palantir / log4j-sniffer

A tool that scans archives to check for vulnerable log4j versions

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Report on individual files rather than only resultant aggregation at top level

glynternet opened this issue · comments

Currently we are combining all nested findings as a single aggregated result for a top-level file on disk.

To provide transparency into exactly why a given top-level file is being flagged as vulnerable, we should report on individual files, even when nested, along with the full nesting path at which they can be found.