一、代碼裏面包含PASSWORD、PWDjava
'PWD' detected in this expression, review this potentially hardcoded credential.
二、父子類或者同一個類有同名的變量名(類方法、類變量、實例方法或者實例變量)express
Rename method "ENCRYPTMethod" to prevent any misunderstanding/clash with method "encryptMethod" defined on line 35.
public static String encryptMethod(String HexString, String keyStr) { .... } public static String ENCRYPTMethod(String HexString, String keyStr, String keyENCODED, String HexStringENCODED, String CipherInstanceType) throws Exception { ..... }
或者app
好比父類定義了一個Logger logger=...的logger變量,ui
子類又再次定義logger變量this
父類裏面已存在spa
或者3d
實體類的get/set方法屢次定義,僅僅大小寫不同 code
同一個類裏面blog
三、涉及到資源關閉這種,Use try-with-resources or close this "BufferedOutputStream" in a "finally" clause.ip
Use try-with-resources or close this "BufferedOutputStream" in a "finally" clause.
這種比較麻煩,傳統的作法,即在finally裏面進行if(stream!=null)(try{}catch(){})關閉仍然沒法經過
這種單獨開一篇博客尋找解決方法,見下一篇博客
Resources should be closed (squid:S2095) Bug Blocker Connections, streams, files, and other classes that implement the Closeable interface or its super-interface, AutoCloseable, needs to be closed after use. Further, that close call must be made in a finally block otherwise an exception could keep the call from being made. Preferably, when class implements AutoCloseable, resource should be created using "try-with-resources" pattern and will be closed automatically. Failure to properly close resources will result in a resource leak which could bring first the application and then perhaps the box it's on to their knees. Noncompliant Code Example private void readTheFile() throws IOException { Path path = Paths.get(this.fileName); BufferedReader reader = Files.newBufferedReader(path, this.charset); // ... reader.close(); // Noncompliant // ... Files.lines("input.txt").forEach(System.out::println); // Noncompliant: The stream needs to be closed } private void doSomething() { OutputStream stream = null; try { for (String property : propertyList) { stream = new FileOutputStream("myfile.txt"); // Noncompliant // ... } } catch (Exception e) { // ... } finally { stream.close(); // Multiple streams were opened. Only the last is closed. } } Compliant Solution private void readTheFile(String fileName) throws IOException { Path path = Paths.get(fileName); try (BufferedReader reader = Files.newBufferedReader(path, StandardCharsets.UTF_8)) { reader.readLine(); // ... } // .. try (Stream<String> input = Files.lines("input.txt")) { input.forEach(System.out::println); } } private void doSomething() { OutputStream stream = null; try { stream = new FileOutputStream("myfile.txt"); for (String property : propertyList) { // ... } } catch (Exception e) { // ... } finally { stream.close(); } } Exceptions Instances of the following classes are ignored by this rule because close has no effect: •java.io.ByteArrayOutputStream •java.io.ByteArrayInputStream •java.io.CharArrayReader •java.io.CharArrayWriter •java.io.StringReader •java.io.StringWriter Java 7 introduced the try-with-resources statement, which implicitly closes Closeables. All resources opened in a try-with-resources statement are ignored by this rule. try (BufferedReader br = new BufferedReader(new FileReader(fileName))) { //... } catch ( ... ) { //... } See •MITRE, CWE-459 - Incomplete Cleanup •CERT, FIO04-J. - Release resources when they are no longer needed •CERT, FIO42-C. - Close files when they are no longer needed •Try With Resources