-
Notifications
You must be signed in to change notification settings - Fork 231
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Rule S4529: Exposing HTTP endpoints is security-sensitive #1991
Comments
@valhristov We are seeing this pop up in SonarCloud, but not in Visual Studio, any idea why that is? |
@PeterRockstars The hotspot rules are not displayed in SonarLint because they are a special kind of rules that might generate more FPs and so lower having a good experience inside the IDE. |
That makes sense, thanks. Our build server is logging those errors during the build however, and if I run the same dotnet build command on my machine, the warnings are not logged. Is that because of something the "Prepare Sonar Analysis" step does? |
Any Update on this issue. @PeterRockstars ? |
FYI the hotspot rules are only executed when an analysis is being run and the results pushed to SonarQube/Cloud. @vishnu2017 if you have an issue/question about using the scanner, please start a thread on the community forum. |
RSPEC-4529
Exposing HTTP endpoints is security-sensitive. It has led in the past to the following vulnerabilities:
The text was updated successfully, but these errors were encountered: