mirror of
https://github.com/elicpeter/nyx.git
synced 2026-07-18 21:21:03 +02:00
Feat/configurable sanitizers and js precision (#32)
* chore: Exclude CLAUDE.md from Cargo.toml * feat: Add configurable analysis rules and CLI commands for custom sanitizers and terminators * feat: Enhance resource management and analysis efficiency - Implemented parallel summary merging in `scan_filesystem` using rayon for improved performance. - Introduced `GlobalSummaries::merge()` for efficient merging of summaries. - Optimized file reading and hashing to eliminate redundant I/O operations. - Added `should_scan_with_hash()` and `upsert_file_with_hash()` methods to streamline file processing. - Enhanced taint analysis with in-place mutations to reduce memory allocations. - Updated resource acquisition patterns to exclude false positives for `freopen` and wrapper functions. * feat: Implement severity downgrade for findings in non-production paths and add source kind inference * feat: Update versioning information in SECURITY.md for new stable line * feat: Update categories in Cargo.toml to include parser-implementations and text-processing * feat: Update dependencies in Cargo.lock for improved compatibility and performance * feat: Update dependencies in Cargo.lock and Cargo.toml for improved compatibility
This commit is contained in:
parent
f96a89e7c1
commit
19b578c5c4
37 changed files with 3775 additions and 432 deletions
|
|
@ -108,3 +108,29 @@ scan_timeout_secs = null
|
|||
|
||||
## Maximum memory to use in MiB; 0 = no limit (UNIMPLEMENTED)
|
||||
memory_limit_mb = 512
|
||||
|
||||
|
||||
# ─── Per-language analysis rules ─────────────────────────────────────
|
||||
# Add custom sources, sanitizers, sinks, terminators, and event handlers.
|
||||
# Each language is keyed under [analysis.languages.<slug>] where slug is
|
||||
# one of: rust, javascript, typescript, python, go, java, c, cpp, php, ruby.
|
||||
#
|
||||
# Example: recognise `escapeHtml` as an HTML sanitizer in JavaScript:
|
||||
#
|
||||
# [analysis.languages.javascript]
|
||||
# event_handlers = ["addEventListener"]
|
||||
# terminators = ["process.exit"]
|
||||
#
|
||||
# [[analysis.languages.javascript.rules]]
|
||||
# matchers = ["escapeHtml"]
|
||||
# kind = "sanitizer"
|
||||
# cap = "html_escape"
|
||||
#
|
||||
# [[analysis.languages.javascript.rules]]
|
||||
# matchers = ["location.href", "window.location.href"]
|
||||
# kind = "sink"
|
||||
# cap = "url_encode"
|
||||
#
|
||||
# Valid `kind` values: "source", "sanitizer", "sink"
|
||||
# Valid `cap` values: "env_var", "html_escape", "shell_escape",
|
||||
# "url_encode", "json_parse", "file_io", "all"
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue