github / github/codeql-cli-binaries

CodeQL: Make any() expression and exists() formula variable identifier optional

Aberta
#53 4 comentários 0 reações 0 responsáveis Ver no GitHub
CLI Engine: Compiler and Optimiser enhancement QLIP
Linguagem predominante
Sem dados de linguagem
Estrelas
1k
Forks
184
Métricas de merge de PRs
Nenhum PR com merge em 30d

Descrição

What do you think about making the variable identifiers of the CodeQL [`any(...)` expression](https://codeql.github.com/docs/ql-language-reference/expressions/#any) and [`exists(...)` formula](https://codeql.github.com/docs/ql-language-reference/formulas/#exists) optional if they do not have any formulas?
Currently the CodeQL language specification requires an identifier even though it is not used.

Examples:
```ql
exists(GadgetClass unused) // Check whether a vulnerable "gadget" class exists on the class path
and any(CustomMethodCall unused).getArgument(0) instanceof CustomArgument
```
Here in both cases it is currently necessary to specify a variable identifier (`unused`), even though it is not used.

For the `exists` formula this could lead to some ambiguity because it currently allows using expressions (e.g. `exists(call.getAnArgument())`), however because type names as part of variable declarations cannot contain a period, this should be unambiguous.

Guia de contribuição

Abrir o guia de contribuição

Avaliação

Esta issue ainda não foi avaliada.

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.