4 ms·
Tools like semgrep allow catching injection-like issues like that. For instance, just among existing published rules: - shell=True: https://semgrep.dev/r?q=pyt
by dbaupp 5y ago
Tools like semgrep allow catching injection-like issues like that. For instance, just among existing published rules:
- shell=True: https://semgrep.dev/r?q=python.lang.security.audit.subprocess-shell-true.subprocess-shell-true https://semgrep.dev/r?q=python.lang.security.audit.subproces...
- system-like calls with a non-static argument: https://semgrep.dev/r?q=python.lang.security.audit.dangerous-system-call.dangerous-system-call https://semgrep.dev/r?q=python.lang.security.audit.dangerous...
Custom rules can be written for additional patterns of concern (or specific/uncommon/private APIs) too.