Documentation
¶
Overview ¶
Package regexpdynamicpattern implements a Go analysis linter that flags calls to regexp.MustCompile() and regexp.Compile() whose pattern argument is not a compile-time constant string. Dynamically constructed patterns can panic at runtime on malformed input and, when influenced by untrusted input, can enable catastrophic-backtracking (ReDoS) denial-of-service attacks.
Index ¶
Constants ¶
This section is empty.
Variables ¶
View Source
var Analyzer = analyzerutil.New("regexpdynamicpattern", "reports regexp.MustCompile and regexp.Compile calls whose pattern is not a compile-time constant string", run)
Analyzer is the regexp-dynamic-pattern analysis pass.
Functions ¶
This section is empty.
Types ¶
This section is empty.
Click to show internal directories.
Click to hide internal directories.