This repository hosts a set of files that should be identified by static code analysis engines.
Each case lives at <LANGUAGE>/<CWE-ID>/<N>/ and pairs a bad file (which a
scanner should flag) with a good file (the same program with the flaw fixed,
which it should not flag).
Languages covered: C, C++, C#, and Rust. The Rust cases target the weaknesses the compiler and borrow checker do not catch, and each declares the Rust editions it applies to; see CONTRIBUTING.md.
- INDEX.md — coverage matrix of languages and CWEs.
- CONTRIBUTING.md — case layout, conventions, and how to add one.
- Jon Hood - Initial Work - squinky86
This project is licensed under the ISC License. See the LICENSE.md file for details.