
Product Announcements — Mike M (Veracode TPM) (Community Member) asked a question.
This week's December Static Analysis Release includes the following:
- Added .NET 8 initial support
- Added JavaScript ECMAScript 2023 (ES14) support
- Added Config support for AWS SDK for Go
- Enhanced Android 13 support
- Enhanced Node.js v20 support
- Added Dart 3.2 and Flutter 3.16 support
- Improved CWE-327 (Use of Broken or Risky Cryptographic Algorithm) and CWE-352 (Cross-Site Request Forgery (CSRF)) detection for Ruby on Rails
- Improved CWE-366 (Authorization Bypass Through User-Controlled SQL Primary Key) detection for .NET applications
- Improved CWE-352 (Unchecked Return Value), CWE-915 (Improperly Controlled Modification of Dynamically-Determined Object Attributes) for .NET
- Improved CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')) detection for Python resulting in a reduction in FPs
- Improved CWE-926 (Improper Export of Android Application Components) detection for Android applications
- Improved CWE-321 (Use of Hard-coded Cryptographic Key) detection for all languages
- Improved CWE-331 (Insufficient Entropy) detection for Java
- Improved CWE-601 (URL Redirection to Untrusted Site ('Open Redirect')) detection for PHP
- Improved parsing for PL/SQL
- Added Python jsonify cleanser support for flaw class CWE-80 (Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS))
.png)