Findings by static analyzers in Fedora 45 Critical Path Packages - August 2026

Siteshwar Vashisht via devel <[email protected]>
Newsgroups gmane.linux.redhat.fedora.devel
Message-ID <CAEbT0X2uwppuBYzYrDcONh7CRVK70xNgngk3c_yM8-WpuNAM5w@mail.gmail.com>
Hello,

I am writing this message to get feedback from the community on
findings by static analyzers in Critical Path Packages that have
changed in Fedora 45.

TLDR: This report[1] contains a total of 83009 findings and 3997 new
findings identified since Fedora 44. An AI analysis has identified 28
important and 34 moderate impact findings that may have a security
impact. The reports containing these findings are highlighted in red.
Please review the report and provide feedback.

A mass scan was performed on the packages that have changed in Fedora
45. This report[1] contains all the findings that have been identified
in the Critical Path Packages. Newly added findings since Fedora 44
are listed under ‘+’ column. Not all findings reported by OpenScanHub
may be actual bugs, so please verify reported findings before
investing time into fixing or reporting them.

We have performed an AI analysis through Opus 4.6 (1M context) on GCC
reports for findings that may have a security impact. AI analysis has
identified a total of 28 important, 34 moderate and 2757 low impact
findings. These should be prioritized while reviewing the findings
(and fixing them upstream). Each analysis contains a patch with a
proposed fix.

False positives can be recorded in the known-false-positives[5]
repository. These findings are automatically suppressed by OpenScanHub
in scans that are triggered later. Also, you can filter findings with
the csgrep utility to make it easier to review reports that may
contain a large amount of false positives. Examples of csgrep
invocation are available on the Fedora wiki[4].

We hope this is helpful for the packages you maintain and for the
upstream projects. Questions can be asked on the OpenScanHub mailing
list[2]. If you want to see the raw scan results, they are available
on the tasks[3] page. User documentation for performing a scan is
available on the Fedora wiki[4].

I would like to thank contributors who have made fixes based on these
reports in the past:

Alan Coopersmith - xorg-x11-server-Xwayland
Ales Matej - libdnf
Andrew G. Morgan - libcap
Arjun Shankar - glibc
Benjamin Marzinski - device-mapper-multipath
Chet Ramey - bash, readline
David Malcolm - gcc
Debarshi Ray - flatpak
Dirk Farin - libheif
Frantisek Sumsal - polkit
Jeremy Cline - pkcs11-provider
Lasse Collin - xz
Mikel Olasagasti Uranga - nss-mdns
Panu Matilainen - rpm
Paolo Bonzini - qemu
Petr Pisar - libmodulemd
Steve Grubb - OpenSSL

Also, I would like to thank people who spent time on reviewing the
previous reports but did not make any fixes due to false positives. If
you are making fixes based on these reports, please contact me off
list so that I can give you due credits in the future.

Please keep the feedback on this thread constructive. Thank you!

[1] https://svashisht.fedorapeople.org/openscanhub/mass-scans/f45-03-Aug-2026/

[2] https://lists.fedoraproject.org/archives/list/[email protected]/

[3] https://openscanhub.fedoraproject.org/task/

[4] https://fedoraproject.org/wiki/OpenScanHub

[5] https://github.com/openscanhub/known-false-positives

-- 
_______________________________________________
devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.