Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Commit 508b09f

Browse files
committed
C#: Address review comments
1 parent fd63246 commit 508b09f

3 files changed

Lines changed: 4 additions & 4 deletions

File tree

change-notes/1.23/analysis-csharp.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,9 +9,9 @@ The following changes in version 1.23 affect C# analysis in all applications.
99
| **Query** | **Tags** | **Purpose** |
1010
|-----------------------------|-----------|--------------------------------------------------------------------|
1111
| Deserialized delegate (`cs/deserialized-delegate`) | security, external/cwe/cwe-502 | Finds unsafe deserialization of delegate types. |
12-
| Deserialization of untrusted data (`cs/unsafe-deserialization-untrusted-input`) | security | Finds flow of untrusted input to calls to unsafe deserializers. |
12+
| Deserialization of untrusted data (`cs/unsafe-deserialization-untrusted-input`) | security, external/cwe/cwe-502 | Finds flow of untrusted input to calls to unsafe deserializers. |
1313
| Unsafe year argument for 'DateTime' constructor (`cs/unsafe-year-construction`) | reliability, date-time | Finds incorrect manipulation of `DateTime` values, which could lead to invalid dates. |
14-
| Unsafe deserializer (`cs/unsafe-deserialization`) | security | Finds calls to unsafe deserializers. |
14+
| Unsafe deserializer (`cs/unsafe-deserialization`) | security, external/cwe/cwe-502 | Finds calls to unsafe deserializers. |
1515
| Mishandling the Japanese era start date (`cs/mishandling-japanese-era`) | reliability, date-time | Finds hard-coded Japanese era start dates that could be invalid. |
1616

1717
## Changes to existing queries

csharp/ql/src/Security Features/CWE-502/UnsafeDeserialization.qhelp

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@
55
<overview>
66

77
<p>Deserializing an object from untrusted input may result in security problems, such
8-
as denial-of-service or remote code execution.</p>
8+
as denial of service or remote code execution.</p>
99

1010
</overview>
1111
<recommendation>

csharp/ql/src/Security Features/CWE-502/UnsafeDeserializationUntrustedInput.qhelp

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@
55
<overview>
66

77
<p>Deserializing an object from untrusted input may result in security problems, such
8-
as denial-of-service or remote code execution.</p>
8+
as denial of service or remote code execution.</p>
99

1010
</overview>
1111
<recommendation>

0 commit comments

Comments
 (0)