to non-termination or a stack overflow.", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-missing-fld": [ + "doc_url:https://fbinfer.com/docs/all-issue-types", + "profile:unknown", + "severity:HIGH" + ], + "infer-nil-block-call": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#nil_block_call", + "description:This check reports when one tries to call an Objective-C block that is nil. This causes a crash.", + "profile:unknown", + "severity:HIGH" + ], + "infer-nil-block-call-latent": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#nil_block_call_latent", + "description:A latent NIL_BLOCK_CALL. See the documentation on Pulse latent issues.", + "profile:unknown", + "severity:HIGH" + ], + "infer-nil-insertion-into-collection": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#nil_insertion_into_collection", + "description:This checks reports when nil is passed to collections in Objective-C such as arrays and dictionaries. This causes a crash.", + "profile:unknown", + "severity:HIGH" + ], + "infer-nil-insertion-into-collection-latent": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#nil_insertion_into_collection_latent", + "description:A latent NIL_INSERTION_INTO_COLLECTION. See the documentation on Pulse latent issues.", + "profile:unknown", + "severity:HIGH" + ], + "infer-nil-messaging-to-non-pod": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#nil_messaging_to_non_pod", + "description:In Objective-C, calling a method on nil (or in Objective-C terms, sending a message to nil) does not crash, it simply returns a falsy value (nil/0/false). However, sending a message that returns a non-POD C++ type (POD being \"Plain Old Data\", essentially anything that cannot be compiled as a C-style struct) to nil causes undefined behaviour.", + "profile:unknown", + "severity:HIGH" + ], + "infer-nil-messaging-to-non-pod-latent": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#nil_messaging_to_non_pod_latent", + "description:A latent NIL_MESSAGING_TO_NON_POD. See the documentation on Pulse latent issues.", + "profile:unknown", + "severity:HIGH" + ], + "infer-no-matching-branch-in-try": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#no_matching_branch_in_try", + "description:No matching branch is found when evaluating the of section of a try expression. Corresponds to the {try_clause,V} error in the Erlang runtime.", + "profile:unknown", + "severity:HIGH" + ], + "infer-no-matching-branch-in-try-latent": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#no_matching_branch_in_try_latent", + "description:A latent NO_MATCHING_BRANCH_IN_TRY. See the documentation on Pulse latent issues.", + "profile:unknown", + "severity:HIGH" + ], + "infer-no-matching-case-clause": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#no_matching_case_clause", + "description:No matching case clause in Erlang: Reports an error when none of the clauses of a case match the expression. Corresponds to the {case_clause,V} error in the Erlang runtime.", + "profile:unknown", + "severity:HIGH" + ], + "infer-no-matching-case-clause-latent": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#no_matching_case_clause_latent", + "description:A latent NO_MATCHING_CASE_CLAUSE. See the documentation on Pulse latent issues.", + "profile:unknown", + "severity:HIGH" + ], + "infer-no-matching-else-clause": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#no_matching_else_clause", + "description:No matching else clause in Erlang: Reports an error when none of the clauses of an else match the short-circuit result from maybe body. Corresponds to the {else_clause,V} error in the Erlang runtime.", + "profile:unknown", + "severity:HIGH" + ], + "infer-no-matching-else-clause-latent": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#no_matching_else_clause_latent", + "description:A latent NO_MATCHING_ELSE_CLAUSE. See the documentation on Pulse latent issues.", + "profile:unknown", + "severity:HIGH" + ], + "infer-no-matching-function-clause": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#no_matching_function_clause", + "description:No matching function clause in Erlang: Reports an error when none of the clauses of a function match the arguments of a call. Corresponds to the function_clause error in the Erlang runtime.", + "profile:unknown", + "severity:HIGH" + ], + "infer-no-matching-function-clause-latent": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#no_matching_function_clause_latent", + "description:A latent NO_MATCHING_FUNCTION_CLAUSE. See the documentation on Pulse latent issues.", + "profile:unknown", + "severity:HIGH" + ], + "infer-no-match-of-rhs": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#no_match_of_rhs", + "description:No match of right hand side value in Erlang: Reports an error when the right hand side value of a match expression does not match the pattern on the left hand side. Corresponds to the {badmatch,V} error in the Erlang runtime.", + "profile:unknown", + "severity:HIGH" + ], + "infer-no-match-of-rhs-latent": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#no_match_of_rhs_latent", + "description:A latent NO_MATCH_OF_RHS. See the documentation on Pulse latent issues.", + "profile:unknown", + "severity:HIGH" + ], + "infer-no-true-branch-in-if": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#no_true_branch_in_if", + "description:No true branch when evaluating an if expression in Erlang: Reports an error when none of the branches of an if expression evaluate to true. Corresponds to the if_clause error in the Erlang runtime.", + "profile:unknown", + "severity:HIGH" + ], + "infer-no-true-branch-in-if-latent": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#no_true_branch_in_if_latent", + "description:A latent NO_TRUE_BRANCH_IN_IF. See the documentation on Pulse latent issues.", + "profile:unknown", + "severity:HIGH" + ], + "infer-nullptr-dereference": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#nullptr_dereference", + "description:Infer reports null dereference bugs in Java, C, C++, and Objective-C when it is possible that the null pointer is dereferenced, leading to a crash.", + "profile:unknown", + "severity:HIGH" + ], + "infer-nullptr-dereference-in-nullsafe-class": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#nullptr_dereference_in_nullsafe_class", + "description:Infer reports null dereference bugs in Java, C, C++, and Objective-C when it is possible that the null pointer is dereferenced, leading to a crash.", + "profile:unknown", + "severity:HIGH" + ], + "infer-nullptr-dereference-in-nullsafe-class-latent": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#nullptr_dereference_in_nullsafe_class_latent", + "description:A latent NULLPTR_DEREFERENCE_IN_NULLSAFE_CLASS. See the documentation on Pulse latent issues.", + "profile:unknown", + "severity:HIGH" + ], + "infer-nullptr-dereference-latent": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#nullptr_dereference_latent", + "description:A latent NULLPTR_DEREFERENCE. See the documentation on Pulse latent issues.", + "profile:unknown", + "severity:HIGH" + ], + "infer-null-argument": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#null_argument", + "description:This issue type indicates `nil` being passed as argument where a non-nil value expected.", + "profile:unknown", + "severity:HIGH" + ], + "infer-null-argument-latent": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#null_argument_latent", + "description:A latent NULL_ARGUMENT. See the documentation on Pulse latent issues.", + "profile:unknown", + "severity:HIGH" + ], + "infer-null-dereference": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#null_dereference", + "description:See NULLPTR_DEREFERENCE.", + "profile:unknown", + "severity:HIGH" + ], + "infer-optional-empty-access": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#optional_empty_access", + "description:Optional Empty Access warnings are reported when we try to retrieve the value of a folly::Optional when it is empty (i.e. folly::none).", + "profile:unknown", + "severity:HIGH" + ], + "infer-optional-empty-access-latent": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#optional_empty_access_latent", + "description:A latent OPTIONAL_EMPTY_ACCESS. See the documentation on Pulse latent issues.", + "profile:unknown", + "severity:HIGH" + ], + "infer-precondition-not-found": [ + "doc_url:https://fbinfer.com/docs/all-issue-types", + "profile:unknown", + "severity:HIGH" + ], + "infer-precondition-not-met": [ + "doc_url:https://fbinfer.com/docs/all-issue-types", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-premature-nil-termination-argument": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#premature_nil_termination_argument", + "description:This error type is reported in C and Objective-C. In many variadic methods, nil is used to signify the end of the list of input objects. This is similar to nil-termination of C strings. If one of the arguments that is not the last argument to the method is nil as well, Infer reports an error because that may lead to unexpected