遵循以下最佳实践的项目将能够自愿的自我认证,并显示他们已经实现了核心基础设施计划(OpenSSF)徽章。 显示详细资料
[](https://www.bestpractices.dev/projects/3224)
<a href="https://www.bestpractices.dev/projects/3224"><img src="https://www.bestpractices.dev/projects/3224/badge"></a>
The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)
https://github.com/find-sec-bugs/find-sec-bugs/wiki#wrench-developers-corner
https://github.com/find-sec-bugs/find-sec-bugs/issues
We are validating typo in configuration for mistyped class name https://github.com/find-sec-bugs/find-sec-bugs/blob/2340b90bc3993a595011e1cce20982533799cc0d/findsecbugs-plugin/src/test/java/com/h3xstream/findsecbugs/injection/SinkFilesValidationTest.java
We are validating for missing LGPL header during the Maven verify phase. https://github.com/find-sec-bugs/find-sec-bugs/blob/master/pom.xml#L38
We run SpotBugs manually in an IDE at the moment. The attack surface of a code analyzer is limited.
Mainly coded in Java
后退