Skip to content

Commit 96048f9

Browse files
GeekMasherRasmusWL
andauthored
Update python/ql/src/Security/CWE-798/HardcodedCredentials.ql
Co-authored-by: Rasmus Wriedt Larsen <[email protected]>
1 parent ed314b1 commit 96048f9

File tree

1 file changed

+4
-1
lines changed

1 file changed

+4
-1
lines changed

python/ql/src/Security/CWE-798/HardcodedCredentials.ql

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -81,7 +81,10 @@ class HardcodedValueSource extends DataFlow::Node {
8181

8282
class CredentialSink extends DataFlow::Node {
8383
CredentialSink() {
84-
this = ModelOutput::getASinkNode("credentials-hardcoded").asSink()
84+
exists(string s | s.matches("credentials-%") |
85+
// Actual sink-type will be things like `credentials-password` or `credentials-username`
86+
this = ModelOutput::getASinkNode(s).asSink()
87+
)
8588
or
8689
exists(string name |
8790
name.regexpMatch(getACredentialRegex()) and

0 commit comments

Comments
 (0)