github / github/codeql-cli-binaries

Cannot access CodeQL environment variables in `database create --command`

Ouverte
#2 4 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
CLI
Langage dominant
Aucune donnée de langage
Étoiles
1k
Forks
184
Métriques de merge des PR
Aucune PR mergée en 30 j

Description

I would like to explicitly invoke the JavaScript autobuilder as part of `codeql database create`, with the ultimate goal of passing it some custom options. However, even invoking it without any options isn't as easy as I would have hoped, since I cannot figure out how to access CodeQL environment variables to specify the path to the autobuilder.

My first attempt of

```sh
codeql database create -l javascript --command '${CODEQL_EXTRACTOR_JAVASCRIPT_ROOT}/tools/autobuild.sh /path/to/database
```

was met with

```sh
A fatal error occurred: Failed to expand '${CODEQL_EXTRACTOR_JAVASCRIPT_ROOT}/tools/autobuild.sh' as an argument list.
(eventual cause: UserError "Attempting to expand unknown variable: CODEQL_EXTRACTOR_JAVASCRIPT_ROOT, available variables are: []")
```

@lcartey suggested adding `env.` like so:

```sh
codeql database create -l javascript --command '${env.CODEQL_EXTRACTOR_JAVASCRIPT_ROOT}/tools/autobuild.sh' /path/to/database
```

but that resulted in

```
A fatal error occurred: Failed to expand '${env.CODEQL_EXTRACTOR_JAVASCRIPT_ROOT}/tools/autobuild.sh' as an argument list.
(eventual cause: UserError "Attempting to expand unknown variable: env.CODEQL_EXTRACTOR_JAVASCRIPT_ROOT, ava...")
```

I am pretty sure this is the right environment variable name, cf. [here](https://git.semmle.com/Semmle/code/blob/master/language-packs/javascript/tools/autobuild.sh#L28).

Specifying the full path to the autobuild script is, of course, possible, but annoying.

Guide de contribution

Ouvrir le guide de contribution

Piste de recherche

Start with the `codeql database create --command` entry point and its argument-variable expansion, using the reported `CODEQL_EXTRACTOR_JAVASCRIPT_ROOT` and `env.` examples as reproduction cases. Trace why the command environment is unavailable during expansion; done when the JavaScript autobuilder path can be supplied through the CodeQL environment variable and the behavior is covered by an appropriate test.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
javascript, shell
Domaine
cli
Type d'issue
Bug
Difficulté
4/5
Temps estimé
3-5 jours
Activité
À l'abandon
Clarté
Plutôt claire
Accessibilité débutants
35/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.