Skip to content

Conversation

@AkhtarAmir
Copy link
Contributor

No description provided.

@AkhtarAmir
Copy link
Contributor Author

Added input validation for suppression expressions to prevent potential ReDoS vulnerabilities. The validation ensures suppression patterns are properly formatted and restricts malicious regex patterns while maintaining existing functionality

@alphadev4 alphadev4 merged commit 09e7fa3 into aquasecurity:master Feb 6, 2025
2 checks passed
@jdgregson
Copy link

Hi @AkhtarAmir and @tzurielweisberg. This change removed the ability to use wildcards in suppression rules, which is a significant loss of functionality. Removed here: bfe40f9. Was this intentional?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants