Skip to content

Commit 9c658ef

Browse files
authored
Update owasp-webgoat.md
1 parent c3e4aac commit 9c658ef

File tree

1 file changed

+2
-3
lines changed

1 file changed

+2
-3
lines changed

code-scanning-guides/synthetic-applications/owasp-webgoat.md

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,6 @@ This is due to the following:
1414
3. Dependencies are not all present in Dependency Graph
1515
- Using [Submission API](https://docs.github.com/en/enterprise-cloud@latest/code-security/supply-chain-security/understanding-your-software-supply-chain/using-the-dependency-submission-api#using-pre-made-actions)
1616
4. Vulnerabilities not detected.
17-
1. Local sources not detected
18-
- The default threat model includes remote sources of untrusted data. Use a CodeQL custom configuration file to [expand the threat model to include local sources](https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/customizing-your-advanced-setup-for-code-scanning#extending-codeql-coverage-with-threat-models)https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/customizing-your-advanced-setup-for-code-scanning#extending-codeql-coverage-with-threat-models: `threat-models: local`
19-
2. For a lower precision scan that may include elevated false positive rates, use a custom configuration file that pulls in additional expirmental, low precision, and community packs/queries.
17+
- Enhance CodeQL to use a custom configuration file that broadens the threat model and pulls in additional expirmental, low precision, and community packs/queries. Note that this may include alerts with elevated false positive rates due to lower precision.
2018
- See: [Synthetics.yml](https://github.com/GitHubSecurityLab/CodeQL-Community-Packs/tree/main/configs#synthetics)
19+
- The default threat model includes remote sources of untrusted data. This config will also [expand the threat model to include local sources](https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/customizing-your-advanced-setup-for-code-scanning#extending-codeql-coverage-with-threat-models): `threat-models: local`

0 commit comments

Comments
 (0)