semgrep-rules icon indicating copy to clipboard operation
semgrep-rules copied to clipboard

New Rules Proposal: Detect usage of SHA1PRNG in java.

Open righettod opened this issue 2 months ago • 0 comments

Hello,

This rule, for java language, is intended to detect and raise a warning when SHA1PRNG, a pseudo random number generator algorithm which is considered insecure, is used.

I tested the rule against the sample code using the online rule editor:

image image

Thank you very much for your feedback 😉

righettod avatar Oct 30 '25 07:10 righettod