Aug 06, 2019
03:34 PM
1 Kudo
This is a terrible solution. Attached is my proposal for how CodeInsight should support versions.
... View more
Jul 15, 2019
08:49 PM
Your comments did not address the issue. Below are some examples to further explain the problem. Exact Matches Example: Scan detected icon file "Magic_Wand.png" in source code and provides potential matches to 58 open source projects. None of these open source projects were the author of the file which was located at https://www.iconfinder.com/icons/58574/magic_wand_icon along with details on author and license. Since all 58 project contain the exact file, it would be good to establish timeline to know who created the file first to help narrow search. In this specific example, they likely all copied off internet. It would be good enhancement for CodeInsight to index the publicly available image & icons from https://www.iconfinder.com & http://www.softicons.com Partial Match Example: Scan detected partial code match against >1000 open source projects which all had 95% code match. When there is such as large number of potential matches, it would be good to establish timeline to know who created the file first to help narrow search. We eventually located the author website https://www.wpftutorial.net/PasswordBox.html by searching Google using code snippet of the first couple of lines.
... View more
Jul 15, 2019
12:02 PM
1 Kudo
We actually use all three depending on our situation. For example, if we have multiple people reviewing the same scan, the person who is responsible for following up on text and license matches to "gpl" will often create an unpublished group called "not gpl" so that if other people working on the scan are reviewing other indicators they can see that someone has already identified the gpl match is a false positive. If I am just working on a scan by myself, once I have reviewed all the indicators associated with a file I will mark it as reviewed.
If you find a search term is creating "too many" false positive you can try to fine tune the text strings that are in the scan settings based on the results you are seeing.
If the false positive is in in-house proprietary code, it might be helpful to create a group called in-house code to mark files that have false positive indicators. Especially, if you are familiar with the code and know that it was authored by your developers. It can be a quicker way to remove false positives.
Ultimately, practice seems to be the best medicine for quickly identifying false positives and quickly marking them.
... View more
Jul 15, 2019
11:31 AM
Thanks for the suggestion. I'll pass it along to our product team!!
Cheers,
Dave McLoughlin
... View more
Jul 01, 2019
04:57 AM
1 Kudo
Hi Thanks for that. Email has been sent as you suggest. Awaiting for the response. Thanks again. Thanks, G Harihara Sudhan +91-9972390371
... View more
Jun 10, 2019
07:31 PM
Thanks @dmcloughlin for pointing this out. I opened a ticket to correct this.
... View more
Jun 05, 2019
12:02 PM
1 Kudo
This was an issue when we first went live, but should have been fixed. Are you still seeing the problem?
... View more
Latest posts by dmcloughlin
Subject | Views | Posted |
---|---|---|
1363 | Jul 15, 2019 12:18 PM | |
1078 | Jul 15, 2019 12:02 PM | |
6254 | Jul 15, 2019 11:46 AM | |
1278 | Jul 15, 2019 11:31 AM | |
1715 | Jun 10, 2019 12:54 PM | |
1827 | Jun 10, 2019 12:46 PM | |
1000 | Jun 05, 2019 12:02 PM | |
1860 | Jun 05, 2019 11:50 AM |
Activity Feed
- Got a Kudo for Re: False Positive Best Practice. Jul 19, 2019 08:10 AM
- Kudoed Partial and exact matches results in a lot of wasted time chasing false positives for sewechad. Jul 15, 2019 12:26 PM
- Posted Re: Partial and exact matches results in a lot of wasted time chasing false positives on Code Insight Forum. Jul 15, 2019 12:18 PM
- Kudoed Case Section for TarunKumarSingh. Jul 15, 2019 12:03 PM
- Posted Re: False Positive Best Practice on Code Insight Forum. Jul 15, 2019 12:02 PM
- Kudoed False Positive Best Practice for sewechad. Jul 15, 2019 11:49 AM
- Posted Re: Version Scanning Best Practices on Code Insight Forum. Jul 15, 2019 11:46 AM
- Kudoed Re: Case Section for TarunKumarSingh. Jul 15, 2019 11:37 AM
- Posted Re: Scanning Docker Files on Code Insight Forum. Jul 15, 2019 11:31 AM
- Kudoed Scanning Docker Files for sewechad. Jul 15, 2019 11:31 AM
- Kudoed FlexNet Code Insight 2019 R2 is available! for cvirata. Jul 15, 2019 11:29 AM
- Posted Re: Open New Case: Missing version numbers for FNCI 2019.R1 and FNCI 6.13.0 on Code Insight Forum. Jun 10, 2019 12:54 PM
- Kudoed SCA User Group Meeting - May 23, 2019 in San Francisco for kemorton. Jun 10, 2019 12:50 PM
- Posted Re: Case Section on Code Insight Forum. Jun 10, 2019 12:46 PM
- Got a Kudo for Re: No longer receiving confirmation email after opening new cases. Jun 05, 2019 04:24 PM
- Posted Re: No longer receiving confirmation email after opening new cases on Code Insight Forum. Jun 05, 2019 12:02 PM
- Posted Re: Case Section on Code Insight Forum. Jun 05, 2019 11:50 AM