Skip to content

fix: Reduce Malcontent JS False Positives#904

Merged
antitree merged 5 commits into
chainguard-dev:mainfrom
antitree:main
May 8, 2025
Merged

fix: Reduce Malcontent JS False Positives#904
antitree merged 5 commits into
chainguard-dev:mainfrom
antitree:main

Conversation

@antitree
Copy link
Copy Markdown
Contributor

@antitree antitree commented May 7, 2025

This fix adjusts the severity on some of the obfuscation rules and one of the rules for javascript reversing that was producing a high number of false positives. I think we can roll this change back after we've tuned these rules to producer higher quality results.

antitree and others added 2 commits May 7, 2025 14:36
fix(js): Reducing severity of javascript issues to reduce false positive blockers
Copy link
Copy Markdown
Contributor

@eslerm eslerm left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you for jumping on this!

@antitree antitree enabled auto-merge (squash) May 7, 2025 19:58
antitree and others added 2 commits May 7, 2025 16:13
Copy link
Copy Markdown
Contributor

@eslerm eslerm left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

cheers for test fix

@antitree antitree disabled auto-merge May 8, 2025 12:55
@antitree antitree merged commit e2a9022 into chainguard-dev:main May 8, 2025
11 of 12 checks passed
antitree added a commit to antitree/malcontent that referenced this pull request May 8, 2025
fix: Reduce Malcontent JS False Positives (chainguard-dev#904)
antitree added a commit to antitree/malcontent that referenced this pull request May 8, 2025
antitree added a commit to antitree/malcontent that referenced this pull request May 8, 2025
Revert "fix: Reduce Malcontent JS False Positives (chainguard-dev#904)"
antitree added a commit to antitree/malcontent that referenced this pull request May 8, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants