![JAR search and dependency download from the Maven repository](/logo.png)
io.codemodder.codemods.harden-xmlinputfactory.yaml Maven / Gradle / Ivy
rules:
- id: harden-xmlinputfactory
patterns:
- pattern-either:
- pattern: $XMLF = XMLInputFactory.newInstance(...)
- pattern: $XMLF = XMLInputFactory.newFactory(...)
- pattern-not-inside: |
$RT $METHOD ($ARGS) {
...
XMLInputFactorySecurity.hardenFactory($XMLF);
...
}
- pattern-not-inside: |
$RT $METHOD ($ARGS) {
...
io.github.pixee.security.XMLInputFactorySecurity.hardenFactory(...);
...
}
- focus-metavariable: $XMLF
message: Semgrep found a match
languages:
- java
severity: WARNING
© 2015 - 2025 Weber Informatics LLC | Privacy Policy