Skip to content

Commit 2e8bd62

Browse files
authored
Merge pull request github#6164 from github/workflow/coverage/update
Update CSV framework coverage reports
2 parents 267e369 + 991404a commit 2e8bd62

File tree

2 files changed

+59
-52
lines changed

2 files changed

+59
-52
lines changed
Lines changed: 50 additions & 44 deletions
Original file line numberDiff line numberDiff line change
@@ -1,44 +1,50 @@
1-
package,sink,source,summary,sink:bean-validation,sink:create-file,sink:header-splitting,sink:information-leak,sink:jexl,sink:ldap,sink:open-url,sink:set-hostname-verifier,sink:url-open-stream,sink:xpath,sink:xss,source:remote,summary:taint,summary:value
2-
android.util,,16,,,,,,,,,,,,,16,,
3-
android.webkit,3,2,,,,,,,,,,,,3,2,,
4-
com.esotericsoftware.kryo.io,,,1,,,,,,,,,,,,,1,
5-
com.esotericsoftware.kryo5.io,,,1,,,,,,,,,,,,,1,
6-
com.fasterxml.jackson.databind,,,3,,,,,,,,,,,,,3,
7-
com.google.common.base,,,34,,,,,,,,,,,,,28,6
8-
com.google.common.io,6,,73,,,,,,,,,6,,,,72,1
9-
com.unboundid.ldap.sdk,17,,,,,,,,17,,,,,,,,
10-
java.beans,,,1,,,,,,,,,,,,,1,
11-
java.io,3,,20,,3,,,,,,,,,,,20,
12-
java.lang,,,3,,,,,,,,,,,,,1,2
13-
java.net,2,3,4,,,,,,,2,,,,,3,4,
14-
java.nio,10,,2,,10,,,,,,,,,,,2,
15-
java.util,,,283,,,,,,,,,,,,,15,268
16-
javax.naming.directory,1,,,,,,,,1,,,,,,,,
17-
javax.net.ssl,2,,,,,,,,,,2,,,,,,
18-
javax.servlet,4,21,2,,,3,1,,,,,,,,21,2,
19-
javax.validation,1,1,,1,,,,,,,,,,,1,,
20-
javax.ws.rs.core,1,,,,,1,,,,,,,,,,,
21-
javax.xml.transform.sax,,,4,,,,,,,,,,,,,4,
22-
javax.xml.transform.stream,,,2,,,,,,,,,,,,,2,
23-
javax.xml.xpath,3,,,,,,,,,,,,3,,,,
24-
org.apache.commons.codec,,,2,,,,,,,,,,,,,2,
25-
org.apache.commons.io,,,22,,,,,,,,,,,,,22,
26-
org.apache.commons.jexl2,15,,,,,,,15,,,,,,,,,
27-
org.apache.commons.jexl3,15,,,,,,,15,,,,,,,,,
28-
org.apache.commons.lang3,,,370,,,,,,,,,,,,,324,46
29-
org.apache.commons.text,,,272,,,,,,,,,,,,,220,52
30-
org.apache.directory.ldap.client.api,1,,,,,,,,1,,,,,,,,
31-
org.apache.hc.core5.function,,,1,,,,,,,,,,,,,1,
32-
org.apache.hc.core5.http,1,2,39,,,,,,,,,,,1,2,39,
33-
org.apache.hc.core5.net,,,2,,,,,,,,,,,,,2,
34-
org.apache.hc.core5.util,,,24,,,,,,,,,,,,,18,6
35-
org.apache.http,2,3,67,,,,,,,,,,,2,3,59,8
36-
org.dom4j,20,,,,,,,,,,,,20,,,,
37-
org.springframework.ldap.core,14,,,,,,,,14,,,,,,,,
38-
org.springframework.security.web.savedrequest,,6,,,,,,,,,,,,,6,,
39-
org.springframework.web.client,,3,,,,,,,,,,,,,3,,
40-
org.springframework.web.context.request,,8,,,,,,,,,,,,,8,,
41-
org.springframework.web.multipart,,12,,,,,,,,,,,,,12,,
42-
org.xml.sax,,,1,,,,,,,,,,,,,1,
43-
org.xmlpull.v1,,3,,,,,,,,,,,,,3,,
44-
play.mvc,,4,,,,,,,,,,,,,4,,
1+
package,sink,source,summary,sink:bean-validation,sink:create-file,sink:header-splitting,sink:information-leak,sink:jexl,sink:ldap,sink:open-url,sink:set-hostname-verifier,sink:url-open-stream,sink:url-redirect,sink:xpath,sink:xss,source:remote,summary:taint,summary:value
2+
android.util,,16,,,,,,,,,,,,,,16,,
3+
android.webkit,3,2,,,,,,,,,,,,,3,2,,
4+
com.esotericsoftware.kryo.io,,,1,,,,,,,,,,,,,,1,
5+
com.esotericsoftware.kryo5.io,,,1,,,,,,,,,,,,,,1,
6+
com.fasterxml.jackson.databind,,,3,,,,,,,,,,,,,,3,
7+
com.google.common.base,,,85,,,,,,,,,,,,,,62,23
8+
com.google.common.io,6,,73,,,,,,,,,6,,,,,72,1
9+
com.unboundid.ldap.sdk,17,,,,,,,,17,,,,,,,,,
10+
jakarta.ws.rs.client,1,,,,,,,,,1,,,,,,,,
11+
jakarta.ws.rs.core,2,,143,,,,,,,,,,2,,,,88,55
12+
java.beans,,,1,,,,,,,,,,,,,,1,
13+
java.io,3,,20,,3,,,,,,,,,,,,20,
14+
java.lang,,,3,,,,,,,,,,,,,,1,2
15+
java.net,4,3,6,,,,,,,4,,,,,,3,6,
16+
java.nio,10,,2,,10,,,,,,,,,,,,2,
17+
java.util,,,295,,,,,,,,,,,,,,15,280
18+
javax.naming.directory,1,,,,,,,,1,,,,,,,,,
19+
javax.net.ssl,2,,,,,,,,,,2,,,,,,,
20+
javax.servlet,4,21,2,,,3,1,,,,,,,,,21,2,
21+
javax.validation,1,1,,1,,,,,,,,,,,,1,,
22+
javax.ws.rs.client,1,,,,,,,,,1,,,,,,,,
23+
javax.ws.rs.core,3,,143,,,1,,,,,,,2,,,,88,55
24+
javax.xml.transform.sax,,,4,,,,,,,,,,,,,,4,
25+
javax.xml.transform.stream,,,2,,,,,,,,,,,,,,2,
26+
javax.xml.xpath,3,,,,,,,,,,,,,3,,,,
27+
org.apache.commons.codec,,,2,,,,,,,,,,,,,,2,
28+
org.apache.commons.collections,,,99,,,,,,,,,,,,,,4,95
29+
org.apache.commons.collections4,,,99,,,,,,,,,,,,,,4,95
30+
org.apache.commons.io,,,22,,,,,,,,,,,,,,22,
31+
org.apache.commons.jexl2,15,,,,,,,15,,,,,,,,,,
32+
org.apache.commons.jexl3,15,,,,,,,15,,,,,,,,,,
33+
org.apache.commons.lang3,,,420,,,,,,,,,,,,,,292,128
34+
org.apache.commons.text,,,272,,,,,,,,,,,,,,220,52
35+
org.apache.directory.ldap.client.api,1,,,,,,,,1,,,,,,,,,
36+
org.apache.hc.core5.function,,,1,,,,,,,,,,,,,,1,
37+
org.apache.hc.core5.http,1,2,39,,,,,,,,,,,,1,2,39,
38+
org.apache.hc.core5.net,,,2,,,,,,,,,,,,,,2,
39+
org.apache.hc.core5.util,,,24,,,,,,,,,,,,,,18,6
40+
org.apache.http,27,3,70,,,,,,,25,,,,,2,3,62,8
41+
org.dom4j,20,,,,,,,,,,,,,20,,,,
42+
org.springframework.http,14,,,,,,,,,14,,,,,,,,
43+
org.springframework.ldap.core,14,,,,,,,,14,,,,,,,,,
44+
org.springframework.security.web.savedrequest,,6,,,,,,,,,,,,,,6,,
45+
org.springframework.web.client,13,3,,,,,,,,13,,,,,,3,,
46+
org.springframework.web.context.request,,8,,,,,,,,,,,,,,8,,
47+
org.springframework.web.multipart,,12,,,,,,,,,,,,,,12,,
48+
org.xml.sax,,,1,,,,,,,,,,,,,,1,
49+
org.xmlpull.v1,,3,,,,,,,,,,,,,,3,,
50+
play.mvc,,4,,,,,,,,,,,,,,4,,

java/documentation/library-coverage/coverage.rst

Lines changed: 9 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -8,14 +8,15 @@ Java framework & library support
88

