github / github/codeql-cli-binaries

Running CodeQL within a Flask server silently interrupts connection

オープン
#132 コメント 2 件 リアクション 1 件 担当者 0 名 GitHub で見る
CLI
主要言語
言語のデータがありません
スター
1k
フォーク
184
PR マージ指標
30日以内にマージされた PR はありません

説明

I have extended the [official CodeQL container](https://github.com/microsoft/codeql-container) to run CodeQL analysis during a Python Flask HTTP request.

Throughout the request, three codeql CLI commands are executed:

```
codeql database create
codeql database upgrade
codeql database analyze
```

create and upgrade do not interrupt the connection, but I find that when the analyze command occurs, Flask will respond as normal but the client never receives the response. Leading me to believe something within the analyze command is silently interrupting the connection.

The python code I'm using uses the Python code found in the official CodeQL Docker container. Here is the code I'm running within the request:

```python
database_update_command = f"database upgrade {database_directory}"
database_analyze_command = f"database analyze {database_directory} --threads=0 --format=sarifv2.1.0 --output=output.json {database_lang}-security-and-quality.qls"
run_result = self.codeql.execute_codeql_command(
database_update_command)
run_result = self.codeql.execute_codeql_command(
database_analyze_command)
```

Any help would be appreciated!

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

Reproduce the Flask request using the three CodeQL CLI commands, especially database analyze, and inspect the Python execute_codeql_command call and its output handling. Compare analyze with database create and database upgrade to isolate why the client receives no response; done means identifying the interruption and documenting or fixing the integration.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
docker, flask, python
領域
backend, cli, security
issue の種類
バグ
難易度
4/5
見積もり時間
3〜5日
活発さ
停滞
明瞭さ
説明が足りない
初心者へのやさしさ
25/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。