How to exclude warnings in Fortify?

人走茶凉 提交于 2021-01-28 06:30:46

问题


There are some warnings that we don't want to fix. How to suppress or exclude them from being generated in future reports, in local and Jenkins CI?

Like in PMD or FindBugs, some warnings we can use annotations.

For example: Logging error messages in catch blocks. This is important for us to know about the operation. Checked this but does not meets our need.


回答1:


From the SCA User Guide:

You can create a file to filter out particular vulnerability instances, rules, and vulnerability categories when you run the sourceanalyzer command. You specify the file with the -filter analysis option.



来源:https://stackoverflow.com/questions/44798596/how-to-exclude-warnings-in-fortify

标签
易学教程内所有资源均来自网络或用户发布的内容,如有违反法律规定的内容欢迎反馈
该文章没有解决你所遇到的问题?点击提问,说说你的问题,让更多的人一起探讨吧!