Skip to content
This repository was archived by the owner on Jun 30, 2023. It is now read-only.

Report CVEs identified - #60

Merged
ericchiang merged 1 commit into
google:mainfrom
singlethink:report-cves
May 10, 2022
Merged

ericchiang merged 1 commit into
google:mainfrom
singlethink:report-cves

Conversation

@singlethink

Copy link
Copy Markdown
Contributor

Updates jar.Parse to return the specific CVEs identified during the
scan.

To ensure that refactoring of detection logic is correct, I've tested
this on a corpus of all log4j2 releases through 2.16.0 and verified
that there are no false positives or false negatives.

Comment thread jar/jar.go
Comment thread jar/jar_test.go Outdated

@junjiey1988 junjiey1988 left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Mostly LGTM with one question and a minor nit.

Updates jar.Parse to return the specific CVEs identified during the
scan.

To ensure that refactoring of detection logic is correct, I've tested
this on a corpus of all log4j2 releases through 2.16.0 and verified
that there are no false positives or false negatives.

@junjiey1988 junjiey1988 left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks Matt!

@ericchiang
ericchiang merged commit 48dbe0d into google:main May 10, 2022
@singlethink
singlethink deleted the report-cves branch May 10, 2022 21:39
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants