docs(security): Semgrep triage inventory (5 findings) - #51
docs(security): Semgrep triage inventory (5 findings)#51marlon-costa-dc wants to merge 2 commits into
Conversation
Inventario dos findings da plataforma Semgrep com regra, arquivo e linha por achado. Totais: high 0, medium 5, low 0 (high confidence: 4) Classes: Insecure Configuration x4; Improper Authorization x1 Bead: mro-p57t.31 Nenhuma alteracao de codigo de producao. Findings SAST exigem analise caso a caso do fluxo de dados.
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…e messages Cada achado agora traz: - codigo real numerado extraido da worktree (linha >>> = sink) - mensagem completa da regra (descricao do problema e do fix) - CWE/classe de vulnerabilidade e effort onde disponivel
|



Triagem Semgrep — inventário
5 findings — high 0, medium 5, low 0 (high confidence: 4)
Bead:
mro-p57t.31O que este PR contém
Apenas
docs/security/semgrep-triage.md: regra, severidade, confiança, arquivo e linha de cada finding, com coluna de decisão a preencher (corrigir/falso-positivo/risco-aceito).Nenhuma alteração de código.
Classes: Insecure Configuration x4; Improper Authorization x1
Findings SAST não têm remediação automática — cada um exige seguir o fluxo de dados até o sink. Priorizar high com confidence=high.
Dados brutos:
~/semgrep-violations/by-repo/flext-sh_flext-tests.jsonSummary by cubic
Added
docs/security/semgrep-triage.mdwith a Semgrep triage inventory of 5 medium findings (0 high, 0 low).Each entry now includes the full rule message (with fix guidance), CWE/class, and a numbered code snippet with the sink marked (>>>), plus file/line, severity, confidence, and a triage decision; no code changes.
Written for commit 1d061df. Summary will update on new commits.