docs(ubs): add --only flag guidance to prevent cross-language false positives #504
+45
−147
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
Updates the UBS (Ultimate Bug Scanner) documentation to emphasize the importance of using the
--onlyflag when scanning files.Problem
UBS auto-detects all 8 languages (js, python, cpp, rust, golang, java, ruby, swift) and scans every file with every scanner. This causes false positives:
Solution
Updated
.cursor/rules/ubs.mdwith:Changes
--only=<lang>flag usage--only" anti-patternImpact
Prevents Python/JavaScript scanners from producing false positives when scanning Rust files (e.g., 'invalid-syntax' errors, 'loose equality' warnings on OsString comparisons).
Testing
--only=rustflag works as expected on Rust filesChecklist