Packages
metastatic
0.5.2
0.26.0
0.25.0
0.24.1
0.24.0
0.23.0
0.22.2
0.22.1
0.22.0
0.21.3
0.21.2
0.21.1
0.21.0
0.20.3
0.20.2
0.20.1
0.20.0
0.19.0
0.18.0
0.17.0
0.16.0
0.15.1
0.15.0
0.14.2
0.14.1
0.14.0
0.13.3
0.13.2
0.13.1
0.13.0
0.12.0
0.11.0
0.10.4
0.10.3
0.10.2
0.10.1
0.10.0
0.9.2
0.9.1
0.9.0
0.8.6
0.8.5
0.8.4
0.8.3
0.8.2
0.8.1
0.8.0
0.7.7
0.7.6
0.7.5
0.7.4
0.7.3
0.7.1
0.7.0
0.6.1
0.6.0
0.5.2
0.5.1
0.5.0
0.4.2
0.4.1
0.4.0
0.3.5
0.3.4
0.3.3
0.3.2
0.3.1
0.3.0
0.2.0
0.1.3
0.1.2
0.1.1
0.1.0
Cross-language code meta-model library using unified MetaAST representation. Parse, transform, and translate code across Python, Elixir, Ruby, Erlang, Haskell, and more via a shared three-tuple AST format.
Current section
Files
Jump to
Current section
Files
lib/metastatic/analysis/business_logic/direct_struct_update.ex
defmodule Metastatic.Analysis.BusinessLogic.DirectStructUpdate do
@moduledoc """
Detects direct object/struct updates bypassing validation.
Universal pattern: updating structured data without validation functions.
Applies to: Pydantic, Rails validations, ASP.NET validators, Ecto changesets, etc.
"""
@behaviour Metastatic.Analysis.Analyzer
alias Metastatic.Analysis.Analyzer
@impl true
def info do
%{
name: :direct_struct_update,
category: :correctness,
description: "Detects object updates without validation",
severity: :warning,
explanation: "Use validation functions (changesets, validators) for data integrity",
configurable: false
}
end
@impl true
def analyze({:map, _fields} = node, _context) do
# Map update - could be struct update bypassing validation
# This is a simplified detection; real implementation would check context
[
Analyzer.issue(
analyzer: __MODULE__,
category: :correctness,
severity: :info,
message: "Consider using validation (changeset/validator) for struct updates",
node: node,
metadata: %{suggestion: "Use validation functions"}
)
]
end
def analyze(_node, _context), do: []
end