github / github/codeql

False Positive: "Statement has no effect" on Airflow task chaining with >> operator

Offen
#19,687 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
false-positive
Vorherrschende Sprache
CodeQL
Sterne
10.1k
Forks
2.1k
Ø Merge
2 T. 15 Std.
Gemergte PRs (30 T.)
141

Beschreibung

**Description of the false positive**

The CodeQL analysis is reporting a "Statement has no effect" false positive when using Apache Airflow's operator chaining syntax with >>. This is a valid and idiomatic way to declare task dependencies in Airflow DAGs, and these statements have clear side effects within the context of Airflow’s task graph construction.

**Code samples or links to source code**
The following is a minimal reproducible example using Apache Airflow:
```python
from airflow import DAG
from airflow.operators.empty import EmptyOperator
from datetime import datetime

with DAG("example_dag", start_date=datetime(2025, 6, 5), schedule_interval=None) as dag:
task_1 = EmptyOperator(task_id="task_1")
task_2 = EmptyOperator(task_id="task_2")
task_3 = EmptyOperator(task_id="task_3")
task_4 = EmptyOperator(task_id="task_4")

task_1 >> task_2 # CodeQL incorrectly flags this
task_2 >> [task_3, task_4] # CodeQL incorrectly flags this too
```

These lines are not no-op statements; they define execution order between tasks (task_1 precedes task_2, etc.). Removing them would break DAG functionality.

**URL to the alert on GitHub code scanning (optional)**
Code is proprietary.

**Suggested solution**
If possible, please provide a way to configure CodeQL to ignore `>>` operator overload on Airflow operator objects, which have intentional and important side effects.. Please note that this operator works only in DAG context manager (`with DAG(...) as dag:`).

If that's not feasible, then I would greatly appreciate help setting up custom CodeQL rule to ignore this false positive.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Beginne damit, den Alert mit dem minimalen Apache Airflow-Python-Beispiel im Issue zu reproduzieren. Lies die CodeQL-Abfrage und die Python-Modellierung im Zusammenhang mit dem Alert „Statement has no effect“ und ermittle anschließend, wie überladene >>-Ausdrücke analysiert werden. Die Aufgabe ist abgeschlossen, wenn die Task-Verkettungsausdrücke von Airflow nicht mehr gemeldet werden, während echte Ausdrücke ohne Effekt weiterhin erkennbar bleiben.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
python
Bereich
devtools, security
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Veraltet
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
45/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.