Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

static secure coding #2118

Closed
jhjo-jhjo opened this issue Nov 18, 2024 · 3 comments
Closed

static secure coding #2118

jhjo-jhjo opened this issue Nov 18, 2024 · 3 comments

Comments

@jhjo-jhjo
Copy link

yara is wonderful library.
I am using version 4.2.3, but yara library is not complied with secure coding.
what version is satisfied with secure coding?

@plusvic
Copy link
Member

plusvic commented Nov 18, 2024

What do you mean exactly with secure coding?

@jhjo-jhjo
Copy link
Author

as I know, secure coding can be tested in static and runtime analysis.
for example, codesonar or Coverity Static Analysis !

@plusvic
Copy link
Member

plusvic commented Nov 19, 2024

I still don't know what do mean exactly. I use Coverity for finding issues (https://github.com/VirusTotal/yara/blob/master/.github/workflows/coverity.yml) and also use oss-fuzz.

@plusvic plusvic closed this as completed Nov 28, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants