Findings by static analyzers in Fedora 45 Critical Path Packages - August 2026
Siteshwar Vashisht via devel <[email protected]>
| Newsgroups | gmane.linux.redhat.fedora.devel |
|---|---|
| Message-ID | <CAEbT0X2uwppuBYzYrDcONh7CRVK70xNgngk3c_yM8-WpuNAM5w@mail.gmail.com> |
Hello, I am writing this message to get feedback from the community on findings by static analyzers in Critical Path Packages that have changed in Fedora 45. TLDR: This report[1] contains a total of 83009 findings and 3997 new findings identified since Fedora 44. An AI analysis has identified 28 important and 34 moderate impact findings that may have a security impact. The reports containing these findings are highlighted in red. Please review the report and provide feedback. A mass scan was performed on the packages that have changed in Fedora 45. This report[1] contains all the findings that have been identified in the Critical Path Packages. Newly added findings since Fedora 44 are listed under ‘+’ column. Not all findings reported by OpenScanHub may be actual bugs, so please verify reported findings before investing time into fixing or reporting them. We have performed an AI analysis through Opus 4.6 (1M context) on GCC reports for findings that may have a security impact. AI analysis has identified a total of 28 important, 34 moderate and 2757 low impact findings. These should be prioritized while reviewing the findings (and fixing them upstream). Each analysis contains a patch with a proposed fix. False positives can be recorded in the known-false-positives[5] repository. These findings are automatically suppressed by OpenScanHub in scans that are triggered later. Also, you can filter findings with the csgrep utility to make it easier to review reports that may contain a large amount of false positives. Examples of csgrep invocation are available on the Fedora wiki[4]. We hope this is helpful for the packages you maintain and for the upstream projects. Questions can be asked on the OpenScanHub mailing list[2]. If you want to see the raw scan results, they are available on the tasks[3] page. User documentation for performing a scan is available on the Fedora wiki[4]. I would like to thank contributors who have made fixes based on these reports in the past: Alan Coopersmith - xorg-x11-server-Xwayland Ales Matej - libdnf Andrew G. Morgan - libcap Arjun Shankar - glibc Benjamin Marzinski - device-mapper-multipath Chet Ramey - bash, readline David Malcolm - gcc Debarshi Ray - flatpak Dirk Farin - libheif Frantisek Sumsal - polkit Jeremy Cline - pkcs11-provider Lasse Collin - xz Mikel Olasagasti Uranga - nss-mdns Panu Matilainen - rpm Paolo Bonzini - qemu Petr Pisar - libmodulemd Steve Grubb - OpenSSL Also, I would like to thank people who spent time on reviewing the previous reports but did not make any fixes due to false positives. If you are making fixes based on these reports, please contact me off list so that I can give you due credits in the future. Please keep the feedback on this thread constructive. Thank you! [1] https://svashisht.fedorapeople.org/openscanhub/mass-scans/f45-03-Aug-2026/ [2] https://lists.fedoraproject.org/archives/list/[email protected]/ [3] https://openscanhub.fedoraproject.org/task/ [4] https://fedoraproject.org/wiki/OpenScanHub [5] https://github.com/openscanhub/known-false-positives -- _______________________________________________ devel mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected] Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new