Is it possible to delete (instead of marking removed) issues from files which are deleted now?

I've tried excluding the files from the Project Translation when scanning, but it didn't help. Now when those files are deleted, I don't want to see their issues in the Fortify project.

BTW I'm using HP Fortify 3.70.

有帮助吗?

解决方案

I believe that best practices would say:

  1. Audit tag as appropriate
  2. Add comment that they were removed
  3. Suppress the vulnerabilities.

You can do this quickly by "grouping by" source file, multiselecting, then Tag/Comment/Suppress all at one time.

Actually removing vulnerabilities would break the history audit trail.

许可以下: CC-BY-SA归因
不隶属于 StackOverflow
scroll top