github / github/codeql-cli-binaries

No result of the query

Ouverte
#116 1 commentaire 0 réactions 0 personnes assignées Voir sur GitHub
CLI
Langage dominant
Aucune donnée de langage
Étoiles
1k
Forks
184
Métriques de merge des PR
Aucune PR mergée en 30 j

Description

Hello, my name is Sofya
I was trying to run an example from this link on Visual Studio Code:
https://codeql.github.com/docs/codeql-language-guides/analyzing-data-flow-in-javascript-and-typescript/#analyzing-data-flow-in-javascript-and-typescript
I created a database of Node.js library manually and added it to Visual Studio Code and it is activated.
My query look like that:

/**
* @kind path-problem
*/

import javascript
import DataFlow::PathGraph

class CommandLineFileNameConfiguration extends TaintTracking::Configuration {
CommandLineFileNameConfiguration() { this = "CommandLineFileNameConfiguration" }

override predicate isSource(DataFlow::Node source) {
DataFlow::globalVarRef("process").getAPropertyRead("argv").getAPropertyRead() = source
}

override predicate isSink(DataFlow::Node sink) {
DataFlow::moduleMember("fs", "readFile").getACall().getArgument(0) = sink
}
}

from CommandLineFileNameConfiguration cfg, DataFlow::Node source, DataFlow::Node sink
where cfg.hasFlow(source, sink)
select sink, source, sink, ""

Unfortunately this query is not giving any results. (no errors occured)
Can you help me with it please? Maybe the problem is in database?

Guide de contribution

Ouvrir le guide de contribution

Piste de recherche

Start with the linked CodeQL data-flow guide, then compare the query's source and sink predicates with the manually created Node.js database in Visual Studio Code. Check whether the database contains the referenced process.argv and fs.readFile flow. Done means explaining why no results appear or identifying the database/query mismatch.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
javascript, node.js, typescript, vscode
Domaine
devtools, security
Type d'issue
Bug
Difficulté
4/5
Temps estimé
3-5 jours
Activité
À l'abandon
Clarté
À clarifier
Accessibilité débutants
25/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.