github / github/codeql

[False positive] `py/call-to-non-callable` on _decorated_ `__call__` magic methods

未關閉
#11,408 1 則留言 1 個 reaction 已指派 0 人 在 GitHub 檢視
acknowledged false-positive not security Python
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

Hi there,

thanks a stack for bringing LGTM to CodeQL. We used your kickstart template PR https://github.com/crate/crash/pull/373 for making the transition happen on one of our Python repositories and wanted to report back about a potential false positive, after mitigating all other admonitions on our end before.

With kind regards,
Andreas.

**Description of the false positive**

`py/call-to-non-callable` is raised on _decorated_ `__call__` magic methods.

**Code samples or links to source code**

```python
class FooBarCommand(Command):

@noargs_command
def __call__(self, cmd, *args, **kwargs):
return f"{cmd}: foobar"
```

- There is a corresponding PR, including the offending code, in a repro repository at https://github.com/crate-workbench/codeql-evaluations/pull/3.

**URL to the alert on GitHub code scanning (optional)**

- https://github.com/crate/crash/security/code-scanning/5
- https://github.com/crate-workbench/codeql-evaluations/security/code-scanning/1

**Thoughts**

I wonder if anything can be done about it, other than manually dismissing corresponding admonitions? Do you have any other suggestions on this matter?

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。