Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FEATURE]Can support ignoring some detected problems #2377

Open
junwei-liu opened this issue Apr 17, 2024 · 5 comments
Open

[FEATURE]Can support ignoring some detected problems #2377

junwei-liu opened this issue Apr 17, 2024 · 5 comments
Assignees
Labels
enhancement MobSF enhancements and feature requests

Comments

@junwei-liu
Copy link

I hope mobsf can support ignoring some detected problems and prevent these ignored problems from appearing in the report.

@junwei-liu junwei-liu added the enhancement MobSF enhancements and feature requests label Apr 17, 2024
Copy link

👋 @junwei-liu
Issues is only for reporting a bug/feature request. For limited support, questions, and discussions, please join MobSF Slack channel
Please include all the requested and relevant information when opening a bug report. Improper reports will be closed without any response.

@junwei-liu
Copy link
Author

Sorry, because I am in mainland China. So I can't join https://mobsf.slack.com/unsupported-geo#/.

@ajinabraham
Copy link
Member

We do have suppression feature for a lot of findings. What are you trying to suppress in particular?

@jvictors-tp
Copy link

@ajinabraham I am also trying to find documentation on suppressing findings within the static analysis of an APK or IPA app file. For example, known behaviors or permissions that I'd like to ignore so that it isn't part of the scorecard. I see that there's a section to list suppressed findings, but there's no control to add new ones. I've gone through the documentation and the DEFCON video and I haven't seen how to do this. Can this be better documented?

@ajinabraham
Copy link
Member

@junwei-liu @jvictors-tp Suppression is currently available for MANIFEST ANALYSIS, CODE ANALYSIS for Android and IPA BINARY CODE ANALYSIS, CODE_ANALYIS findings for iOS. There are columns at the end of the table that allow you to do so.
Screenshot 2024-05-20 at 9 41 52 AM

Some features like permissions does not contribute to a score and cannot be suppressed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement MobSF enhancements and feature requests
Projects
None yet
Development

No branches or pull requests

3 participants