github / github/codeql

[False positive] `py/call-to-non-callable` on _decorated_ `__call__` magic methods

オープン
#11,408 コメント 1 件 リアクション 1 件 担当者 0 名 GitHub で見る
acknowledged false-positive not security Python
主要言語
CodeQL
スター
10.1k
フォーク
2.1k
平均マージ
2日 15時間
マージ済み PR(30日)
141

説明

Hi there,

thanks a stack for bringing LGTM to CodeQL. We used your kickstart template PR https://github.com/crate/crash/pull/373 for making the transition happen on one of our Python repositories and wanted to report back about a potential false positive, after mitigating all other admonitions on our end before.

With kind regards,
Andreas.

**Description of the false positive**

`py/call-to-non-callable` is raised on _decorated_ `__call__` magic methods.

**Code samples or links to source code**

```python
class FooBarCommand(Command):

@noargs_command
def __call__(self, cmd, *args, **kwargs):
return f"{cmd}: foobar"
```

- There is a corresponding PR, including the offending code, in a repro repository at https://github.com/crate-workbench/codeql-evaluations/pull/3.

**URL to the alert on GitHub code scanning (optional)**

- https://github.com/crate/crash/security/code-scanning/5
- https://github.com/crate-workbench/codeql-evaluations/security/code-scanning/1

**Thoughts**

I wonder if anything can be done about it, other than manually dismissing corresponding admonitions? Do you have any other suggestions on this matter?

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。