github / github/codeql-cli-binaries

CodeQL: Make any() expression and exists() formula variable identifier optional

Abierto
#53 4 comentarios 0 reacciones 0 asignados Ver en GitHub
CLI Engine: Compiler and Optimiser enhancement QLIP
Lenguaje dominante
Sin datos de lenguaje
Estrellas
1k
Forks
184
Métricas de merge de PR
Sin PR fusionados en 30 d

Descripción

What do you think about making the variable identifiers of the CodeQL [`any(...)` expression](https://codeql.github.com/docs/ql-language-reference/expressions/#any) and [`exists(...)` formula](https://codeql.github.com/docs/ql-language-reference/formulas/#exists) optional if they do not have any formulas?
Currently the CodeQL language specification requires an identifier even though it is not used.

Examples:
```ql
exists(GadgetClass unused) // Check whether a vulnerable "gadget" class exists on the class path
and any(CustomMethodCall unused).getArgument(0) instanceof CustomArgument
```
Here in both cases it is currently necessary to specify a variable identifier (`unused`), even though it is not used.

For the `exists` formula this could lead to some ambiguity because it currently allows using expressions (e.g. `exists(call.getAnArgument())`), however because type names as part of variable declarations cannot contain a period, this should be unambiguous.

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.