Skip to content

fix(scanner): enable multi-file cross-taint analysis across all supported languages - #67

Open
Adityakk9031 wants to merge 2 commits into
Corgea:mainfrom
Adityakk9031:fix/multifile-cross-taint-multi-language
Open

fix(scanner): enable multi-file cross-taint analysis across all supported languages#67
Adityakk9031 wants to merge 2 commits into
Corgea:mainfrom
Adityakk9031:fix/multifile-cross-taint-multi-language

Conversation

@Adityakk9031

Copy link
Copy Markdown
Contributor

Summary

  • Generalizes select_cross_file_targets in src/scanner/multifile_taint.rs to target all active languages in iles_by_language instead of hardcoding Python only.
  • Updates �uild_import_export_maps to process all supported target languages.
  • Generalizes sibling source file lookup and definition pattern matching in src/scanner/dataflow.rs to support non-Python extensions and multiple language function signatures.

@Adityakk9031

Copy link
Copy Markdown
Contributor Author

@juangaitanv and @Ibrahimrahhal have a look

@juangaitanv
juangaitanv self-requested a review August 17, 2026 08:32
Comment on lines +334 to +335
for file_path in files {
self.analyze_file_for_imports_exports(file_path, language, &rule_deduplicator)?;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

a read or parser failure aborts all cross-file analysis and produces no findings; could we handle failures per file and continue?

Comment thread src/scanner/dataflow.rs
Comment on lines +1190 to +1199
let py_pattern = format!("def {}(", function_name);
let js_pattern1 = format!("function {}(", function_name);
let js_pattern2 = format!("const {} =", function_name);
let js_pattern3 = format!("let {} =", function_name);
let fn_pattern = format!("fn {}(", function_name);
content.contains(&py_pattern)
|| content.contains(&js_pattern1)
|| content.contains(&js_pattern2)
|| content.contains(&js_pattern3)
|| content.contains(&fn_pattern)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

const and let bindings are treated as functions while body extraction accepts only Python def; could we limit lookup to callable declarations and align body extraction?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants