Skip to content

2025/06/02 false positive reduction#976

Merged
egibs merged 2 commits into
chainguard-dev:mainfrom
egibs:20250602-fpr
Jun 2, 2025
Merged

2025/06/02 false positive reduction#976
egibs merged 2 commits into
chainguard-dev:mainfrom
egibs:20250602-fpr

Conversation

@egibs
Copy link
Copy Markdown
Member

@egibs egibs commented Jun 2, 2025

This PR addresses most of the outstanding false positives we've seen recently. The plan is to merge this and run another audit. Any outstanding findings can be picked up in a subsequent PR.

@egibs egibs requested review from antitree and eslerm June 2, 2025 14:17
Signed-off-by: egibs <20933572+egibs@users.noreply.github.com>
Copy link
Copy Markdown
Contributor

@antitree antitree left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we can approve this in the short term but I'm interested in your response to the comments. If the goala are 1) protect the product 2) do not block a team on a false positive we're doing a good job at 1 but what's our assessment of 2?

Comment thread rules/anti-static/obfuscation/bitwise.yara Outdated
Comment thread tests/npm/2024.testerrrrrrrrrr/init.js.simple
Signed-off-by: egibs <20933572+egibs@users.noreply.github.com>
@egibs egibs requested a review from antitree June 2, 2025 15:30
@egibs egibs merged commit 17f889c into chainguard-dev:main Jun 2, 2025
12 checks passed
@egibs egibs deleted the 20250602-fpr branch June 25, 2025 13:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants