Revisions of flawfinder

Michael Vetter's avatar Michael Vetter (jubalh) committed (revision 16)
Michael Vetter's avatar Michael Vetter (jubalh) committed (revision 15)
- Update to 2.0.19:
  * entrypoint.sh: Don't require output filename to be escaped
  * entrypoint.sh: Make minor improvements (#54)
  * print warning messages to stderr (#58)
  * changes to github actions
Michael Vetter's avatar Michael Vetter (jubalh) committed (revision 14)
- Update to 2.0.18:
  * Fix Sarif output relationship target id format.
buildservice-autocommit accepted request 898180 from Michael Vetter's avatar Michael Vetter (jubalh) (revision 13)
baserev update by copy to link target
Michael Vetter's avatar Michael Vetter (jubalh) committed (revision 12)
- Update to 2.0.17:
  * Fix the distributed tarball, which didn't include the
    key source file due to the earlier file restructure.
  * Minor code style fix, which simplifies the code slightly.
  * Update date in manual page to 2021. That's important because
    the documentation now includes information on `--sarif`.
buildservice-autocommit accepted request 896596 from Michael Vetter's avatar Michael Vetter (jubalh) (revision 11)
baserev update by copy to link target
Michael Vetter's avatar Michael Vetter (jubalh) committed (revision 10)
- Update to 2.0.16:
  * The distributed source file is now flawfinder.py, not flawfinder.
    This is part of a change that improves
    improve cross-platform ease-of-use by using entry_points.
    That said, "make install" will still
    install it as "flawfinder" (so those who install it via
    "make install" will see no change).
  * Added support for generating SARIF output, use --sarif.
  * Track curly brace level to reduce some problems, my thanks to
  * Improved handling of Git patch format
buildservice-autocommit accepted request 862538 from Michael Vetter's avatar Michael Vetter (jubalh) (revision 9)
baserev update by copy to link target
Michael Vetter's avatar Michael Vetter (jubalh) committed (revision 8)
- Update to 2.0.15:
  * Fixed some release problems in 2.0.14. (#30)
  * Improved handling of LoadLibraryEx; flawfinderr no longer complains
    about certain constructs that are known to be safe (eliminating
    some false positives).

- Update to 2.0.14:
  * If there are >0 hits, tell users how to ignore them as part of the
    tool output.
  * Various Windows improvments.
    Ignore LoadLibraryEx if its third parameter is
    LOAD_LIBRARY_SEARCH_SYSTEM32, as this is safe, and
    remove the rule for InitialCriticalSection
    (this is no longer a vulnerability on current widely-used versions
    of Windows)
  * Various C++ improvements.  Add .hpp support for C++,
    ignore "system::" to reduce false positives,
    treat ' as digit separator when file extension is a C++ file
    (for C++14).
  * I had some release problems; this is identified as 2.0.14
    (skipping a few minor numbers) to ensure that the version
    number uniquely identifies a specific release.
buildservice-autocommit accepted request 775114 from Michael Vetter's avatar Michael Vetter (jubalh) (revision 7)
baserev update by copy to link target
Michael Vetter's avatar Michael Vetter (jubalh) committed (revision 6)
- Update to 2.0.11:
  * Provide a much more detailed error report, including recommended
    solutions, when character encoding problems hit.
    As Python3 has slowly gained in popularity, its failure to provide
    useful built-ins to handle real-world character encoding problems
    hurts more people. (E.g., many files don't comply with *any*
    character set encoding standard, and Python3 can't read them
    without enabling options that are wrong for others.)
    We can at least provide much more detailed feedback to help
    explain the various options available.
Dominique Leuenberger's avatar Dominique Leuenberger (dimstar_suse) accepted request 728478 from Michael Vetter's avatar Michael Vetter (jubalh) (revision 5)
initialized devel package after accepting 728478
Michael Vetter's avatar Michael Vetter (jubalh) committed (revision 4)
- Use python3
Martin Pluskal's avatar Martin Pluskal (pluskalm) accepted request 728448 from Jan Engelhardt's avatar Jan Engelhardt (jengelh) (revision 3)
- Use noun phrase in summary. Drop metadata redundancies from
  description.
Michael Vetter's avatar Michael Vetter (jubalh) committed (revision 2)
- Update to 2.0.10:
	* Use binary mode when reading a diffhitlist.
	* Fix a serious defect in --diffhitlist option and added a
      unit test
	* Don't warn if memcpy call includes sizeof(first arg).
	* Bugfix (banned function _ftcsat should be _ftcscat).
	* Documentation tweaks. Make it clear that GitHub issues and
	  pull requests are supported, and use ~~~~ in markdown
	  to ease copy-and-paste from documentation.
Martin Pluskal's avatar Martin Pluskal (pluskalm) accepted request 666985 from Michael Vetter's avatar Michael Vetter (jubalh) (revision 1)
Please add me as maintainer too.
Displaying all 16 revisions
openSUSE Build Service is sponsored by