-
Notifications
You must be signed in to change notification settings - Fork 396
Open
Description
I'm just picking on integers right now, because that's top of mind, but:
strconv.Atoiis almost never correct; I cover this in a few different talks- We list
strconv.ParseIntbut notParseUint(thanks @disconnect3d for pointing that out) - We need to explain that many things take flows that are
intbut can pun those flows toint32orint64oruintflavors without the compiler complaining, but can lead to various issues. I spoke about this vis-a-vis Kubernetes in my talk at OWASP Global AppSec DC.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels