c:S2068 dont detect hard coded password in macro definition

SonarQube Developer Edition

#define DB_PASSWORD 	"secret"

This hard coded password is not detected. Please confirm whether this pattern should be detected or not since the rule does not explicitly state anything regarding macro definition.

I found this old open issue on adding evaluation for this pattern:

Does this means password hardcoded in macro definition won’t be flagged by SonarQube?


That ticket is still open, so the rule hasn’t been updated yet for your case.


I mentioned this in the CPP-2852 ticket so that we don’t forget about this post. Thanks for raising this.

Great, thanks!

