github / github/codeql

False positive – "Statement has no effect" for Python type hint ellipsis

Abierto
#11,351 7 comentarios 7 reacciones 0 asignados Ver en GitHub
false-positive
Lenguaje dominante
CodeQL
Estrellas
10.1k
Forks
2.1k
Merge medio
2 d 15 h
PR fusionados (30 d)
141

Descripción

**Description of the false positive**

The ellipsis `...` (three dots) is commonly used in Python to omit bodies for type hinting declarations. Since technically a lone `...` is an expression statement, LGTM/CodeQL marks it as a statement without effect.

For example, we could have something like this:
```
@overload
def some_func(a: float) -> str:
... # body is omitted since this is just for type hinting

@overload
def some_func(a: int) -> int:
...

def some_func(a):
return a if isinstance(a, int) else str(a)
```
In this case, both `@overload` definitions exist only for type hinting. Only the final definition is actually executable at runtime. *Emitting a warning for the type hint bodies is misleading;* they have no effect on purpose.

Roughly, it *should* be fine to suppress the warning for `def` blocks if:
- the *entire* body is `...`
- it is in a type-declaration context such as `@overload` or `Protocol`

See [PEP 8](https://peps.python.org/pep-0008/#other-recommendations) on "Function annotations …" for reference.

**Code samples or links to source code**

https://github.com/maxfischer2781/asyncstdlib/blob/b4b3a557bf7d0c411495d9fd7bd8e8f500ab6b97/asyncstdlib/builtins.py#L328-L335

https://github.com/maxfischer2781/asyncstdlib/blob/57f372b3ea8367b9cb448647664e582e783e4e75/asyncstdlib/_lrucache.py#L77-L79

**URL to the alert on GitHub code scanning (optional)**

https://github.com/maxfischer2781/asyncstdlib/security/code-scanning/33

https://github.com/maxfischer2781/asyncstdlib/security/code-scanning/98

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.