github / github/codeql-cli-binaries

Running CodeQL within a Flask server silently interrupts connection

Aberta
#132 2 comentários 1 reação 0 responsáveis Ver no GitHub
CLI
Linguagem predominante
Sem dados de linguagem
Estrelas
1k
Forks
184
Métricas de merge de PRs
Nenhum PR com merge em 30d

Descrição

I have extended the [official CodeQL container](https://github.com/microsoft/codeql-container) to run CodeQL analysis during a Python Flask HTTP request.

Throughout the request, three codeql CLI commands are executed:

```
codeql database create
codeql database upgrade
codeql database analyze
```

create and upgrade do not interrupt the connection, but I find that when the analyze command occurs, Flask will respond as normal but the client never receives the response. Leading me to believe something within the analyze command is silently interrupting the connection.

The python code I'm using uses the Python code found in the official CodeQL Docker container. Here is the code I'm running within the request:

```python
database_update_command = f"database upgrade {database_directory}"
database_analyze_command = f"database analyze {database_directory} --threads=0 --format=sarifv2.1.0 --output=output.json {database_lang}-security-and-quality.qls"
run_result = self.codeql.execute_codeql_command(
database_update_command)
run_result = self.codeql.execute_codeql_command(
database_analyze_command)
```

Any help would be appreciated!

Guia de contribuição

Abrir o guia de contribuição

Direção de pesquisa

Reproduce the Flask request using the three CodeQL CLI commands, especially database analyze, and inspect the Python execute_codeql_command call and its output handling. Compare analyze with database create and database upgrade to isolate why the client receives no response; done means identifying the interruption and documenting or fixing the integration.

Escrita pelo modelo de indexação a partir do texto da issue.

Avaliação

Stack de tecnologia
docker, flask, python
Domínio
backend, cli, security
Tipo de issue
Bug
Dificuldade
4/5
Tempo estimado
3-5 dias
Status de atividade
Estagnada
Clareza
Precisa de esclarecimento
Facilidade para iniciantes
25/100

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.