99
Framework / library,Package,Remote flow sources,Taint & value steps,Sinks (total),`CWE‑022` :sub:`Path injection`,`CWE‑036` :sub:`Path traversal`,`CWE‑079` :sub:`Cross-site scripting`,`CWE‑089` :sub:`SQL injection`,`CWE‑090` :sub:`LDAP injection`,`CWE‑094` :sub:`Code injection`,`CWE‑319` :sub:`Cleartext transmission`
1010
Android,``android.*``,18,,3,,,3,,,,
11+
`Apache Commons Collections <https://commons.apache.org/proper/commons-collections/>`_,"``org.apache.commons.collections``, ``org.apache.commons.collections4``",,198,,,,,,,,
1112
`Apache Commons IO <https://commons.apache.org/proper/commons-io/>`_,``org.apache.commons.io``,,22,,,,,,,,
12-
`Apache Commons Lang <https://commons.apache.org/proper/commons-lang/>`_,``org.apache.commons.lang3``,,370,,,,,,,,
13+
`Apache Commons Lang <https://commons.apache.org/proper/commons-lang/>`_,``org.apache.commons.lang3``,,420,,,,,,,,
1314
`Apache Commons Text <https://commons.apache.org/proper/commons-text/>`_,``org.apache.commons.text``,,272,,,,,,,,
14-
`Apache HttpComponents <https://hc.apache.org/>`_,"``org.apache.hc.core5.*``, ``org.apache.http``",5,133,3,,,3,,,,
15-
`Google Guava <https://guava.dev/>`_,``com.google.common.*``,,107,6,,6,,,,,
16-
Java Standard Library,``java.*``,3,313,15,13,,,,,,2
17-
Java extensions,``javax.*``,22,8,12,,,,,1,1,
18-
`Spring <https://spring.io/>`_,``org.springframework.*``,29,,14,,,,,14,,
19-
Others,"``com.esotericsoftware.kryo.io``, ``com.esotericsoftware.kryo5.io``, ``com.fasterxml.jackson.databind``, ``com.unboundid.ldap.sdk``, ``org.apache.commons.codec``, ``org.apache.commons.jexl2``, ``org.apache.commons.jexl3``, ``org.apache.directory.ldap.client.api``, ``org.dom4j``, ``org.xml.sax``, ``org.xmlpull.v1``, ``play.mvc``",7,8,68,,,,,18,,
20-
Totals,,84,1233,121,13,6,6,,33,1,2
15+
`Apache HttpComponents <https://hc.apache.org/>`_,"``org.apache.hc.core5.*``, ``org.apache.http``",5,136,28,,,3,,,,25
16+
`Google Guava <https://guava.dev/>`_,``com.google.common.*``,,158,6,,6,,,,,
17+
Java Standard Library,``java.*``,3,327,17,13,,,,,,4
18+
Java extensions,``javax.*``,22,151,15,,,,,1,1,1
19+
`Spring <https://spring.io/>`_,``org.springframework.*``,29,,41,,,,,14,,27
20+
Others,"``com.esotericsoftware.kryo.io``, ``com.esotericsoftware.kryo5.io``, ``com.fasterxml.jackson.databind``, ``com.unboundid.ldap.sdk``, ``jakarta.ws.rs.client``, ``jakarta.ws.rs.core``, ``org.apache.commons.codec``, ``org.apache.commons.jexl2``, ``org.apache.commons.jexl3``, ``org.apache.directory.ldap.client.api``, ``org.dom4j``, ``org.xml.sax``, ``org.xmlpull.v1``, ``play.mvc``",7,151,71,,,,,18,,1
21+
Totals,,84,1835,181,13,6,6,,33,1,58
2122

0 commit comments

Comments
 (0)