mirror of
https://github.com/github/codeql.git
synced 2026-04-21 15:05:56 +02:00
Remove variables with "null" in their name as sources
This commit is contained in:
@@ -9,7 +9,12 @@ private import semmle.code.java.security.Sanitizers
|
||||
|
||||
/** A variable that may hold sensitive information, judging by its name. */
|
||||
class VariableWithSensitiveName extends Variable {
|
||||
VariableWithSensitiveName() { this.getName().regexpMatch(getCommonSensitiveInfoRegex()) }
|
||||
VariableWithSensitiveName() {
|
||||
exists(string name | name = this.getName() |
|
||||
name.regexpMatch(getCommonSensitiveInfoRegex()) and
|
||||
not name.regexpMatch("(?i).*null.*")
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
/** A reference to a variable that may hold sensitive information, judging by its name. */
|
||||
|
||||
Reference in New Issue
Block a user