Class JEXLInjectionCodemod

java.lang.Object
io.codemodder.javaparser.JavaParserChanger
io.codemodder.SarifPluginJavaParserChanger<com.github.javaparser.ast.expr.Expression>
io.codemodder.codemods.JEXLInjectionCodemod
All Implemented Interfaces:
io.codemodder.CodeChanger

@Codemod(id="codeql:java/jexl-expression-injection", reviewGuidance=MERGE_WITHOUT_REVIEW, executionPriority=HIGH) public final class JEXLInjectionCodemod extends io.codemodder.SarifPluginJavaParserChanger<com.github.javaparser.ast.expr.Expression>
A codemod for automatically fixing JEXL injections detected by CodeQL's rule "java/jexl-expression-injection" whenever possible.
  • Field Summary

    Fields inherited from class io.codemodder.SarifPluginJavaParserChanger

    sarif

    Fields inherited from class io.codemodder.javaparser.JavaParserChanger

    reporter
  • Constructor Summary

    Constructors
    Constructor
    Description
    JEXLInjectionCodemod(io.codemodder.RuleSarif sarif)
     
  • Method Summary

    Modifier and Type
    Method
    Description
    List<io.codemodder.DependencyGAV>
     
    boolean
    onResultFound(io.codemodder.CodemodInvocationContext context, com.github.javaparser.ast.CompilationUnit cu, com.github.javaparser.ast.expr.Expression expression, com.contrastsecurity.sarif.Result result)
     

    Methods inherited from class io.codemodder.SarifPluginJavaParserChanger

    shouldRun, visit

    Methods inherited from class io.codemodder.javaparser.JavaParserChanger

    getDescription, getIndividualChangeDescription, getReferences, getSummary

    Methods inherited from class java.lang.Object

    clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
  • Constructor Details

    • JEXLInjectionCodemod

      @Inject public JEXLInjectionCodemod(@ProvidedCodeQLScan(ruleId="java/jexl-expression-injection") io.codemodder.RuleSarif sarif)
  • Method Details

    • onResultFound

      public boolean onResultFound(io.codemodder.CodemodInvocationContext context, com.github.javaparser.ast.CompilationUnit cu, com.github.javaparser.ast.expr.Expression expression, com.contrastsecurity.sarif.Result result)
      Specified by:
      onResultFound in class io.codemodder.SarifPluginJavaParserChanger<com.github.javaparser.ast.expr.Expression>
    • dependenciesRequired

      public List<io.codemodder.DependencyGAV> dependenciesRequired()
      Overrides:
      dependenciesRequired in class io.codemodder.javaparser.JavaParserChanger