fix(unix): exclude pg command from pl-1#4613
Conversation
|
📊 Quantitative test results for language: |
|
do'nt confuse |
|
@HackingRepo I'm not sure what your trying to say? I'm removing |
|
I see relunsec@relunsec:~$ pg
pg: command not found
relunsec@relunsec:~$ So just we can move the command to PL3 better not just PL2 |
|
it even completly removed https://askubuntu.com/questions/1065434/usr-bin-pg-no-longer-present-in-18-04-util-linux-package, so that need to be on PL3 and PL4 only detected |
That's what I said in my PR description.
There's no stricter sibling rule at PL-3, and I don't see a reason to even make a PL-3 rule. |
|
No, at PL2 that still can cause FPs @EsadCetiner, it must be also excluded at PL1 and PL2 both not just PL1 |
|
simply add also it to |
Ok, and? do you have anything to prove this is a big enough problem at PL-2? As far as I can tell this specific false positive doesn't look too common, and considering the fact
As I mentioned before, there is no stricter sibling rule at PL-3 which can detect |
9e3ebe4 to
a1a77e6
Compare
|
I'll say let's first merge this one, and if @HackingRepo wants to run some tests to see the value of moving to major PLs we can reconsider. |
Proposed changes
The
pgcommand isn't installed by default on most Linux distros and is typically not installed afterwards by sysadmins. Fixes a false positive reported in CRS dev chat with thepgcommand.PR Checklist
commentfield to write the expected behaviorFurther comments
For the reviewer
ctl:requestBodyAccess=Offwere used in the rule