github / github/codeql

gradle: False positives from generated code from the version catalog feature

Open
#14,530 3 comments 0 reactions 0 assignees View on GitHub
false-positive
Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 15h
Merged PRs (30d)
141

Description

Using the version catalog feature of gradle () with the default `libs.versions.toml` file produces false positives such as:

> `.gradle/8.4/dependencies-accessors/1989acdfa2790571c9dc5975340ca543de5bf0a0/sources/org/gradle/accessors/dm/LibrariesForLibsInPluginsBlock.java:609`
> This method overrides `ProviderConvertible.asProvider;` it is advisable to add an Override annotation.

This is generated code and should not produce a warning (even if it's just at the *note* level)

Example source:
Corresponding alerts:

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.