feat(cpp): add CppCheck and CppSymbol engine types#402
Open
Divyateja2709 wants to merge 7 commits into
Open
Conversation
Signed-off-by: Divyateja Indrakanti <[email protected]>
Signed-off-by: Divyateja Indrakanti <[email protected]>
Signed-off-by: Divyateja Indrakanti <[email protected]>
Signed-off-by: Divyateja Indrakanti <[email protected]>
Signed-off-by: Divyateja Indrakanti <[email protected]>
Signed-off-by: Divyateja Indrakanti <[email protected]>
Signed-off-by: Divyateja Indrakanti <[email protected]>
Contributor
|
Hi @Divyateja2709, Thank you for your PR and for the time and effort you put into contributing to CBOMkit—we truly appreciate your interest. You may have noticed that we are already working on adding C/C++ support to sonar-cryptography in PR #377. This approach differs from yours, as it relies on Sonar’s native C/C++ support package rather than ANTLR, similar to how the existing Java module is implemented. Work on PR #377 is already quite advanced, and at this stage we are leaning toward this approach because we expect it to provide stronger support for cross-file symbol tracing through the Sonar infrastructure. That said, we will keep your PR open for now until a final decision is made. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
hi @n1ckl0sk0rtge
This PR adds the first C/C++ language-specific engine types required for upcoming C/C++ support in the Sonar Cryptography Plugin.
Changes Included
CppCheck.javaas the marker interface for C/C++ detection rulesCppSymbol.javaas a lightweight symbol representation for C/C++ source identifiersPurpose
The detection engine uses language-specific generic types for each supported language. These classes prepare the C/C++ support layer by introducing:
CppCheckfor the rule/check generic typeCppSymbolfor the symbol generic typeBecause the planned C/C++ support is parser-based and does not yet include a full semantic model,
CppSymbolintentionally keeps symbol handling lightweight.This prepares future work on: