This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Rule IDs for Filtering

The Fortify SCA documentation provides an example for filtering using RuleID (for Path Manipulation):

#This is a specific Rule ID that leads to the reporting of a 
#specific issue in the scan output: in this case the 
#dataflow sink for a Path Manipulation issue.
823FE039-A7FE-4AAD-B976-9EC53FFE4A59

If the complete list (or even a substantial list)  of Rule IDs with the related documentation exists, can someone point me to it?

Tags:

  •  

    Hi Pramath,


    The list of rules with their rule IDs is not public information. Practically, you have the following options to create the filter file you need:

    • Obtain the rule IDs from a previous scan. In AWB, you can view the analysis trace of each issue and see which rules were responsible for which conclusion.
    • Filter by (sub)category rather than rule ID.

    Regards,
    Frans

  • in reply to   

    Frans, thank you for your reply. It was hugely helpful.

    Pramath