https://github.com/ros/rosdistro ·
lang: python ·
LOC: ·
source: user_submitted
| Rule | Severity | Count |
|---|---|---|
SEC004 SQL Injection Risk |
high | 1 |
SEC005 Command Injection Risk |
high | 1 |
SEC004
SQL Injection Risk
migration-tools/migrate-rosdistro.py:33
· conf 0.85
[SEC004] SQL Injection Risk: String interpolation in SQL execution. Allows SQL injection.
SEC005
Command Injection Risk
scripts/count_rosdistro_packages.py:72
· conf 0.30
[SEC005] Command Injection Risk: Unsafe shell execution or eval of user input.
Reading from rp.scan + rp.finding + rp.rule (unified schema, R78 series). Legacy data path unchanged. Compare with /scan/426fecd2-3115-406b-a69e-ea1e3bfadd3e/.