Collaborative repository to catalogue insecure functions in various programming languages.
This project is maintained by @c3l3si4n and @caioluders
The main goal is to have a definitive and precise list of functions that are likely to be insecure. The main usage is to help security code reviews. We do not aim to detail why the function is insecure and how to exploit it, this would be a gargantuan work (maybe later tho).
-
Want to add more functions? Fist take a look at the CONTRIBUTING.md, the document defines what types of functions makes senses to include, and how to represent them. After that please make a Pull Request with the functions that you think should be included.
-
Think a function shouldn't be here? Please read the CONTRIBUTING.md, and if the function doesn't comply with the guideline open an Issue so we can debate.
-
Requests / Ideas ? Open an Issue !