Skip to content

Upgrade github/codeql dependency to 2.23.9 - #1179

Open
github-actions[bot] wants to merge 116 commits into
mainfrom
codeql/upgrade-to-2.23.9
Open

Upgrade github/codeql dependency to 2.23.9#1179
github-actions[bot] wants to merge 116 commits into
mainfrom
codeql/upgrade-to-2.23.9

Conversation

@github-actions

Copy link
Copy Markdown

This PR upgrades the CodeQL CLI version to 2.23.9.

CodeQL dependency upgrade checklist:

  • Confirm the code has been correctly reformatted according to the new CodeQL CLI.
  • Identify any CodeQL compiler warnings and errors, and update queries as required.
  • Validate that the github/codeql test cases succeed.
  • Address any CodeQL test failures in the github/codeql-coding-standards repository.
  • Validate performance vs pre-upgrade, using /test-performance

jketema and others added 30 commits March 6, 2025 13:52
Update expected test results after frontend update
Update MISRA queries and tests after merging location tables
C++: accept new test results after QL changes
Observe that `sizeof(...)` might not occur as a dataflow node if it has a
parent node with a concrete value. That value will be a dataflow node instead.
Hence, the query has be changed to check for expressions where `sizeof(...)`
is a child of an expression with a concrete value.
Note that we now properly report the offending cast instead of the expression
that is being cast.
As it is the dataflow used by `asctime` that is relevant, and not the pointer,
use the indirect expression.
Convert a number of queries to use the new dataflow library
Update expected test results for MSC33-C
Since the new dataflow library uses use-use dataflow and not def-use dataflow,
we now need to check for definitions. Note that these queries can probably be
improved by using a dataflow configuration - possibly limited to the local
context of a function by including `DataFlow::FeatureEqualSourceSinkCallContext`
jketema and others added 30 commits August 19, 2025 11:26
…taflow library

Note this introduces some new results. This seems to be correct, as before the
update the query seemed to have missed problems with code like the following:
```cpp
void f3(int *v1) {
  int *v2 = v1;
  std::shared_ptr<int> p1(v1);        // NON_COMPLIANT
  new std::shared_ptr<int>(p1.get()); // NON_COMPLIANT
  new std::shared_ptr<int>(v2);       // NON_COMPLIANT
}

void f4() {
  f3(new int(0));
}
```
…w library

Note that this removes - what seems to be - a duplicated test result.
Note that there's a small issue here where the dataflow library causes one of
the results to get duplicated.
Update more queries to the new dataflow library
…guards-2

C++: Fix more queries after shared guards (part 2)
With CodeQL 2.23.4 we recognize that the instantiation type was `uintptr_t`.
Update expected test results after frontend update
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants