github / github/codeql

False positive for `go/incomplete-hostname-regexp` and `\Q`

未关闭
#15,894 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
false-positive Go
主要语言
CodeQL
星标
10.1k
派生
2.1k
平均合并
2 天 15 小时
30 天内合并 PR
141

描述

**Description of the false positive**

```go
var todoRE = regexp.MustCompile(`^// TODO (\Qhttps://github.com/FerretDB/\E([-\w]+)/issues/(\d+))$`)
```

That line is annotated with: "This regular expression has an unescaped dot before 'com', so it might match more hosts than expected when the regular expression is used."

What it misses is [`\Q...\E` escape syntax](https://pkg.go.dev/regexp/syntax).

**Code samples or links to source code**

https://github.com/FerretDB/FerretDB/blob/ea9c5bda8f3f80a9263e006995d4257084a600a5/tools/checkcomments/checkcomments.go#L32

**URL to the alert on GitHub code scanning (optional)**

https://github.com/FerretDB/FerretDB/security/code-scanning/9

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。