github / github/codeql

gradle: False positives from generated code from the version catalog feature

未关闭
#14,530 3 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
false-positive
主要语言
CodeQL
星标
10.1k
派生
2.1k
平均合并
2 天 15 小时
30 天内合并 PR
141

描述

Using the version catalog feature of gradle () with the default `libs.versions.toml` file produces false positives such as:

> `.gradle/8.4/dependencies-accessors/1989acdfa2790571c9dc5975340ca543de5bf0a0/sources/org/gradle/accessors/dm/LibrariesForLibsInPluginsBlock.java:609`
> This method overrides `ProviderConvertible.asProvider;` it is advisable to add an Override annotation.

This is generated code and should not produce a warning (even if it's just at the *note* level)

Example source:
Corresponding alerts:

贡献指南

打开贡献指南

调研方向

Start by reproducing the warning from the generated Gradle path `.gradle/8.4/dependencies-accessors/.../LibrariesForLibsInPluginsBlock.java` using the linked `libs.versions.toml` example. Inspect the corresponding code-scanning alert and determine how generated sources are handled; done means the `ProviderConvertible.asProvider` warning no longer appears for this generated code.

由索引模型根据 Issue 内容生成。

评估

技术栈
java
领域
security
Issue 类型
缺陷
难度
4/5
预计耗时
3-5 天
活跃度
停滞
描述清晰度
基本清楚
新手友好度
35/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。