behavior.", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-pulse-cannot-instantiate-abstract-class": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_cannot_instantiate_abstract_class", + "description:Instantiating an abstract class will lead to Cannot instantiate abstract class error.", + "profile:unknown", + "severity:HIGH" + ], + "infer-pulse-const-refable": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_const_refable", + "description:This issue is reported when a function parameter is a) passed by value and b) is not modified inside the function. Instead, parameter can be passed by const reference, i.e. converted to a const& so that no unnecessary copy is created at the callsite of the function.", + "profile:unknown", + "severity:HIGH" + ], + "infer-pulse-dict-missing-key": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_dict_missing_key", + "description:This issue is similar to PULSE_UNINITIALIZED_VALUE, but it is to warn reading a missing key of dictionary in Hack.", + "profile:unknown", + "severity:HIGH" + ], + "infer-pulse-dynamic-type-mismatch": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_dynamic_type_mismatch", + "description:This error is reported in Hack. It fires when we detect an operation that is incompatible with the dynamic type of its arguments.", + "profile:unknown", + "severity:HIGH" + ], + "infer-pulse-readonly-shared-ptr-param": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_readonly_shared_ptr_param", + "description:This issue is reported when a shared pointer parameter is a) passed by value and b) is used only for reading, rather than lifetime extension. At the callsite, this might cause a potentially expensive unnecessary copy of the shared pointer, especially when many number of threads are sharing it. To avoid this, consider 1) passing the raw pointer instead and 2) use std::shared_ptr::get at callsites.", + "profile:unknown", + "severity:HIGH" + ], + "infer-pulse-reference-stability": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_reference_stability", + "description:The family of maps folly::F14ValueMap, folly::F14VectorMap, and by extension folly::F14FastMap differs slightly from std::unordered_map as it does not provide reference stability. When the map resizes such as when reserve is called or new elements are added, all existing references become invalid and should not be used.", + "profile:unknown", + "severity:HIGH" + ], + "infer-pulse-resource-leak": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_resource_leak", + "description:See RESOURCE_LEAK", + "profile:unknown", + "severity:HIGH" + ], + "infer-pulse-transitive-access": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_transitive_access", + "description:This issue tracks spurious accesses that are reachable from specific entry functions.", + "profile:unknown", + "severity:HIGH" + ], + "infer-pulse-unawaited-awaitable": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_unawaited_awaitable", + "description:Awaitable values created by calls to asynchronous methods should eventually be awaited along all codepaths (even if their value is unused). Hence the following is not OK", + "profile:unknown", + "severity:HIGH" + ], + "infer-pulse-uninitialized-const": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_uninitialized_const", + "description:This issue is similar to PULSE_UNINITIALIZED_VALUE, but it is to detect the uninitialized abstract const value in Hack.", + "profile:unknown", + "severity:HIGH" + ], + "infer-pulse-uninitialized-value": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_uninitialized_value", + "description:The code uses a variable that has not been initialized, leading to unpredictable or unintended results.", + "profile:unknown", + "severity:HIGH" + ], + "infer-pulse-unnecessary-copy": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_unnecessary_copy", + "description:This is reported when Infer detects an unnecessary copy of an object via copy constructor where neither the source nor the copied variable are modified before the variable goes out of scope. Rather than the copy, a reference to the source object could be used to save memory.", + "profile:unknown", + "severity:HIGH" + ], + "infer-pulse-unnecessary-copy-assignment": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_unnecessary_copy_assignment", + "description:See PULSE_UNNECESSARY_COPY.", + "profile:unknown", + "severity:HIGH" + ], + "infer-pulse-unnecessary-copy-assignment-const": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_unnecessary_copy_assignment_const", + "description:See PULSE_UNNECESSARY_COPY.", + "profile:unknown", + "severity:HIGH" + ], + "infer-pulse-unnecessary-copy-assignment-movable": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_unnecessary_copy_assignment_movable", + "description:See PULSE_UNNECESSARY_COPY_MOVABLE.", + "profile:unknown", + "severity:HIGH" + ], + "infer-pulse-unnecessary-copy-intermediate": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_unnecessary_copy_intermediate", + "description:This is reported when Infer detects an unnecessary temporary copy of an intermediate object where copy is created to be passed down to a function unnecessarily. Instead, the intermediate object should either be moved into the callee or the type of the callee's parameter should be made const &.", + "profile:unknown", + "severity:HIGH" + ], + "infer-pulse-unnecessary-copy-intermediate-const": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_unnecessary_copy_intermediate_const", + "description:See PULSE_UNNECESSARY_COPY.", + "profile:unknown", + "severity:HIGH" + ], + "infer-pulse-unnecessary-copy-movable": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_unnecessary_copy_movable", + "description:This is reported when Infer detects an unnecessary copy into a field where", + "profile:unknown", + "severity:HIGH" + ], + "infer-pulse-unnecessary-copy-optional": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_unnecessary_copy_optional", + "description:This is reported when Infer detects an unnecessary copy of an object via optional value construction where the source is not modified before it goes out of scope. To avoid the copy, we can move the source object or change the callee's type.", + "profile:unknown", + "severity:HIGH" + ], + "infer-pulse-unnecessary-copy-optional-const": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_unnecessary_copy_optional_const", + "description:See PULSE_UNNECESSARY_COPY_OPTIONAL.", + "profile:unknown", + "severity:HIGH" + ], + "infer-pulse-unnecessary-copy-return": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#pulse_unnecessary_copy_return", + "description:This is similar to PULSE_UNNECESSARY_COPY, but reported when a callee returns a copied value and it is not modified in its caller. We may be able to return const-ref typed value or try std::move to avoid the copy.", + "profile:unknown", + "severity:HIGH" + ], + "infer-pure-function": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#pure_function", + "description:This issue type indicates pure functions. For instance, below functions would be marked as pure:", + "profile:unknown", + "severity:HIGH" + ], + "infer-quandary-taint-error": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#quandary_taint_error", + "description:Generic taint error when nothing else fits.", + "profile:unknown", + "severity:HIGH" + ], + "infer-regex-op-on-ui-thread": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#regex_op_on_ui_thread", + "description:A potentially costly operation on a regular expression occurs on the UI thread.", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-resource-leak": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#resource_leak", + "description:Infer reports resource leaks in C, Objective-C and Java. In general, resources are entities such as files, sockets, connections, etc, that need to be closed after being used.", + "profile:unknown", + "severity:HIGH" + ], + "infer-retain-cycle": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#retain_cycle", + "description:A retain cycle is a situation when object A retains object B, and object B retains object A at the same time. Here is an example:", + "profile:unknown", + "severity:HIGH" + ], + "infer-retain-cycle-no-weak-info": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#retain_cycle_no_weak_info", + "description:A retain cycle is a situation when object A retains object B, and object B retains object A at the same time. Here is an example:", + "profile:unknown", + "severity:HIGH" + ], + "infer-scope-leakage": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#scope_leakage", + "description:This issue type indicates that a class with scope annotation A stores a field with whose (dynamic) type (or one of its super types) is annotated with scope B such that a scope nesting restriction is violated. By \"stores\", we mean either directly or transitively.", + "profile:unknown", + "severity:HIGH" + ], + "infer-sensitive-data-flow": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#sensitive_data_flow", + "description:A flow of sensitive data was detected from a source.", + "profile:unknown", + "severity:STYLE" + ], + "infer-shell-injection": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#shell_injection", + "description:Environment variable or file data flowing to shell.", + "profile:unknown", + "severity:HIGH" + ], + "infer-shell-injection-risk": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#shell_injection_risk", + "description:Code injection if the caller of the endpoint doesn't sanitize on its end.", + "profile:unknown", + "severity:HIGH" + ], + "infer-skip-function": [ + "doc_url:https://fbinfer.com/docs/all-issue-types", + "profile:unknown", + "severity:LOW" + ], + "infer-sql-injection": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#sql_injection", + "description:Untrusted and unescaped data flows to SQL.", + "profile:unknown", + "severity:HIGH" + ], + "infer-sql-injection-risk": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#sql_injection_risk", + "description:Untrusted and unescaped data flows to SQL.", + "profile:unknown", + "severity:HIGH" + ], + "infer-stack-variable-address-escape": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#stack_variable_address_escape", + "description:Reported when an address pointing into the stack of the current function will escape to its calling context. Such addresses will become invalid by the time the function actually returns so are potentially dangerous.", + "profile:unknown", + "severity:HIGH" + ], + "infer-starvation": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#starvation", + "description:This error is reported in Java, and specifically on Android. These reports are triggered when a method that runs on the UI thread may block, thus potentially leading to an Application Not Responding error.", + "profile:unknown", + "severity:HIGH" + ], + "infer-static-initialization-order-fiasco": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#static_initialization_order_fiasco", + "description:This error is reported in C++. It fires when the initialization of a static variable A, accesses a static variable B from another translation unit (usually another .cpp file). There are no guarantees whether B has been already initialized or not at that point.", + "profile:unknown", + "severity:HIGH" + ], + "infer-strict-mode-violation": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#strict_mode_violation", + "description:Android has a feature called strict mode, which if enabled, will flag the occasions where the main thread makes a call that results in disk I/O, waiting on a network socket, etc. The analysis catching starvation errors and deadlocks (the --starvation analysis) has the ability to statically detect such violations.", + "profile:unknown", + "severity:HIGH" + ], + "infer-strong-self-not-checked": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#strong_self_not_checked", + "description:This checks reports a potential issue when a block captures weakSelf (a weak pointer to self), then one assigns this pointer to a local variable strongSelf inside the block and uses this variable without checking first whether it is nil. The problem here is that the weak pointer could be nil at the time when the block is executed. So, the correct usage is to first check whether strongSelf is a valid pointer, and then use it.", + "profile:unknown", + "severity:HIGH" + ], + "infer-symexec-memory-error": [ + "doc_url:https://fbinfer.com/docs/all-issue-types", + "profile:unknown", + "severity:HIGH" + ], + "infer-taint-error": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#taint_error", + "description:A taint flow was detected from a source to a sink", + "profile:unknown", + "severity:HIGH" + ], + "infer-thread-safety-violation": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#thread_safety_violation", + "description:This warning indicates a potential data race in Java. The analyser is called RacerD and this section gives brief but a mostly complete description of its features. See the RacerD page for more in-depth information and examples.", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-topl-error": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#topl_error", + "description:A violation of a Topl property (user-specified). There is an execution path in the code that drives a Topl property from a start state to an error state.", + "profile:unknown", + "severity:HIGH" + ], + "infer-topl-error-latent": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#topl_error_latent", + "description:A latent TOPL_ERROR. See the documentation on Pulse latent issues.", + "profile:unknown", + "severity:HIGH" + ], + "infer-unreachable-code": [ + "doc_url:https://fbinfer.com/docs/all-issue-types", + "profile:unknown", + "severity:HIGH" + ], + "infer-untrusted-buffer-access": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#untrusted_buffer_access", + "description:Untrusted data of any kind flowing to buffer.", + "profile:unknown", + "severity:HIGH" + ], + "infer-untrusted-deserialization": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#untrusted_deserialization", + "description:User-controlled deserialization.", + "profile:unknown", + "severity:HIGH" + ], + "infer-untrusted-deserialization-risk": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#untrusted_deserialization_risk", + "description:User-controlled deserialization", + "profile:unknown", + "severity:HIGH" + ], + "infer-untrusted-environment-change-risk": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#untrusted_environment_change_risk", + "description:User-controlled environment mutation.", + "profile:unknown", + "severity:HIGH" + ], + "infer-untrusted-file": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#untrusted_file", + "description:User-controlled file creation; may be vulnerable to path traversal and more.", + "profile:unknown", + "severity:HIGH" + ], + "infer-untrusted-file-risk": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#untrusted_file_risk", + "description:User-controlled file creation; may be vulnerable to path traversal and more.", + "profile:unknown", + "severity:HIGH" + ], + "infer-untrusted-heap-allocation": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#untrusted_heap_allocation", + "description:Untrusted data of any kind flowing to heap allocation. this can cause crashes or DOS.", + "profile:unknown", + "severity:HIGH" + ], + "infer-untrusted-intent-creation": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#untrusted_intent_creation", + "description:Creating an Intent from user-controlled data.", + "profile:unknown", + "severity:HIGH" + ], + "infer-untrusted-url-risk": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#untrusted_url_risk", + "description:Untrusted flag, environment variable, or file data flowing to URL.", + "profile:unknown", + "severity:HIGH" + ], + "infer-untrusted-variable-length-array": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#untrusted_variable_length_array", + "description:Untrusted data of any kind flowing to stack buffer allocation. Trying to allocate a stack buffer that's too large will cause a stack overflow.", + "profile:unknown", + "severity:HIGH" + ], + "infer-user-controlled-sql-risk": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#user_controlled_sql_risk", + "description:Untrusted data flows to SQL (no injection risk).", + "profile:unknown", + "severity:HIGH" + ], + "infer-use-after-delete": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#use_after_delete", + "description:An address that was invalidated by a call to delete in C++ is dereferenced.", + "profile:unknown", + "severity:HIGH" + ], + "infer-use-after-delete-latent": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#use_after_delete_latent", + "description:A latent USE_AFTER_DELETE. See the documentation on Pulse latent issues.", + "profile:unknown", + "severity:HIGH" + ], + "infer-use-after-free": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#use_after_free", + "description:An address that was invalidated by a call to free in C is dereferenced.", + "profile:unknown", + "severity:HIGH" + ], + "infer-use-after-free-latent": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#use_after_free_latent", + "description:A latent USE_AFTER_FREE. See the documentation on Pulse latent issues.", + "profile:unknown", + "severity:HIGH" + ], + "infer-use-after-lifetime": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#use_after_lifetime", + "description:The lifetime of an object has ended but that object is being accessed. For example, the address of a variable holding a C++ object is accessed after the variable has gone out of scope:", + "profile:unknown", + "severity:HIGH" + ], + "infer-use-after-lifetime-latent": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#use_after_lifetime_latent", + "description:A latent USE_AFTER_LIFETIME. See the documentation on Pulse latent issues.", + "profile:unknown", + "severity:HIGH" + ], + "infer-vector-invalidation": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#vector_invalidation", + "description:An address pointing into a C++ std::vector might have become invalid. This can happen when an address is taken into a vector, then the vector is mutated in a way that might invalidate the address, for example by adding elements to the vector, which might trigger a re-allocation of the entire vector contents (thereby invalidating the pointers into the previous location of the contents).", + "profile:unknown", + "severity:HIGH" + ], + "infer-vector-invalidation-latent": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#vector_invalidation_latent", + "description:A latent VECTOR_INVALIDATION. See the documentation on Pulse latent issues.", + "profile:unknown", + "severity:HIGH" + ], + "infer-weak-self-in-no-escape-block": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#weak_self_in_no_escape_block", + "description:This check reports when weakSelf (a weak pointer to self) is used in a block, and this block is passed to a \"no escaping\" method. This means that the block passed to that method won't be leaving the current scope, this is marked with the annotation NS_NOESCAPE.", + "profile:unknown", + "severity:HIGH" + ], + "infer-wrong-argument-number": [ + "doc_url:https://fbinfer.com/docs/all-issue-types", + "profile:unknown", + "severity:HIGH" + ], + "infer-assign-pointer-MEDIUM": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#assign_pointer_warning", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-autoreleasepool-size-complexity-increase": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#autoreleasepool_size_complexity_increase", + "profile:unknown", + "severity:HIGH" + ], + "infer-autoreleasepool-size-complexity-increase-ui-thread": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#autoreleasepool_size_complexity_increase_ui_thread", + "profile:unknown", + "severity:HIGH" + ], + "infer-autoreleasepool-size-unreachable-at-exit": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#autoreleasepool_size_unreachable_at_exit", + "profile:unknown", + "severity:HIGH" + ], + "infer-bad-pointer-comparison": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#bad_pointer_comparison", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-checkers-annotation-reachability-HIGH": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#checkers_annotation_reachability_error", + "profile:unknown", + "severity:HIGH" + ], + "infer-checkers-immutable-cast": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#checkers_immutable_cast", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-component-with-multiple-factory-methods": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#component_with_multiple_factory_methods", + "profile:unknown", + "severity:LOW" + ], + "infer-config-checks-between-markers": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#config_checks_between_markers", + "profile:unknown", + "severity:LOW" + ], + "infer-cxx-reference-captured-in-objc-block": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#cxx_reference_captured_in_objc_block", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-direct-atomic-property-access": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#direct_atomic_property_access", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-discouraged-weak-property-custom-setter": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#discouraged_weak_property_custom_setter", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-dotnet-resource-leak": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#dotnet_resource_leak", + "profile:unknown", + "severity:HIGH" + ], + "infer-eradicate-annotation-graph": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_annotation_graph", + "profile:unknown", + "severity:STYLE" + ], + "infer-eradicate-bad-nested-class-annotation": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_bad_nested_class_annotation", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-eradicate-condition-redundant": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_condition_redundant", + "profile:unknown", + "severity:LOW" + ], + "infer-eradicate-field-not-initialized": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_field_not_initialized", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-eradicate-field-not-nullable": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_field_not_nullable", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-eradicate-field-over-annotated": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_field_over_annotated", + "profile:unknown", + "severity:LOW" + ], + "infer-eradicate-inconsistent-subclass-parameter-annotation": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_inconsistent_subclass_parameter_annotation", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-eradicate-inconsistent-subclass-return-annotation": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_inconsistent_subclass_return_annotation", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-eradicate-meta-class-can-be-nullsafe": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_meta_class_can_be_nullsafe", + "profile:unknown", + "severity:LOW" + ], + "infer-eradicate-meta-class-is-nullsafe": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_meta_class_is_nullsafe", + "profile:unknown", + "severity:STYLE" + ], + "infer-eradicate-meta-class-needs-improvement": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_meta_class_needs_improvement", + "profile:unknown", + "severity:STYLE" + ], + "infer-eradicate-nullable-dereference": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_nullable_dereference", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-eradicate-parameter-not-nullable": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_parameter_not_nullable", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-eradicate-redundant-nested-class-annotation": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_redundant_nested_class_annotation", + "profile:unknown", + "severity:LOW" + ], + "infer-eradicate-return-not-nullable": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_return_not_nullable", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-eradicate-return-over-annotated": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_return_over_annotated", + "profile:unknown", + "severity:LOW" + ], + "infer-eradicate-unchecked-usage-in-nullsafe": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_unchecked_usage_in_nullsafe", + "profile:unknown", + "severity:UNSPECIFIED" + ], + "infer-eradicate-unvetted-third-party-in-nullsafe": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#eradicate_unvetted_third_party_in_nullsafe", + "profile:unknown", + "severity:UNSPECIFIED" + ], + "infer-expensive-autoreleasepool-size": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#expensive_autoreleasepool_size", + "profile:unknown", + "severity:HIGH" + ], + "infer-global-variable-initialized-with-function-or-method-call": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#global_variable_initialized_with_function_or_method_call", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-guardedby-violation-nullsafe": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#guardedby_violation_nullsafe", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-infinite-autoreleasepool-size": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#infinite_autoreleasepool_size", + "profile:unknown", + "severity:HIGH" + ], + "infer-ivar-not-null-checked": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#ivar_not_null_checked", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-memory-leak": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#memory_leak", + "profile:unknown", + "severity:HIGH" + ], + "infer-mutable-local-variable-in-component-file": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#mutable_local_variable_in_component_file", + "profile:unknown", + "severity:LOW" + ], + "infer-parameter-not-null-checked": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#parameter_not_null_checked", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-pointer-to-const-objc-class": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#pointer_to_const_objc_class", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-quandary-taint-HIGH": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#quandary_taint_error", + "profile:unknown", + "severity:HIGH" + ], + "infer-strong-delegate-MEDIUM": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#strong_delegate_warning", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-thread-safety-violation-nullsafe": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#thread_safety_violation_nullsafe", + "profile:unknown", + "severity:MEDIUM" + ], + "infer-topl-HIGH": [ + "doc_url:https://fbinfer.com/docs/all-issue-types#topl_error", + "profile:unknown", + "severity:HIGH" + ], + "infer-uninitialized-value": [ + "doc_url:https://fbinfer.com/docs/1.1.0/all-issue-types#uninitialized_value", + "profile:unknown", + "severity:HIGH" + ], + "infer-internal-HIGH": [ + "doc_url:https://fbinfer.com/docs/all-issue-types", + "profile:unknown", + "severity:HIGH" + ], + "infer-symexec-memory-HIGH": [ + "doc_url:https://fbinfer.com/docs/all-issue-types", + "profile:unknown", + "severity:HIGH" + ] + } } diff --git a/config/labels/descriptions.json b/config/labels/descriptions.json