Commit 491b2e3
committed
fix: add NOSONAR markers for RSA signature false positives
SonarCloud rule S5542 incorrectly flags rsa.SignPKCS1v15 as insecure
encryption when it's actually a signature scheme (not encryption).
RSA-PKCS1v15 signatures are standard and secure, used in JWT RS256/384/512.
- Added NOSONAR inline comments to both SignDigest implementations
- Added file-level exclusions in sonar-project.properties for PKI signers1 parent 4417a63 commit 491b2e3
File tree
3 files changed
+11
-3
lines changed- pkg/pki
3 files changed
+11
-3
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
73 | 73 | | |
74 | 74 | | |
75 | 75 | | |
76 | | - | |
| 76 | + | |
77 | 77 | | |
78 | 78 | | |
79 | 79 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
79 | 79 | | |
80 | 80 | | |
81 | 81 | | |
82 | | - | |
| 82 | + | |
83 | 83 | | |
84 | 84 | | |
85 | 85 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
29 | 29 | | |
30 | 30 | | |
31 | 31 | | |
32 | | - | |
| 32 | + | |
33 | 33 | | |
34 | 34 | | |
35 | 35 | | |
| |||
38 | 38 | | |
39 | 39 | | |
40 | 40 | | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
0 commit comments