Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Rules Coverage of Horusec #1125

Open
MarkLee131 opened this issue Dec 16, 2022 · 0 comments
Open

Rules Coverage of Horusec #1125

MarkLee131 opened this issue Dec 16, 2022 · 0 comments

Comments

@MarkLee131
Copy link

What would you like to be added:
Hi, I am performing an evaluation study on Java SAST tools, and I noticed that Horusec is better than other tools like Spotbugs(with FindSecurityBugs) when running on our dataset.

  • However, we found that Horusec cannot support to scan vulnerabilities related to CWE-682 and CWE-697. which is an interesting point to us. So, we want to inquire developers that why these types are not supported? We infer that it is because that these types are overlapping with other CWE classes, but we are not sure.

  • Another concern is that we found that the time performance of Horusec is better than Semgrep although Semgrep is one of the tools integrated within it. Is there any optimization technology related architecture?

We will appreciate it if you could kindly explain this point of view.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant