Skip to content

Fix hidden-UI false positives on generic View.GONE toggles - #124

Merged
ajinabraham merged 1 commit into
mainfrom
fix/123-hidden-ui-false-positives
Sep 21, 2026
Merged

ajinabraham merged 1 commit into
mainfrom
fix/123-hidden-ui-false-positives

Conversation

@ajinabraham

Copy link
Copy Markdown
Member

Summary

  • Scope android_kotlin_hiddenui and android_hidden_ui to sensitive-sounding view names (password, pin, token, etc.) so ordinary visibility toggles on dividers, buttons, and snackbars no longer fire as findings.
  • Drop both rules from ERROR to WARNING, matching the other name-heuristic sensitive-UI checks in the same rulesets.
  • Bump the package version to 1.0.1.

Fixes #123.

Test plan

  • semgrep --validate --strict on the Kotlin and Java hidden-UI rule files
  • semgrep --test for android.yaml / hidden_ui.yaml (benign headerDivider / btn2 cases are ok:, sensitive passwordView / passwordField cases are ruleid:)
  • pytest tests (45 passed)

Made with Cursor

Co-authored-by: Cursor <cursoragent@cursor.com>
@ajinabraham
ajinabraham merged commit bc17b74 into main Sep 21, 2026
12 checks passed
@ajinabraham
ajinabraham deleted the fix/123-hidden-ui-false-positives branch September 21, 2026 02:56
@byrongehman-ezpz

Copy link
Copy Markdown

Thank you @ajinabraham 👍

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

android_kotlin_hiddenui fires as Critical/ERROR on any View.GONE/INVISIBLE, not just sensitive views — massive false-positive rate

2 participants