From b59fc6c902f668a855efded64c7f7080cfff6710 Mon Sep 17 00:00:00 2001 From: Niels Lohmann Date: Thu, 1 Oct 2026 10:26:18 +0200 Subject: [PATCH 1/3] Mark string_ref's strlen as a Flawfinder false positive string_ref(const char*) requires a null-terminated string, like std::string_view's constructor. Signed-off-by: Niels Lohmann --- include/nlohmann/detail/view/string_ref.hpp | 2 ++ 1 file changed, 2 insertions(+) diff --git a/include/nlohmann/detail/view/string_ref.hpp b/include/nlohmann/detail/view/string_ref.hpp index bb9605bf6..d401500ec 100644 --- a/include/nlohmann/detail/view/string_ref.hpp +++ b/include/nlohmann/detail/view/string_ref.hpp @@ -40,6 +40,8 @@ class string_ref using const_iterator = const char*; string_ref() noexcept = default; + // s must be null-terminated, as for std::string_view(const char*) + // flawfinder: ignore string_ref(const char* s) : m_data(s), m_size(std::strlen(s)) {} // NOLINT(google-explicit-constructor,hicpp-explicit-conversions) string_ref(const char* s, std::size_t n) noexcept : m_data(s), m_size(n) {} template From 134b2f0efe973e62251b41aa0ed0bd0d8a8eede9 Mon Sep 17 00:00:00 2001 From: Niels Lohmann Date: Thu, 1 Oct 2026 10:27:01 +0200 Subject: [PATCH 2/3] Mark json_view.hpp's read() and strlen as Flawfinder false positives json_document::read is a member function, not POSIX read(), and the C string overload requires null-terminated input like json::parse. Signed-off-by: Niels Lohmann --- include/nlohmann/json_view.hpp | 3 +++ single_include/nlohmann/json_view.hpp | 5 +++++ 2 files changed, 8 insertions(+) diff --git a/include/nlohmann/json_view.hpp b/include/nlohmann/json_view.hpp index 071cf61be..5aec36ef9 100644 --- a/include/nlohmann/json_view.hpp +++ b/include/nlohmann/json_view.hpp @@ -329,6 +329,7 @@ class basic_json_document /// parse into this document, reusing its memory template + // flawfinder: ignore (a member function, not POSIX read()) void read(InputType&& input, const bool allow_exceptions = true, const bool ignore_comments = false, @@ -495,6 +496,8 @@ class basic_json_document return; } const char* cs = reinterpret_cast(s); // NOLINT(cppcoreguidelines-pro-type-reinterpret-cast) + // C strings are null-terminated, as for json::parse(const char*) + // flawfinder: ignore build(cs, std::strlen(cs), ae, c, tc, false, true); } diff --git a/single_include/nlohmann/json_view.hpp b/single_include/nlohmann/json_view.hpp index 1b6fee52f..d3040e120 100644 --- a/single_include/nlohmann/json_view.hpp +++ b/single_include/nlohmann/json_view.hpp @@ -2009,6 +2009,8 @@ class string_ref using const_iterator = const char*; string_ref() noexcept = default; + // s must be null-terminated, as for std::string_view(const char*) + // flawfinder: ignore string_ref(const char* s) : m_data(s), m_size(std::strlen(s)) {} // NOLINT(google-explicit-constructor,hicpp-explicit-conversions) string_ref(const char* s, std::size_t n) noexcept : m_data(s), m_size(n) {} template @@ -2361,6 +2363,7 @@ class basic_json_document /// parse into this document, reusing its memory template + // flawfinder: ignore (a member function, not POSIX read()) void read(InputType&& input, const bool allow_exceptions = true, const bool ignore_comments = false, @@ -2527,6 +2530,8 @@ class basic_json_document return; } const char* cs = reinterpret_cast(s); // NOLINT(cppcoreguidelines-pro-type-reinterpret-cast) + // C strings are null-terminated, as for json::parse(const char*) + // flawfinder: ignore build(cs, std::strlen(cs), ae, c, tc, false, true); } From 057c86de8cb99ee83fd509d90959c5b0f0d5a276 Mon Sep 17 00:00:00 2001 From: Niels Lohmann Date: Thu, 1 Oct 2026 10:28:47 +0200 Subject: [PATCH 3/3] Mark compare.py's subprocess and download calls for Bandit The commands are argument lists the script builds itself, and the downloads are pinned https URLs whose SHA-256 is checked. Signed-off-by: Niels Lohmann --- tests/benchmarks/json_view/compare.py | 14 +++++++++----- 1 file changed, 9 insertions(+), 5 deletions(-) diff --git a/tests/benchmarks/json_view/compare.py b/tests/benchmarks/json_view/compare.py index 0901011ca..91e7d0a83 100755 --- a/tests/benchmarks/json_view/compare.py +++ b/tests/benchmarks/json_view/compare.py @@ -30,7 +30,8 @@ import platform import re import shlex import shutil -import subprocess +# runs only the compilers and benchmark binaries this script builds +import subprocess # nosec B404 import sys import tarfile import urllib.request @@ -71,12 +72,14 @@ DEFAULT_CORPUS = [ def run(cmd, **kwargs): print('+ ' + ' '.join(shlex.quote(c) for c in cmd), flush=True) - return subprocess.run(cmd, check=True, **kwargs) + # cmd is an argument list built by this script, never a shell string + return subprocess.run(cmd, check=True, **kwargs) # nosec B603 def output(cmd): try: - return subprocess.run(cmd, check=True, capture_output=True, text=True).stdout.strip() + # cmd is an argument list built by this script, never a shell string + return subprocess.run(cmd, check=True, capture_output=True, text=True).stdout.strip() # nosec B603 except (OSError, subprocess.CalledProcessError): return '' @@ -150,7 +153,8 @@ def download_library(name, work): os.makedirs(os.path.dirname(archive), exist_ok=True) if not os.path.isfile(archive): print(f'downloading {pin["url"]}', flush=True) - urllib.request.urlretrieve(pin['url'], archive) + # the URLs are the https constants in PINNED, and the SHA-256 is checked below + urllib.request.urlretrieve(pin['url'], archive) # nosec B310 with open(archive, 'rb') as f: digest = hashlib.sha256(f.read()).hexdigest() if digest != pin['sha256']: @@ -160,7 +164,7 @@ def download_library(name, work): with tarfile.open(archive) as t: # (the 'data' filter rejects links and paths outside the target where Python has it) kwargs = {'filter': 'data'} if hasattr(tarfile, 'data_filter') else {} - t.extractall(os.path.join(work, 'download'), **kwargs) # noqa: S202 (checked archive) + t.extractall(os.path.join(work, 'download'), **kwargs) # noqa: S202 (checked archive) # nosec B202 if name == 'yyjson': return Library(name, [os.path.join(src, 'src')], [os.path.join(src, 'src', 'yyjson.c')], [], pin['version']) if name == 'simdjson':