Skip to content
Grav 2.0 is officially stable. Read the announcement →
Support

Static code analyzer for grav and admin plugin

Started by Lahar Shah 7 years ago · 2 replies · 485 views
7 years ago

I am new to grav and currently researching its code security. Is there already something shows all vulnerabilities that the grav code has and list of false positives?

When we have used static code analyzer(fortify) it found many vulnerabilities. It is possible that many of them are false positives, most of them are in grav core! What is the best way to introduce them to contributors?

We used fortify to analyze the grav code and see any security risk.

https://www.microfocus.com/en-us/products/static-code-analysis-sast/overview

7 years ago

Grav uses PHPStan, and to my knowledge there are no new reported, public vulnerabilities at this time.

👍 1

Suggested topics

Topic Participants Replies Views Activity
Support · by Paul Hodges, 4 weeks ago
19 488 6 days ago
Support · by Lauw, 1 week ago
2 104 7 days ago
Support · by Anna, 3 weeks ago
4 427 1 week ago
Support · by gtx, 4 weeks ago
4 378 3 weeks ago
Support · by Anna, 1 month ago
9 485 4 weeks ago