分析对象jar包的所依赖的第三发jar包都为导入到jacodb中,所以设置了UnknownClasses和UnknownClassMethodsAndFields特性。
class path特性设置
database.asyncClasspath(classpath,
List.of(UnknownClasses.INSTANCE,
UnknownClassMethodsAndFields.INSTANCE)).get();
执行jacodb自带的npe和unused分析:
NpeManager npeManager = new NpeManager(applicationGraph, unitResolver);
List<TaintVulnerability> npeVulnerabilities =
npeManager.analyze(entryMethodList,
toDuration(ifdsAnalysisParameter.getTimeout(),
DurationUnit.SECONDS));
UnusedVariableManager unusedVariableManager =
new UnusedVariableManager(applicationGraph, unitResolver);
List<UnusedVariableVulnerability> vulnerabilities =
unusedVariableManager.analyze(entryMethodList,
toDuration

最低0.47元/天 解锁文章
1919

被折叠的 条评论
为什么被折叠?



