py/HardcodedCredentials misses common credential patterns and flags usernames.
还没有人认领这个 Issue。
评估
调研方向
从 py/HardcodedCredentials 规则开始,复现 issue 中的 API-key、URL-credential、username 和 options 示例。阅读该规则如何对 credential 模式建模,以及如何通过 options 字典传播 taint。完成的标准是:能够检测出缺失的 credential 情况,同时不会将普通 username 视为 credential,并且覆盖报告中的示例。
由索引模型根据 Issue 内容生成。
描述
Some patterns are missing, for example:
api_key = "sk-1234567890" # Missed: API key
db_url = "postgres://user:pass@host/db" # Missed: URL credentials
Second, I am not sure if the username is seen as a credential in a usual project, but this rule will flag the username.
This is beyond the definition in CWE-798 (
The product contains hard-coded credentials, such as a password or cryptographic key.)
USERNAME = "admin" # Flagged
I also found that the rule will lose the taint in the following case:
USERNAME = "road_runner"
PASSWORD = "insecure_pwd"
options = {"password": PASSWORD}
conn = client.connect(username=USERNAME, password=PASSWORD) # Flagged
log.debug("Options: %s", options) # Missing
conn = client.connect(options=options) # Still Missing
- 主要语言
- CodeQL
- 星标
- 10.1k
- 派生
- 2.1k
- 平均合并
- 2 天 16 小时
- 30 天内合并 PR
- 143
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
github/codeql 的其他 Issue
-
agentic-workflows
难度 2/5 1-3 小时 新手友好度 70/100
-
false-positive javascript
难度 2/5 1-3 小时 新手友好度 84/100
-
难度 2/5 1-3 小时 新手友好度 82/100
-
难度 2/5 1-3 小时 新手友好度 78/100
-
false-positive
难度 2/5 1-3 小时 新手友好度 70/100
相似的 Issue
-
enhancement
难度 2/5 1-3 小时 新手友好度 70/100
canonical/paas-charm#368 · 1 条评论 ·
-
enhancement
难度 2/5 1-3 小时 新手友好度 75/100
palladius/rails8-app-on-gcp#142 ·
-
难度 1/5 1 小时以内 新手友好度 90/100
StevenBlack/hosts#3256 ·
-
难度 2/5 1-3 小时 新手友好度 75/100
corsairdev/corsair#1764 ·
-
oblt-aw/detector/security
难度 2/5 1-3 小时 新手友好度 70/100