Skip to content

Conversation

@righettod
Copy link
Contributor

@righettod righettod commented Oct 24, 2025

Hello,

This rule, for java language, is intended to detect and raise a warning when an unsanitized String method parameter is used as an argument to a logger call. The goal is to allow to detect such situation and perform a manual control that a validation is in place.

💡 To limit the false positives, I updated the rule to only trigger for methods that are exposed as a "web service". I added annotations used by Spring Web, JAX-RS and JAX-WS frameworks.

I tested the rule against the sample code using the online rule editor:

image

Thank you very much for your feedback 😉

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant