Skip to content
Grav 2.0 is officially stable. Read the announcement →
Support

Static code analyzer for grav and admin plugin

Started by Lahar Shah 7 years ago · 2 replies · 373 views
7 years ago

I am new to grav and currently researching its code security. Is there already something shows all vulnerabilities that the grav code has and list of false positives?

When we have used static code analyzer(fortify) it found many vulnerabilities. It is possible that many of them are false positives, most of them are in grav core! What is the best way to introduce them to contributors?

We used fortify to analyze the grav code and see any security risk.

https://www.microfocus.com/en-us/products/static-code-analysis-sast/overview

7 years ago

Grav uses PHPStan, and to my knowledge there are no new reported, public vulnerabilities at this time.

👍 1

Suggested topics

Topic Participants Replies Views Activity
Support · by Duc , 6 minutes ago
0 5 6 minutes ago
Support · by Thomas, 1 week ago
3 101 9 hours ago
Support · by Anna, 3 days ago
2 99 1 day ago
Support · by Justin Young, 1 day ago
1 66 1 day ago
Support · by Duc , 1 week ago
2 101 6 days ago