github / github/codeql

False positive – "Statement has no effect" for Python type hint ellipsis

Offen
#11,351 7 Kommentare 7 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
false-positive
Vorherrschende Sprache
CodeQL
Sterne
10.1k
Forks
2.1k
Ø Merge
2 T. 15 Std.
Gemergte PRs (30 T.)
141

Beschreibung

**Description of the false positive**

The ellipsis `...` (three dots) is commonly used in Python to omit bodies for type hinting declarations. Since technically a lone `...` is an expression statement, LGTM/CodeQL marks it as a statement without effect.

For example, we could have something like this:
```
@overload
def some_func(a: float) -> str:
... # body is omitted since this is just for type hinting

@overload
def some_func(a: int) -> int:
...

def some_func(a):
return a if isinstance(a, int) else str(a)
```
In this case, both `@overload` definitions exist only for type hinting. Only the final definition is actually executable at runtime. *Emitting a warning for the type hint bodies is misleading;* they have no effect on purpose.

Roughly, it *should* be fine to suppress the warning for `def` blocks if:
- the *entire* body is `...`
- it is in a type-declaration context such as `@overload` or `Protocol`

See [PEP 8](https://peps.python.org/pep-0008/#other-recommendations) on "Function annotations …" for reference.

**Code samples or links to source code**

https://github.com/maxfischer2781/asyncstdlib/blob/b4b3a557bf7d0c411495d9fd7bd8e8f500ab6b97/asyncstdlib/builtins.py#L328-L335

https://github.com/maxfischer2781/asyncstdlib/blob/57f372b3ea8367b9cb448647664e582e783e4e75/asyncstdlib/_lrucache.py#L77-L79

**URL to the alert on GitHub code scanning (optional)**

https://github.com/maxfischer2781/asyncstdlib/security/code-scanning/33

https://github.com/maxfischer2781/asyncstdlib/security/code-scanning/98

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.