Hello,
I am writing this message to get feedback from the community on findings by static analyzers in Critical Path Packages that have changed in Fedora 45.
TLDR: This report[1] contains a total of 83009 findings and 3997 new findings identified since Fedora 44. An AI analysis has identified 28 important and 34 moderate impact findings that may have a security impact. The reports containing these findings are highlighted in red. Please review the report and provide feedback.
A mass scan was performed on the packages that have changed in Fedora 45. This report[1] contains all the findings that have been identified in the Critical Path Packages. Newly added findings since Fedora 44 are listed under ‘+’ column. Not all findings reported by OpenScanHub may be actual bugs, so please verify reported findings before investing time into fixing or reporting them.
We have performed an AI analysis through Opus 4.6 (1M context) on GCC reports for findings that may have a security impact. AI analysis has identified a total of 28 important, 34 moderate and 2757 low impact findings. These should be prioritized while reviewing the findings (and fixing them upstream). Each analysis contains a patch that fixes the issue.
False positives can be recorded in the known-false-positives[5] repository. These findings are automatically suppressed by OpenScanHub in scans that are triggered later. Also, you can filter findings with the csgrep utility to make it easier to review reports that may contain a large amount of false positives. Examples of csgrep invocation are available on the Fedora wiki[4].
We hope this is helpful for the packages you maintain and for the upstream projects. Questions can be asked on the OpenScanHub mailing list[2]. If you want to see the raw scan results, they are available on the tasks[3] page. User documentation for performing a scan is available on the Fedora wiki[4].
I would like to thank contributors who have made fixes based on these reports in the past:
Alan Coopersmith - xorg-x11-server-Xwayland
Ales Matej - libdnf
Andrew G. Morgan - libcap
Arjun Shankar - glibc
Benjamin Marzinski - device-mapper-multipath
Chet Ramey - bash, readline
David Malcolm - gcc
Debarshi Ray - flatpak
Dirk Farin - libheif
Frantisek Sumsal - polkit
Jeremy Cline - pkcs11-provider
Lasse Collin - xz
Mikel Olasagasti Uranga - nss-mdns
Panu Matilainen - rpm
Paolo Bonzini - qemu
Petr Pisar - libmodulemd
Steve Grubb - OpenSSL
Also, I would like to thank people who spent time on reviewing the previous reports but did not make any fixes due to false positives. If you are making fixes based on these reports, please contact me off list so that I can give you due credits in the future.
Please keep the feedback on this thread constructive. Thank you!
[1] Making sure you're not a bot!
[2] Making sure you're not a bot!
[3] All tasks