gabrielbbaldez/Spring Taint Analysis

Interprocedural taint analysis for Spring Boot. Finds multi-layer data-flow vulnerabilities SonarQube cannot reach.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
pathCompiled classes directory or JAR to scan (relative to the workspace). Build your project first.yes
libsDependency classpath needed to resolve the target (path-separator-joined), e.g. from `mvn dependency:build-classpath`.no""
configCustom taint configuration file. Defaults to the bundled Spring config.no""
outputSARIF 2.1 output file.nospring-taint.sarif
severityOnly report these severities (comma-separated: critical,high,medium,low).no""

no outputs