aegilops :github::microsoft: · @aegilops
146 followers · 548 posts · Server fosstodon.org

I’ve released 🤲 a GitHub Action to convert Dart/Flutter analyzer output to SARIF.

That lets you upload ⬆️ the results to GitHub Advanced Security, as I show in a sample workflow.

github.com/advanced-security/d

#appsec #dart #flutter #linting #sarif #github

Last updated 1 year ago

Sebastian Bergmann :phpunit: · @sebastian
1245 followers · 428 posts · Server phpc.social

TIL: there is Static Analysis Results Interchange Format ():

developers.redhat.com/articles

Wondering what the benefits could be for if and/or supported this.

#sarif #php #Psalm #Phpstan

Last updated 1 year ago

Brad Larsen · @bradlarsen
52 followers · 58 posts · Server infosec.exchange

What tools / services do you use that import and do something interesting with SARIF static analysis results?

For example, GitHub Code Analysis understands SARIF. There is also a VSCode viewer plugin.

Context: thinking about adding SARIF output support to Nosey Parker, the secrets detector I'm working on: github.com/praetorian-inc/nose

#sarif #sast #staticanalysis

Last updated 2 years ago

check-spelling · @checkspelling
1 followers · 26 posts · Server fosstodon.org

#sarif

Last updated 2 years ago

OWASP ZAP · @zaproxy
425 followers · 4 posts · Server infosec.exchange
check-spelling · @checkspelling
1 followers · 12 posts · Server fosstodon.org
Ulrich Lintl · @ulintl
235 followers · 9138 posts · Server mstdn.io

Wobei für den Gegenangriff des wohl nicht nur die Tötung von , sondern auch die Einreiseverweigerung ihres Außenministers zur UNO nach New York entscheidend war.
zeit.de/politik/ausland/2020-0

#iran #Solemani #sarif

Last updated 5 years ago