index 2611e74cb7..374b8f6cb4 100644 --- a/config/labels/descriptions.json +++ b/config/labels/descriptions.json @@ -14,15 +14,12 @@ "STYLE": "A true positive indicates that the source code is against a specific coding guideline or could improve readability.", "UNSPECIFIED": "Checker severity is not specified for a checker." }, - "guideline": { - "cwe-top-25-2024": "https://cwe.mitre.org/top25/archive/2024/2024_top25_list", - "cwe-top-25-2025": "https://cwe.mitre.org/top25/archive/2025/2025_cwe_top25.html", - "cwe-vulnerabilities": "https://cwe.mitre.org/", - "sei-cert-c": "https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/", - "sei-cert-cpp": "https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/", - "misra-c": "https://www.misra.org.uk/", - "memory-safety": "https://cwe.mitre.org/data/definitions/1399.html", - "owasp-top-10-2021": "https://owasp.org/Top10/2021/", - "owasp-top-10-2025": "https://owasp.org/Top10/2025/" + "profile-containment": { + "extreme": [ + "sensitive" + ], + "sensitive": [ + "default" + ] } } diff --git a/config/rules/cwe-rules.yaml b/config/rules/cwe-rules.yaml new file mode 100644 index 0000000000..fc1dbad553 --- /dev/null +++ b/config/rules/cwe-rules.yaml @@ -0,0 +1,180 @@ +- rule_id: cwe-119 + title: Improper Restriction of Operations within the Bounds of a Memory Buffer + rule_url: https://cwe.mitre.org/data/definitions/119.html +- rule_id: cwe-120 + title: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') + rule_url: https://cwe.mitre.org/data/definitions/120.html +- rule_id: cwe-121 + title: Stack-Based Buffer Overflow + rule_url: https://cwe.mitre.org/data/definitions/121.html +- rule_id: cwe-122 + title: Heap-based Buffer Overflow + rule_url: https://cwe.mitre.org/data/definitions/122.html +- rule_id: cwe-123 + title: Write-what-where Condition + rule_url: https://cwe.mitre.org/data/definitions/123.html +- rule_id: cwe-124 + title: Buffer Underwrite ('Buffer Underflow') + rule_url: https://cwe.mitre.org/data/definitions/124.html +- rule_id: cwe-125 + title: Out-of-bounds Read + rule_url: https://cwe.mitre.org/data/definitions/125.html +- rule_id: cwe-126 + title: Buffer Over-read + rule_url: https://cwe.mitre.org/data/definitions/126.html +- rule_id: cwe-127 + title: Buffer Under-read + rule_url: https://cwe.mitre.org/data/definitions/127.html +- rule_id: cwe-129 + title: Improper Validation of Array Index + rule_url: https://cwe.mitre.org/data/definitions/129.html +- rule_id: cwe-170 + title: Improper Null Termination + rule_url: https://cwe.mitre.org/data/definitions/170.html +- rule_id: cwe-190 + title: Integer Overflow or Wraparound + rule_url: https://cwe.mitre.org/data/definitions/190.html +- rule_id: cwe-20 + title: Improper Input Validation + rule_url: https://cwe.mitre.org/data/definitions/20.html +- rule_id: cwe-200 + title: Exposure of Sensitive Information to an Unauthorized Actor + rule_url: https://cwe.mitre.org/data/definitions/200.html +- rule_id: cwe-22 + title: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') + rule_url: https://cwe.mitre.org/data/definitions/22.html +- rule_id: cwe-244 + title: Improper Clearing of Heap Memory Before Release ('Heap Inspection') + rule_url: https://cwe.mitre.org/data/definitions/244.html +- rule_id: cwe-252 + title: Unchecked Return Value + rule_url: https://cwe.mitre.org/data/definitions/252.html +- rule_id: cwe-269 + title: Improper Privilege Management + rule_url: https://cwe.mitre.org/data/definitions/269.html +- rule_id: cwe-284 + title: Improper Access Control + rule_url: https://cwe.mitre.org/data/definitions/284.html +- rule_id: cwe-287 + title: Improper Authentication + rule_url: https://cwe.mitre.org/data/definitions/287.html +- rule_id: cwe-306 + title: Missing Authentication for Critical Function + rule_url: https://cwe.mitre.org/data/definitions/306.html +- rule_id: cwe-335 + title: Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) + rule_url: https://cwe.mitre.org/data/definitions/335.html +- rule_id: cwe-338 + title: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) + rule_url: https://cwe.mitre.org/data/definitions/338.html +- rule_id: cwe-352 + title: Cross-Site Request Forgery (CSRF) + rule_url: https://cwe.mitre.org/data/definitions/352.html +- rule_id: cwe-362 + title: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') + rule_url: https://cwe.mitre.org/data/definitions/362.html +- rule_id: cwe-369 + title: Divide By Zero + rule_url: https://cwe.mitre.org/data/definitions/369.html +- rule_id: cwe-377 + title: Insecure Temporary File + rule_url: https://cwe.mitre.org/data/definitions/377.html +- rule_id: cwe-390 + title: Detection of Error Condition Without Action + rule_url: https://cwe.mitre.org/data/definitions/390.html +- rule_id: cwe-400 + title: Uncontrolled Resource Consumption + rule_url: https://cwe.mitre.org/data/definitions/400.html +- rule_id: cwe-401 + title: Missing Release of Memory after Effective Lifetime + rule_url: https://cwe.mitre.org/data/definitions/401.html +- rule_id: cwe-415 + title: Double Free + rule_url: https://cwe.mitre.org/data/definitions/415.html +- rule_id: cwe-416 + title: Use After Free + rule_url: https://cwe.mitre.org/data/definitions/416.html +- rule_id: cwe-434 + title: Unrestricted Upload of File with Dangerous Type + rule_url: https://cwe.mitre.org/data/definitions/434.html +- rule_id: cwe-457 + title: Use of Uninitialized Variable + rule_url: https://cwe.mitre.org/data/definitions/457.html +- rule_id: cwe-476 + title: NULL Pointer Dereference + rule_url: https://cwe.mitre.org/data/definitions/476.html +- rule_id: cwe-478 + title: Missing Default Case in Multiple Condition Expression + rule_url: https://cwe.mitre.org/data/definitions/478.html +- rule_id: cwe-502 + title: Deserialization of Untrusted Data + rule_url: https://cwe.mitre.org/data/definitions/502.html +- rule_id: cwe-562 + title: Return of Stack Variable Address + rule_url: https://cwe.mitre.org/data/definitions/562.html +- rule_id: cwe-590 + title: Free of Memory not on the Heap + rule_url: https://cwe.mitre.org/data/definitions/590.html +- rule_id: cwe-639 + title: Authorization Bypass Through User-Controlled Key + rule_url: https://cwe.mitre.org/data/definitions/639.html +- rule_id: cwe-664 + title: Improper Control of a Resource Through its Lifetime + rule_url: https://cwe.mitre.org/data/definitions/664.html +- rule_id: cwe-668 + title: Exposure of Resource to Wrong Sphere + rule_url: https://cwe.mitre.org/data/definitions/668.html +- rule_id: cwe-676 + title: Use of Potentially Dangerous Function + rule_url: https://cwe.mitre.org/data/definitions/676.html +- rule_id: cwe-732 + title: Incorrect Permission Assignment for Critical Resource + rule_url: https://cwe.mitre.org/data/definitions/732.html +- rule_id: cwe-761 + title: Free of Pointer not at Start of Buffer + rule_url: https://cwe.mitre.org/data/definitions/761.html +- rule_id: cwe-762 + title: Mismatched Memory Management Routines + rule_url: https://cwe.mitre.org/data/definitions/762.html +- rule_id: cwe-77 + title: Improper Neutralization of Special Elements used in a Command ('Command Injection') + rule_url: https://cwe.mitre.org/data/definitions/77.html +- rule_id: cwe-770 + title: Allocation of Resources Without Limits or Throttling + rule_url: https://cwe.mitre.org/data/definitions/770.html +- rule_id: cwe-78 + title: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') + rule_url: https://cwe.mitre.org/data/definitions/78.html +- rule_id: cwe-785 + title: Use of Path Manipulation Function without Maximum Sized Buffer + rule_url: https://cwe.mitre.org/data/definitions/785.html +- rule_id: cwe-787 + title: Out-of-bounds Write + rule_url: https://cwe.mitre.org/data/definitions/787.html +- rule_id: cwe-789 + title: Memory Allocation with Excessive Size Value + rule_url: https://cwe.mitre.org/data/definitions/789.html +- rule_id: cwe-79 + title: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') + rule_url: https://cwe.mitre.org/data/definitions/79.html +- rule_id: cwe-798 + title: Use of Hard-coded Credentials + rule_url: https://cwe.mitre.org/data/definitions/798.html +- rule_id: cwe-843 + title: Access of Resource Using Incompatible Type ('Type Confusion') + rule_url: https://cwe.mitre.org/data/definitions/843.html +- rule_id: cwe-862 + title: Missing Authorization + rule_url: https://cwe.mitre.org/data/definitions/862.html +- rule_id: cwe-863 + title: Incorrect Authorization + rule_url: https://cwe.mitre.org/data/definitions/863.html +- rule_id: cwe-89 + title: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') + rule_url: https://cwe.mitre.org/data/definitions/89.html +- rule_id: cwe-918 + title: Server-Side Request Forgery (SSRF) + rule_url: https://cwe.mitre.org/data/definitions/918.html +- rule_id: cwe-94 + title: Improper Control of Generation of Code ('Code Injection') + rule_url: https://cwe.mitre.org/data/definitions/94.html diff --git a/config/rules/misra-c-rules.yaml b/config/rules/misra-c-rules.yaml new file mode 100644 index 0000000000..334fbaf241 --- /dev/null +++ b/config/rules/misra-c-rules.yaml @@ -0,0 +1,3 @@ +- rule_id: '14.9' + title: '' + rule_url: '' diff --git a/config/rules/owasp-rules.yaml b/config/rules/owasp-rules.yaml new file mode 100644 index 0000000000..a59e51adca --- /dev/null +++ b/config/rules/owasp-rules.yaml @@ -0,0 +1,60 @@ +- rule_id: owasp-A01-2021 + title: Broken Access Control + rule_url: https://owasp.org/Top10/A01_2021-Broken_Access_Control/ +- rule_id: owasp-A01-2025 + title: Broken Access Control + rule_url: https://owasp.org/Top10/2025/A01_2025-Broken_Access_Control/ +- rule_id: owasp-A02-2021 + title: Cryptographic Failures + rule_url: https://owasp.org/Top10/A02_2021-Cryptographic_Failures/ +- rule_id: owasp-A02-2025 + title: Security Misconfiguration + rule_url: https://owasp.org/Top10/2025/A02_2025-Security_Misconfiguration/ +- rule_id: owasp-A03-2021 + title: Injection + rule_url: https://owasp.org/Top10/A03_2021-Injection/ +- rule_id: owasp-A03-2025 + title: Software Supply Chain Failures + rule_url: https://owasp.org/Top10/2025/A03_2025-Software_Supply_Chain_Failures/ +- rule_id: owasp-A04-2021 + title: Insecure Design + rule_url: https://owasp.org/Top10/A04_2021-Insecure_Design/ +- rule_id: owasp-A04-2025 + title: Cryptographic Failures + rule_url: https://owasp.org/Top10/2025/A04_2025-Cryptographic_Failures/ +- rule_id: owasp-A05-2021 + title: Security Misconfiguration + rule_url: https://owasp.org/Top10/A05_2021-Security_Misconfiguration/ +- rule_id: owasp-A05-2025 + title: Injection + rule_url: https://owasp.org/Top10/2025/A05_2025-Injection/ +- rule_id: owasp-A06-2021 + title: Vulnerable and Outdated Components + rule_url: https://owasp.org/Top10/A06_2021-Vulnerable_and_Outdated_Components/ +- rule_id: owasp-A06-2025 + title: Insecure Design + rule_url: https://owasp.org/Top10/2025/A06_2025-Insecure_Design/ +- rule_id: owasp-A07-2021 + title: Identification and Authentication Failures + rule_url: https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/ +- rule_id: owasp-A07-2025 + title: Authentication Failures + rule_url: https://owasp.org/Top10/2025/A07_2025-Authentication_Failures/ +- rule_id: owasp-A08-2021 + title: Software and Data Integrity Failures + rule_url: https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures/ +- rule_id: owasp-A08-2025 + title: Software or Data Integrity Failures + rule_url: https://owasp.org/Top10/2025/A08_2025-Software_or_Data_Integrity_Failures/ +- rule_id: owasp-A09-2021 + title: Security Logging and Monitoring Failures + rule_url: https://owasp.org/Top10/A09_2021-Security_Logging_and_Monitoring_Failures/ +- rule_id: owasp-A09-2025 + title: Security Logging and Alerting Failures + rule_url: https://owasp.org/Top10/2025/A09_2025-Security_Logging_and_Alerting_Failures/ +- rule_id: owasp-A10-2021 + title: Server-Side Request Forgery (SSRF) + rule_url: https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ +- rule_id: owasp-A10-2025 + title: Mishandling of Exceptional Conditions + rule_url: https://owasp.org/Top10/2025/A10_2025-Mishandling_of_Exceptional_Conditions/ diff --git a/config/rules/sei-cert-rules.yaml b/config/rules/sei-cert-rules.yaml new file mode 100644 index 0000000000..676577795c --- /dev/null +++ b/config/rules/sei-cert-rules.yaml @@ -0,0 +1,630 @@ +- rule_id: arr30-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/arrays-arr/arr30-c/ +- rule_id: arr32-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/arrays-arr/arr32-c/ +- rule_id: arr36-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/arrays-arr/arr36-c/ +- rule_id: arr37-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/arrays-arr/arr37-c/ +- rule_id: arr38-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/arrays-arr/arr38-c/ +- rule_id: arr39-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/arrays-arr/arr39-c/ +- rule_id: con30-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con30-c/ +- rule_id: con31-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con31-c/ +- rule_id: con32-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con32-c/ +- rule_id: con33-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con33-c/ +- rule_id: con34-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con34-c/ +- rule_id: con35-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con35-c/ +- rule_id: con36-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con36-c/ +- rule_id: con37-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con37-c/ +- rule_id: con38-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con38-c/ +- rule_id: con39-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con39-c/ +- rule_id: con40-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con40-c/ +- rule_id: con41-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con41-c/ +- rule_id: con43-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/concurrency-con/con43-c/ +- rule_id: con50-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/concurrency-con/con50-cpp/ +- rule_id: con51-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/concurrency-con/con51-cpp/ +- rule_id: con52-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/concurrency-con/con52-cpp/ +- rule_id: con53-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/concurrency-con/con53-cpp/ +- rule_id: con54-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/concurrency-con/con54-cpp/ +- rule_id: con55-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/concurrency-con/con55-cpp/ +- rule_id: con56-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/concurrency-con/con56-cpp/ +- rule_id: ctr50-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/containers-ctr/ctr50-cpp/ +- rule_id: ctr51-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/containers-ctr/ctr51-cpp/ +- rule_id: ctr52-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/containers-ctr/ctr52-cpp/ +- rule_id: ctr53-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/containers-ctr/ctr53-cpp/ +- rule_id: ctr54-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/containers-ctr/ctr54-cpp/ +- rule_id: ctr55-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/containers-ctr/ctr55-cpp/ +- rule_id: ctr56-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/containers-ctr/ctr56-cpp/ +- rule_id: ctr57-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/containers-ctr/ctr57-cpp/ +- rule_id: ctr58-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/containers-ctr/ctr58-cpp/ +- rule_id: dcl03-c + title: Use a static assertion to test the value of a constant expression + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/declarations-and-initialization-dcl/dcl03-c/ +- rule_id: dcl16-c + title: Use "L," not "l," to indicate a long value + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/declarations-and-initialization-dcl/dcl16-c/ +- rule_id: dcl30-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/declarations-and-initialization-dcl/dcl30-c/ +- rule_id: dcl31-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/declarations-and-initialization-dcl/dcl31-c/ +- rule_id: dcl36-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/declarations-and-initialization-dcl/dcl36-c/ +- rule_id: dcl37-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/declarations-and-initialization-dcl/dcl37-c/ +- rule_id: dcl38-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/declarations-and-initialization-dcl/dcl38-c/ +- rule_id: dcl39-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/declarations-and-initialization-dcl/dcl39-c/ +- rule_id: dcl40-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/declarations-and-initialization-dcl/dcl40-c/ +- rule_id: dcl41-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/declarations-and-initialization-dcl/dcl41-c/ +- rule_id: dcl50-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/declarations-and-initialization-dcl/dcl50-cpp/ +- rule_id: dcl51-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/declarations-and-initialization-dcl/dcl51-cpp/ +- rule_id: dcl52-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/declarations-and-initialization-dcl/dcl52-cpp/ +- rule_id: dcl53-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/declarations-and-initialization-dcl/dcl53-cpp/ +- rule_id: dcl54-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/declarations-and-initialization-dcl/dcl54-cpp/ +- rule_id: dcl55-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/declarations-and-initialization-dcl/dcl55-cpp/ +- rule_id: dcl56-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/declarations-and-initialization-dcl/dcl56-cpp/ +- rule_id: dcl57-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/declarations-and-initialization-dcl/dcl57-cpp/ +- rule_id: dcl58-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/declarations-and-initialization-dcl/dcl58-cpp/ +- rule_id: dcl59-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/declarations-and-initialization-dcl/dcl59-cpp/ +- rule_id: dcl60-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/declarations-and-initialization-dcl/dcl60-cpp/ +- rule_id: env30-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/environment-env/env30-c/ +- rule_id: env31-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/environment-env/env31-c/ +- rule_id: env32-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/environment-env/env32-c/ +- rule_id: env33-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/environment-env/env33-c/ +- rule_id: env34-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/environment-env/env34-c/ +- rule_id: err30-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/error-handling-err/err30-c/ +- rule_id: err32-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/error-handling-err/err32-c/ +- rule_id: err33-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/error-handling-err/err33-c/ +- rule_id: err34-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/error-handling-err/err34-c/ +- rule_id: err50-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/exceptions-and-error-handling-err/err50-cpp/ +- rule_id: err51-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/exceptions-and-error-handling-err/err51-cpp/ +- rule_id: err52-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/exceptions-and-error-handling-err/err52-cpp/ +- rule_id: err53-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/exceptions-and-error-handling-err/err53-cpp/ +- rule_id: err54-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/exceptions-and-error-handling-err/err54-cpp/ +- rule_id: err55-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/exceptions-and-error-handling-err/err55-cpp/ +- rule_id: err56-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/exceptions-and-error-handling-err/err56-cpp/ +- rule_id: err57-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/exceptions-and-error-handling-err/err57-cpp/ +- rule_id: err58-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/exceptions-and-error-handling-err/err58-cpp/ +- rule_id: err59-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/exceptions-and-error-handling-err/err59-cpp/ +- rule_id: err60-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/exceptions-and-error-handling-err/err60-cpp/ +- rule_id: err61-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/exceptions-and-error-handling-err/err61-cpp/ +- rule_id: err62-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/exceptions-and-error-handling-err/err62-cpp/ +- rule_id: exp30-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp30-c/ +- rule_id: exp32-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp32-c/ +- rule_id: exp33-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp33-c/ +- rule_id: exp34-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp34-c/ +- rule_id: exp35-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp35-c/ +- rule_id: exp36-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp36-c/ +- rule_id: exp37-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp37-c/ +- rule_id: exp39-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp39-c/ +- rule_id: exp40-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp40-c/ +- rule_id: exp42-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp42-c/ +- rule_id: exp43-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp43-c/ +- rule_id: exp44-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp44-c/ +- rule_id: exp45-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp45-c/ +- rule_id: exp46-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp46-c/ +- rule_id: exp47-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp47-c/ +- rule_id: exp50-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/expressions-exp/exp50-cpp/ +- rule_id: exp51-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/expressions-exp/exp51-cpp/ +- rule_id: exp52-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/expressions-exp/exp52-cpp/ +- rule_id: exp53-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/expressions-exp/exp53-cpp/ +- rule_id: exp54-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/expressions-exp/exp54-cpp/ +- rule_id: exp55-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/expressions-exp/exp55-cpp/ +- rule_id: exp56-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/expressions-exp/exp56-cpp/ +- rule_id: exp57-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/expressions-exp/exp57-cpp/ +- rule_id: exp58-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/expressions-exp/exp58-cpp/ +- rule_id: exp59-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/expressions-exp/exp59-cpp/ +- rule_id: exp60-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/expressions-exp/exp60-cpp/ +- rule_id: exp61-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/expressions-exp/exp61-cpp/ +- rule_id: exp62-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/expressions-exp/exp62-cpp/ +- rule_id: exp63-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/expressions-exp/exp63-cpp/ +- rule_id: fio30-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio30-c/ +- rule_id: fio32-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio32-c/ +- rule_id: fio34-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio34-c/ +- rule_id: fio37-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio37-c/ +- rule_id: fio38-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio38-c/ +- rule_id: fio39-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio39-c/ +- rule_id: fio40-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio40-c/ +- rule_id: fio41-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio41-c/ +- rule_id: fio42-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio42-c/ +- rule_id: fio44-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio44-c/ +- rule_id: fio45-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio45-c/ +- rule_id: fio46-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio46-c/ +- rule_id: fio47-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/input-output-fio/fio47-c/ +- rule_id: fio50-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/input-output-fio/fio50-cpp/ +- rule_id: fio51-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/input-output-fio/fio51-cpp/ +- rule_id: flp30-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/floating-point-flp/flp30-c/ +- rule_id: flp32-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/floating-point-flp/flp32-c/ +- rule_id: flp34-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/floating-point-flp/flp34-c/ +- rule_id: flp36-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/floating-point-flp/flp36-c/ +- rule_id: flp37-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/floating-point-flp/flp37-c/ +- rule_id: int09-c + title: Ensure enumeration constants map to unique values + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/integers-int/int09-c/ +- rule_id: int10-c + title: Do not assume a positive remainder when using the % operator + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/integers-int/int10-c/ +- rule_id: int30-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/integers-int/int30-c/ +- rule_id: int31-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/integers-int/int31-c/ +- rule_id: int32-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/integers-int/int32-c/ +- rule_id: int33-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/integers-int/int33-c/ +- rule_id: int34-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/integers-int/int34-c/ +- rule_id: int35-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/integers-int/int35-c/ +- rule_id: int36-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/integers-int/int36-c/ +- rule_id: int50-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/integers-int/int50-cpp/ +- rule_id: mem30-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/memory-management-mem/mem30-c/ +- rule_id: mem31-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/memory-management-mem/mem31-c/ +- rule_id: mem33-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/memory-management-mem/mem33-c/ +- rule_id: mem34-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/memory-management-mem/mem34-c/ +- rule_id: mem35-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/memory-management-mem/mem35-c/ +- rule_id: mem36-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/memory-management-mem/mem36-c/ +- rule_id: mem50-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/memory-management-mem/mem50-cpp/ +- rule_id: mem51-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/memory-management-mem/mem51-cpp/ +- rule_id: mem52-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/memory-management-mem/mem52-cpp/ +- rule_id: mem53-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/memory-management-mem/mem53-cpp/ +- rule_id: mem54-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/memory-management-mem/mem54-cpp/ +- rule_id: mem55-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/memory-management-mem/mem55-cpp/ +- rule_id: mem56-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/memory-management-mem/mem56-cpp/ +- rule_id: mem57-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/memory-management-mem/mem57-cpp/ +- rule_id: msc12-c + title: Detect and remove code that has no effect or is never executed + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/miscellaneous-msc/msc12-c/ +- rule_id: msc24-c + title: Do not use deprecated or obsolescent functions + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/miscellaneous-msc/msc24-c/ +- rule_id: msc30-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/miscellaneous-msc/msc30-c/ +- rule_id: msc32-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/miscellaneous-msc/msc32-c/ +- rule_id: msc33-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/miscellaneous-msc/msc33-c/ +- rule_id: msc37-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/miscellaneous-msc/msc37-c/ +- rule_id: msc38-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/miscellaneous-msc/msc38-c/ +- rule_id: msc39-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/miscellaneous-msc/msc39-c/ +- rule_id: msc40-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/miscellaneous-msc/msc40-c/ +- rule_id: msc41-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/miscellaneous-msc/msc41-c/ +- rule_id: msc50-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/miscellaneous-msc/msc50-cpp/ +- rule_id: msc51-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/miscellaneous-msc/msc51-cpp/ +- rule_id: msc52-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/miscellaneous-msc/msc52-cpp/ +- rule_id: msc53-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/miscellaneous-msc/msc53-cpp/ +- rule_id: msc54-cpp + title: A signal handler must be a plain old function + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/miscellaneous-msc/msc54-cpp/ +- rule_id: oop50-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/object-oriented-programming-oop/oop50-cpp/ +- rule_id: oop51-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/object-oriented-programming-oop/oop51-cpp/ +- rule_id: oop52-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/object-oriented-programming-oop/oop52-cpp/ +- rule_id: oop53-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/object-oriented-programming-oop/oop53-cpp/ +- rule_id: oop54-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/object-oriented-programming-oop/oop54-cpp/ +- rule_id: oop55-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/object-oriented-programming-oop/oop55-cpp/ +- rule_id: oop56-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/object-oriented-programming-oop/oop56-cpp/ +- rule_id: oop57-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/object-oriented-programming-oop/oop57-cpp/ +- rule_id: oop58-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/object-oriented-programming-oop/oop58-cpp/ +- rule_id: pos30-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos30-c/ +- rule_id: pos34-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos34-c/ +- rule_id: pos35-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos35-c/ +- rule_id: pos36-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos36-c/ +- rule_id: pos37-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos37-c/ +- rule_id: pos38-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos38-c/ +- rule_id: pos39-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos39-c/ +- rule_id: pos44-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos44-c/ +- rule_id: pos47-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos47-c/ +- rule_id: pos48-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos48-c/ +- rule_id: pos49-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos49-c/ +- rule_id: pos50-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos50-c/ +- rule_id: pos51-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos51-c/ +- rule_id: pos52-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos52-c/ +- rule_id: pos53-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos53-c/ +- rule_id: pos54-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/posix-pos/pos54-c/ +- rule_id: pre02-c + title: Macro replacement lists should be parenthesized + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/preprocessor-pre/pre02-c/ +- rule_id: pre30-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/preprocessor-pre/pre30-c/ +- rule_id: pre31-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/preprocessor-pre/pre31-c/ +- rule_id: pre32-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/preprocessor-pre/pre32-c/ +- rule_id: sig30-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/signals-sig/sig30-c/ +- rule_id: sig31-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/signals-sig/sig31-c/ +- rule_id: sig34-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/signals-sig/sig34-c/ +- rule_id: sig35-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/signals-sig/sig35-c/ +- rule_id: str30-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/characters-and-strings-str/str30-c/ +- rule_id: str31-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/characters-and-strings-str/str31-c/ +- rule_id: str32-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/characters-and-strings-str/str32-c/ +- rule_id: str34-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/characters-and-strings-str/str34-c/ +- rule_id: str37-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/characters-and-strings-str/str37-c/ +- rule_id: str38-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/characters-and-strings-str/str38-c/ +- rule_id: str50-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/characters-and-strings-str/str50-cpp/ +- rule_id: str51-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/characters-and-strings-str/str51-cpp/ +- rule_id: str52-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/characters-and-strings-str/str52-cpp/ +- rule_id: str53-cpp + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-cpp-coding-standard/rules/characters-and-strings-str/str53-cpp/ +- rule_id: win30-c + title: '' + rule_url: https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/microsoft-windows-win/win30-c/ diff --git a/web/client/codechecker_client/cmd_line_client.py b/web/client/codechecker_client/cmd_line_client.py index 259c6bd6c2..3aafc11a84 100644 --- a/web/client/codechecker_client/cmd_line_client.py +++ b/web/client/codechecker_client/cmd_line_client.py @@ -1635,18 +1635,38 @@ def formatted_guidelines(guideline_rules: Iterable[dict]) -> str | None: for stat in checker_details.values()] checker_labels = client.getCheckerLabels(checkers) + # Collect the guidelines that appear for the queried checkers. A checker's + # guidelines are derived on the server from its "rule:" labels. + all_guideline_names = set() + for labels in checker_labels: + for label in labels: + if label.startswith("guideline:"): + all_guideline_names.add(label.split("guideline:", 1)[1]) + + # Fetch the rule ids that belong to each guideline so that a checker's + # rules can be bucketed under the guideline they belong to. A single rule + # may belong to multiple guidelines. + guideline_rule_map: dict = {} + if all_guideline_names: + guideline_rules = client.getGuidelineRules([ + ttypes.Guideline(guidelineName=name) + for name in sorted(all_guideline_names)]) + for name, rules in guideline_rules.items(): + guideline_rule_map[name] = {rule.ruleId.lower() for rule in rules} + all_guideline_rules = [] for labels in checker_labels: - guideline_entries = [] - guidelines = [label.split("guideline:")[1] - for label in labels if label.startswith("guideline")] + guidelines = [label.split("guideline:", 1)[1] + for label in labels if label.startswith("guideline:")] + checker_rules = {label.split("rule:", 1)[1].lower() + for label in labels if label.startswith("rule:")} + guideline_entries = [] for guideline in guidelines: + rules_of_guideline = guideline_rule_map.get(guideline, set()) guideline_entries.append({ "guideline": guideline, - "rules": [label.split(f"{guideline}:")[1] - for label in labels - if label.startswith(f"{guideline}:")] + "rules": sorted(checker_rules & rules_of_guideline) }) all_guideline_rules.append(guideline_entries) diff --git a/web/codechecker_web/shared/webserver_context.py b/web/codechecker_web/shared/webserver_context.py index f3bf10a38c..d2f329a5f4 100644 --- a/web/codechecker_web/shared/webserver_context.py +++ b/web/codechecker_web/shared/webserver_context.py @@ -74,8 +74,8 @@ def __init__(self): guidelines_dir = os.path.join(self._data_files_dir_path, 'config', 'guidelines') - self._checker_labels = CheckerLabels(labels_dir) self._guidelines = Guidelines(guidelines_dir) + self._checker_labels = CheckerLabels(labels_dir, self._guidelines) self.__system_comment_map = load_json(self.system_comment_map_file, {}) self.__git_commit_urls = self.__get_git_commit_urls() self.__package_version = None diff --git a/web/server/codechecker_server/api/report_server.py b/web/server/codechecker_server/api/report_server.py index ef4d732954..c32e0c6a57 100644 --- a/web/server/codechecker_server/api/report_server.py +++ b/web/server/codechecker_server/api/report_server.py @@ -3122,7 +3122,7 @@ def getGuidelineRules( continue for rule in rules: checkers = self._context.checker_labels.checkers_by_labels( - [f"{guideline.guidelineName}:{rule}"]) + [f"rule:{rule}"]) guideline_rules[guideline.guidelineName].append( Rule(