From ff0abcc2abf391f1fb61d47d15f06217c1ce93e0 Mon Sep 17 00:00:00 2001 From: Daniel Krupp Date: Mon, 8 Jul 2024 14:26:49 +0200 Subject: [PATCH] Removing alpha checkers from the security profile Alpha checkers are not production ready so they should be removed fromt the security profile. This way, the profile can be used in production without explicitly disabling alpha checkers. --- config/labels/analyzers/clangsa.json | 17 ----------------- 1 file changed, 17 deletions(-) diff --git a/config/labels/analyzers/clangsa.json b/config/labels/analyzers/clangsa.json index 0edb7ba871..ec217740ef 100644 --- a/config/labels/analyzers/clangsa.json +++ b/config/labels/analyzers/clangsa.json @@ -31,13 +31,11 @@ "alpha.core.CastToStruct": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#alpha-core-casttostruct-c-c", "profile:extreme", - "profile:security", "severity:LOW" ], "alpha.core.Conversion": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#alpha-core-conversion-c-c-objc", "profile:extreme", - "profile:security", "profile:sensitive", "severity:LOW" ], @@ -59,13 +57,11 @@ "alpha.core.PointerArithm": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#alpha-core-pointerarithm-c", "profile:extreme", - "profile:security", "severity:LOW" ], "alpha.core.PointerSub": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#alpha-core-pointersub-c", "profile:extreme", - "profile:security", "severity:LOW" ], "alpha.core.PthreadLockBase": [ @@ -214,32 +210,27 @@ "alpha.security.ArrayBound": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#alpha-security-arraybound-c", "profile:extreme", - "profile:security", "severity:HIGH" ], "alpha.security.ArrayBoundV2": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#alpha-security-arrayboundv2-c", "profile:extreme", - "profile:security", "severity:HIGH" ], "alpha.security.MallocOverflow": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#alpha-security-mallocoverflow-c", "profile:extreme", - "profile:security", "severity:HIGH" ], "alpha.security.MmapWriteExec": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#alpha-security-mmapwriteexec-c", "profile:extreme", - "profile:security", "profile:sensitive", "severity:MEDIUM" ], "alpha.security.ReturnPtrRange": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#alpha-security-returnptrrange-c", "profile:extreme", - "profile:security", "profile:sensitive", "severity:HIGH" ], @@ -247,7 +238,6 @@ "doc_url:https://releases.llvm.org/17.0.1/tools/clang/docs/analyzer/checkers.html#alpha-security-cert-env-invalidptr", "profile:default", "profile:extreme", - "profile:security", "profile:sensitive", "severity:MEDIUM" ], @@ -255,14 +245,12 @@ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#alpha-security-cert-pos-34c", "profile:default", "profile:extreme", - "profile:security", "profile:sensitive", "severity:HIGH" ], "alpha.security.taint.TaintPropagation": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#alpha-security-taint-taintpropagation-c-c", "profile:extreme", - "profile:security", "profile:sensitive", "severity:HIGH" ], @@ -275,7 +263,6 @@ "alpha.unix.Chroot": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#alpha-unix-chroot-c", "profile:extreme", - "profile:security", "profile:sensitive", "severity:MEDIUM" ], @@ -288,7 +275,6 @@ "alpha.unix.PthreadLock": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#alpha-unix-pthreadlock-c", "profile:extreme", - "profile:security", "profile:sensitive", "severity:HIGH" ], @@ -305,14 +291,12 @@ "alpha.unix.Stream": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#alpha-unix-stream-c", "profile:extreme", - "profile:security", "profile:sensitive", "severity:MEDIUM" ], "alpha.unix.cstring.BufferOverlap": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#alpha-unix-cstring-bufferoverlap-c", "profile:extreme", - "profile:security", "severity:HIGH" ], "alpha.unix.cstring.NotNullTerminated": [ @@ -324,7 +308,6 @@ "alpha.unix.cstring.OutOfBounds": [ "doc_url:https://clang.llvm.org/docs/analyzer/checkers.html#alpha-unix-cstring-outofbounds-c", "profile:extreme", - "profile:security", "profile:sensitive", "severity:HIGH" ],