Flawfinder version 2.0.10, (C) 2001-2019 David A. Wheeler. Number of rules (primarily dangerous function names) in C/C++ ruleset: 223 Examining data/python-mapnik-0.0~20200224-7da019cf9/src/boost_std_shared_shim.hpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_color.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_coord.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_datasource.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_datasource_cache.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_enumeration.hpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_enumeration_wrapper_converter.hpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_envelope.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_expression.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_feature.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_featureset.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_font_engine.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_fontset.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_gamma_method.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_geometry.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_grid.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_grid_view.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_image.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_image_view.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_label_collision_detector.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_layer.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_logger.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_map.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_palette.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_parameters.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_proj_transform.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_projection.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_python.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_query.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_raster_colorizer.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_rule.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_scaling_method.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_style.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_svg.hpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_symbolizer.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_threads.hpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_value_converter.hpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_view_transform.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/python_grid_utils.cpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/python_grid_utils.hpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/python_optional.hpp Examining data/python-mapnik-0.0~20200224-7da019cf9/src/python_to_value.hpp FINAL RESULTS: data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_layer.cpp:63:5: [3] (random) setstate: This function is not sufficiently random for security-related functions such as key and nonce creation (CWE-327). Use a more secure technique for acquiring random values. setstate (layer& l, boost::python::tuple state) data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_parameters.cpp:69:17: [3] (random) setstate: This function is not sufficiently random for security-related functions such as key and nonce creation (CWE-327). Use a more secure technique for acquiring random values. static void setstate(parameters& p, boost::python::tuple state) data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_image.cpp:239:56: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). return std::make_shared<image_any>(reader->read(0,0,reader->width(),reader->height())); data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_image.cpp:251:52: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). return std::make_shared<image_any>(reader->read(0,0,reader->width(), reader->height())); data/python-mapnik-0.0~20200224-7da019cf9/src/mapnik_image.cpp:265:56: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). return std::make_shared<image_any>(reader->read(0,0,reader->width(),reader->height())); ANALYSIS SUMMARY: Hits = 5 Lines analyzed = 7573 in approximately 0.32 seconds (23964 lines/second) Physical Source Lines of Code (SLOC) = 5717 Hits@level = [0] 0 [1] 3 [2] 0 [3] 2 [4] 0 [5] 0 Hits@level+ = [0+] 5 [1+] 5 [2+] 2 [3+] 2 [4+] 0 [5+] 0 Hits/KSLOC@level+ = [0+] 0.874585 [1+] 0.874585 [2+] 0.349834 [3+] 0.349834 [4+] 0 [5+] 0 Dot directories skipped = 1 (--followdotdir overrides) Minimum risk level = 1 Not every hit is necessarily a security vulnerability. There may be other security vulnerabilities; review your code! See 'Secure Programming HOWTO' (https://dwheeler.com/secure-programs) for more information.