Upgrade github/codeql dependency to 2.23.9 - #1179
Open
github-actions[bot] wants to merge 115 commits into
Open
Conversation
Update expected test results after frontend update
Update MISRA queries and tests after merging location tables
C++: accept new test results after QL changes
Observe that `sizeof(...)` might not occur as a dataflow node if it has a parent node with a concrete value. That value will be a dataflow node instead. Hence, the query has be changed to check for expressions where `sizeof(...)` is a child of an expression with a concrete value.
Note that we now properly report the offending cast instead of the expression that is being cast.
As it is the dataflow used by `asctime` that is relevant, and not the pointer, use the indirect expression.
Convert a number of queries to use the new dataflow library
Update expected test results for MSC33-C
These use the new dataflow library
Since the new dataflow library uses use-use dataflow and not def-use dataflow, we now need to check for definitions. Note that these queries can probably be improved by using a dataflow configuration - possibly limited to the local context of a function by including `DataFlow::FeatureEqualSourceSinkCallContext`
… new dataflow library
…taflow library
Note this introduces some new results. This seems to be correct, as before the
update the query seemed to have missed problems with code like the following:
```cpp
void f3(int *v1) {
int *v2 = v1;
std::shared_ptr<int> p1(v1); // NON_COMPLIANT
new std::shared_ptr<int>(p1.get()); // NON_COMPLIANT
new std::shared_ptr<int>(v2); // NON_COMPLIANT
}
void f4() {
f3(new int(0));
}
```
…w library Note that this removes - what seems to be - a duplicated test result.
Note that there's a small issue here where the dataflow library causes one of the results to get duplicated.
Update more queries to the new dataflow library
C++: Fix queries after shared guards
…guards C++: Fix queries I forgot after merging github/codeql#20485.
…guards-2 C++: Fix more queries after shared guards (part 2)
With CodeQL 2.23.4 we recognize that the instantiation type was `uintptr_t`.
Update expected test results after frontend update
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR upgrades the CodeQL CLI version to 2.23.9.
CodeQL dependency upgrade checklist:
github/codeqltest cases succeed.github/codeql-coding-standardsrepository.