Skip to content
#

static-code-analysis

Here are 386 public repositories matching this topic...

ngan
ngan commented Mar 10, 2021

Is your feature request related to a problem? Please describe.

I'm kicking the tires on changing our Gemfile to gems.rb. However, we have many internal gems within our monorepo and it just occurred to me that it would be cool to have a configurable cop that enforces one or the other.

Describe the solution you'd like

A cop that checks to make sure you have a Gemfile or a `gems.

semgrep
simon-engledew
simon-engledew commented Apr 1, 2021

Describe the bug

According to the SARIF spec, invocation should be the child of a run:

https://docs.oasis-open.org/sarif/sarif/v2.1.0/csprd01/sarif-v2.1.0-csprd01.html#_Toc10540933

Currently build_sarif_output is nesting it at the root of the document, which is producing SARIF which does not conform to the specification:

https://github.com/returntocorp/semgrep/blob/9a73a142dc

vuryleo
vuryleo commented Nov 8, 2019

e.g.

# map.py
def func(a: int) -> float:
    return float(a)

map(func, ['str'])
$ pytype map.py
Computing dependencies
Analyzing 1 sources with 0 local dependencies
ninja: Entering directory `/[redacted]/.pytype'
ninja: no work to do.
Success: no errors found

while

$ mypy map.py
map.py:5: error: Argument 1 to "map" has incompatible type "Ca
larastan
Meijuh
Meijuh commented Mar 4, 2021

I am looking for a list of visitors/detectors that I can omit. Specifically, I am look for the allowed values for https://spotbugs.github.io/spotbugs-maven-plugin/spotbugs-mojo.html#omitVisitors.
Previously, in SpotBugs 3.1, this list could be found under "detectors" at e.g. https://spotbugs-in-kengo-toda.readthedocs.io/en/lqc-list-detectors/detectors.html#standard-detectors, but that page/menu

IvenBach
IvenBach commented Nov 17, 2020

Justification
When first loading RD CodeExplorer displays all nodes as expanded to show contents. If you have other projects (Personal Macro Workbook (PMW), Excel add ins (*.xlam), etc...) they can obscure the project you want to work on.

Description
Add ability to expand/collapse all project nodes to quickly find project you wish to work with.

Where to get started
TestExplore

Improve this page

Add a description, image, and links to the static-code-analysis topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the static-code-analysis topic, visit your repo's landing page and select "manage topics."

Learn more