github / github/codeql

How can I use codeql cli without metadata?

未关闭
#14,872 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
question
主要语言
CodeQL
星标
10.1k
派生
2.1k
平均合并
2 天 15 小时
30 天内合并 PR
141

描述

This is a snippets from codeql's example:

```
/**
* @id java/examples/method-call
* @name Call to method
* @description Finds calls to com.example.Class.methodName
* @tags call
* method
*/

import java

from MethodAccess call, Method method
where
call.getMethod() = method and
method.hasName("methodName") and
method.getDeclaringType().hasQualifiedName("com.example", "Class")
select call, method
```

When I try to run it, codeql give me this error

```
Error was: Cannot process query metadata for a query without the '@kind' metadata property. To learn more, see https://codeql.github.com/docs/writing-codeql-queries/metadata-for-codeql-queries/ [NO_KIND_SPECIFIED]
```

I understand that this is because I didn't add a `@kind` in the metadata. So I added ` @kind problem` and received a new error:

```
Error was: Expected result pattern(s) are not present for problem query: Expected at least 2 columns. [INVALID_RESULT_PATTERNS]
```

My problem is: I don't care about the metadata at all. I just want to use it like a database query and I just want to get the raw result as a csv file.

Is there anyway that I can draft my own query without bothering the metadata?

贡献指南

打开贡献指南

调研方向

Start with the example query, the reported metadata errors, and the linked metadata documentation. Check the CodeQL CLI documentation for query execution and CSV output to determine whether metadata can be bypassed. Done means documenting the supported raw-result workflow or clearly explaining the limitation and required query metadata.

由索引模型根据 Issue 内容生成。

评估

领域
cli, security
Issue 类型
文档
难度
3/5
预计耗时
1-2 天
活跃度
停滞
描述清晰度
基本清楚
新手友好度
35/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。