4 ms·
The essence is: https://github.com/google/log4jscanner/blob/main/jar/jar.go https://github.com/google/log4jscanner/blob/main/jar/jar.go this is the decision lo
by hvasilev 5y ago
The essence is: https://github.com/google/log4jscanner/blob/main/jar/jar.go https://github.com/google/log4jscanner/blob/main/jar/jar.go
this is the decision logic:
func (c *checker) bad() bool {
return (c.hasLookupClass && c.hasOldJndiManagerConstructor) || (c.hasLookupClass && c.seenJndiManagerClass && !c.isAtLeastTwoDotSixteen)
}
- throwaway4good 5y agoIt is a lot of code for just that.
- stingraycharles 5y agoI’d argue that the convenience of this tool isn’t just the fact that it can tell a class/jar is “bad”, but the convenience of being able to automatically scan the filesystem to do that. And most of the code I see is about walking the filesystem, unzipping jars, walking the files inside the jars. Most codebases have this kind of plumbing all the time.
- hvasilev 5y agothe story of browsing through code: "I'm wasting my time reading this", until you read the 3 lines that actually matter.