Files
codeql/cpp/change-notes/2021-08-23-ctime-weaken-claims.md
Jonas Jensen 19ee64d9ad C++:Lower potentially-dangerous-function precision
There have been multiple reports of false positives from this query over
time. Now that it has `@security-severity 10.0`, these false positives
look even worse.

The query looks purely for calls to functions with certain names, not
at whether the calls happen in a dangerous context. To justify a higher
precision, the query should only flag calls that happen in a thread or
another non-reentrant context.
2021-08-24 17:14:42 +02:00

247 B

lgtm,codescanning

  • Lowered the precision of cpp/potentially-dangerous-function so it is run but not displayed on LGTM by default and so it's only run and displayed on Code Scanning if a broader suite like cpp-security-extended is opted into.