-
Notifications
You must be signed in to change notification settings - Fork 135
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Ban java deserialization #2152
Ban java deserialization #2152
Conversation
Generate changelog in
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
👍
.named("deserialize"); | ||
|
||
private static final Matcher<ExpressionTree> DESERIALIZE = | ||
Matchers.anyOf(OBJECT_INPUT_READ_OBJECT, LANG3_SERIALIZATION_UTILS_DESERIALIZE); |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
should we also ban ObjectOutput#writeObject
and the SerializationUtils#serialize
permutations as well under the assumptions that if someone is writing the bytes, someone somewhere will read them
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Perhaps, but I'd like to make sure this doesn't cause issues with spark code that we expect to use java serialization before expanding the breadth of the check.
Released 4.86.0 |
###### _excavator_ is a bot for automating changes across repositories. Changes produced by the roomba/latest-baseline-oss check. # Release Notes ## 4.85.0 | Type | Description | Link | | ---- | ----------- | ---- | | Improvement | Throwable.getMessage is unsafe by default | palantir/gradle-baseline#2151 | ## 4.86.0 | Type | Description | Link | | ---- | ----------- | ---- | | Improvement | Ban java deserialization | palantir/gradle-baseline#2152 | ## 4.87.0 | Type | Description | Link | | ---- | ----------- | ---- | | Improvement | Array assignment merges safety rather than replacing it | palantir/gradle-baseline#2154 | To enable or disable this check, please contact the maintainers of Excavator.
https://cwe.mitre.org/data/definitions/502.html
==COMMIT_MSG==
Ban java deserialization
==COMMIT_MSG==