JavaScript is not currently enabled, but is required for full CodeSonar manual search and browse functionality.
If you are viewing this file in your hub's Web GUI, enable JavaScript in your browser: you will also need it for GUI functionality.
If you opened this file directly from disk, your browser may be directly suppressing JavaScript functionality: certain browsers perform this suppression on local files (but not files delivered by web servers) for security reasons.
| CodeSonar® 9.2p0 | CONFIDENTIAL | CodeSecure Inc |
This page describes the CodeSonar warning classes that are assigned to Go warnings imported from a SARIF file produced by Staticcheck.
See also the table of CodeSonar warning classes that are supported for all languages. If these classes are enabled, the corresponding CodeSonar checks will include all Go source files that were imported into the project with codesonar go_scan.py, codesonar import_sarif.py, or codesonar add_source_files.py.
This page describes the CodeSonar warning classes that are assigned to Go warnings imported from a SARIF file produced by Staticcheck.
For information on setting up your CodeSonar project to incorporate Go source code and the corresponding Staticcheck results, see Including Go Components in a CodeSonar Project.
When CodeSonar imports a SARIF file, it determines a corresponding CodeSonar warning class for each rule object in the SARIF rules. If a given warning class does not already exist, the SARIF importer creates it.
There is special handling for SARIF files produced by Staticcheck.
| CodeSonar Warning Property | Value |
|---|---|
| Name |
Generated from the results of running staticcheck -list-checks (or from
a file specified with the -staticcheck-list option to
codesonar
import-sarif.py).
|
| Categories |
When a warning class is based on a Staticcheck check, its
categories depend on whether the warning class is built in to
CodeSonar or created by the SARIF importer.
|
| otherwise | Other warning class properties are not set by the SARIF importer. |
Suppose the imported SARIF file includes a rule object like the following.
# ... "rules":[ # ... { "id": "SA2001", # SARIF produced by Staticcheck does not include a "name" # ... }, # ... ], # ...
(This corresponds to the Staticcheck Empty critical section, did you mean to defer the unlock? check.)
CodeSonar will consider a SARIF file to be produced by Staticcheck in the following cases.
These warning classes correspond to checks from Staticcheck version 2023.1.6.
You have multiple degrees of control over reporting for the warnings issued by Staticcheck.
See the Staticcheck Configuration File documentation for details.
You can also specify a combination of WARNING_FILTER discard and WARNING_FILTER allow rules, if that is the most convenient way to characterize a specific set. When you specify warning class names (or parts of names) in your WARNING_FILTER rules, make sure you are using the generated CodeSonar warning class name as described above.
To report problems with this documentation, please visit https://support.codesecure.com/.