github / github/codeql

False Positive: "Statement has no effect" on Airflow task chaining with >> operator

Open
#19,687 0 comments 0 reactions 0 assignees View on GitHub
false-positive
Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 15h
Merged PRs (30d)
141

Description

**Description of the false positive**

The CodeQL analysis is reporting a "Statement has no effect" false positive when using Apache Airflow's operator chaining syntax with >>. This is a valid and idiomatic way to declare task dependencies in Airflow DAGs, and these statements have clear side effects within the context of Airflow’s task graph construction.

**Code samples or links to source code**
The following is a minimal reproducible example using Apache Airflow:
```python
from airflow import DAG
from airflow.operators.empty import EmptyOperator
from datetime import datetime

with DAG("example_dag", start_date=datetime(2025, 6, 5), schedule_interval=None) as dag:
task_1 = EmptyOperator(task_id="task_1")
task_2 = EmptyOperator(task_id="task_2")
task_3 = EmptyOperator(task_id="task_3")
task_4 = EmptyOperator(task_id="task_4")

task_1 >> task_2 # CodeQL incorrectly flags this
task_2 >> [task_3, task_4] # CodeQL incorrectly flags this too
```

These lines are not no-op statements; they define execution order between tasks (task_1 precedes task_2, etc.). Removing them would break DAG functionality.

**URL to the alert on GitHub code scanning (optional)**
Code is proprietary.

**Suggested solution**
If possible, please provide a way to configure CodeQL to ignore `>>` operator overload on Airflow operator objects, which have intentional and important side effects.. Please note that this operator works only in DAG context manager (`with DAG(...) as dag:`).

If that's not feasible, then I would greatly appreciate help setting up custom CodeQL rule to ignore this false positive.

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the alert with the minimal Apache Airflow Python example in the issue. Read the CodeQL query and Python modeling related to the “Statement has no effect” alert, then determine how overloaded >> expressions are analyzed. Done means the Airflow task-chaining statements are no longer reported while genuine no-effect statements remain detectable.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
devtools, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.