github / github/codeql

[False positive] `py/call-to-non-callable` on _decorated_ `__call__` magic methods

未关闭
#11,408 1 条评论 1 个 reaction 已指派 0 人 在 GitHub 查看
acknowledged false-positive not security Python
主要语言
CodeQL
星标
10.1k
派生
2.1k
平均合并
2 天 15 小时
30 天内合并 PR
141

描述

Hi there,

thanks a stack for bringing LGTM to CodeQL. We used your kickstart template PR https://github.com/crate/crash/pull/373 for making the transition happen on one of our Python repositories and wanted to report back about a potential false positive, after mitigating all other admonitions on our end before.

With kind regards,
Andreas.

**Description of the false positive**

`py/call-to-non-callable` is raised on _decorated_ `__call__` magic methods.

**Code samples or links to source code**

```python
class FooBarCommand(Command):

@noargs_command
def __call__(self, cmd, *args, **kwargs):
return f"{cmd}: foobar"
```

- There is a corresponding PR, including the offending code, in a repro repository at https://github.com/crate-workbench/codeql-evaluations/pull/3.

**URL to the alert on GitHub code scanning (optional)**

- https://github.com/crate/crash/security/code-scanning/5
- https://github.com/crate-workbench/codeql-evaluations/security/code-scanning/1

**Thoughts**

I wonder if anything can be done about it, other than manually dismissing corresponding admonitions? Do you have any other suggestions on this matter?

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。