📣 Static Analysis Product Updates - Upcoming changes for the February Release

This week's February Static Analysis Release includes the following:

 

Updated language and framework support

 

C/C++

  • Improved flaw detection for exported functions

iOS

  • Improved overall detection for taint based flaws

JavaScript

  • Enhanced Angular 18 support

PL/SQL

  • Improved flaw detection for out-of-scope code, resulting in a reduction in false positives
  • Enhanced flaw detection for new variable declarations initialized with a taint source. As a result, this improvement may lead to an increase in the number of reported flaws.
  • Improved SQL injection detection

Ruby on Rails

  • Rails 3.4 and Rails 8 support

Other languages

  • Improved CWE-259 and 798 flaw detection, resulting in a reduction in false positives for all languages
  • Improved flaw description and remediation details for CWE-284 and CWE-115
  • Updated CWE Top 25 to 2024 version. All policies having Auto-Update CWE Top 25 as Requirement are impacted by this change

 

 

 


Topics (8)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.