docs(security): Semgrep triage inventory (6 findings) - #382
docs(security): Semgrep triage inventory (6 findings)#382marlon-costa-dc wants to merge 2 commits into
Conversation
Inventario dos findings da plataforma Semgrep com regra, arquivo e linha por achado. Totais: high 1, medium 5, low 0 (high confidence: 4) Classes: Insecure Configuration x4; (sem classe) x1; Improper Authorization x1 Bead: mro-p57t.5 Nenhuma alteracao de codigo de producao. Findings SAST exigem analise caso a caso do fluxo de dados.
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…e messages Cada achado agora traz: - codigo real numerado extraido da worktree (linha >>> = sink) - mensagem completa da regra (descricao do problema e do fix) - CWE/classe de vulnerabilidade e effort onde disponivel
|



Triagem Semgrep — inventário
6 findings — high 1, medium 5, low 0 (high confidence: 4)
Bead:
mro-p57t.5O que este PR contém
Apenas
docs/security/semgrep-triage.md: regra, severidade, confiança, arquivo e linha de cada finding, com coluna de decisão a preencher (corrigir/falso-positivo/risco-aceito).Nenhuma alteração de código.
Classes: Insecure Configuration x4; (sem classe) x1; Improper Authorization x1
Findings SAST não têm remediação automática — cada um exige seguir o fluxo de dados até o sink. Priorizar high com confidence=high.
Dados brutos:
~/semgrep-violations/by-repo/flext-sh_flext-core.jsonSummary by cubic
Adds
docs/security/semgrep-triage.mdwith an inventory of 6 Semgrep findings (1 high, 5 medium) forflext-sh/flext-core, listing rule, severity, confidence, file and line, plus a decision column for triage. Enriched with numbered code snippets (sink marked with >>>), full rule messages, and vulnerability metadata (class, CWE/OWASP, effort); docs-only change, no code modifications.Written for commit 0f48f9d. Summary will update on new commits.