Skip to content

Latest commit

 

History

History
4 lines (4 loc) · 348 Bytes

File metadata and controls

4 lines (4 loc) · 348 Bytes
category minorAnalysis
  • The java/tainted-arithmetic query no longer flags arithmetic expressions that are used directly as an operand of a comparison in bounds-checking patterns. For example, if (off + len > array.length) is now recognized as a bounds check rather than a potentially vulnerable computation, reducing false positives.