github / github/codeql

False Positive: "Statement has no effect" on Airflow task chaining with >> operator

Ouverte
#19,687 0 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
false-positive
Langage dominant
CodeQL
Étoiles
10.1k
Forks
2.1k
Merge moyen
2 j 15 h
PR mergées (30 j)
141

Description

**Description of the false positive**

The CodeQL analysis is reporting a "Statement has no effect" false positive when using Apache Airflow's operator chaining syntax with >>. This is a valid and idiomatic way to declare task dependencies in Airflow DAGs, and these statements have clear side effects within the context of Airflow’s task graph construction.

**Code samples or links to source code**
The following is a minimal reproducible example using Apache Airflow:
```python
from airflow import DAG
from airflow.operators.empty import EmptyOperator
from datetime import datetime

with DAG("example_dag", start_date=datetime(2025, 6, 5), schedule_interval=None) as dag:
task_1 = EmptyOperator(task_id="task_1")
task_2 = EmptyOperator(task_id="task_2")
task_3 = EmptyOperator(task_id="task_3")
task_4 = EmptyOperator(task_id="task_4")

task_1 >> task_2 # CodeQL incorrectly flags this
task_2 >> [task_3, task_4] # CodeQL incorrectly flags this too
```

These lines are not no-op statements; they define execution order between tasks (task_1 precedes task_2, etc.). Removing them would break DAG functionality.

**URL to the alert on GitHub code scanning (optional)**
Code is proprietary.

**Suggested solution**
If possible, please provide a way to configure CodeQL to ignore `>>` operator overload on Airflow operator objects, which have intentional and important side effects.. Please note that this operator works only in DAG context manager (`with DAG(...) as dag:`).

If that's not feasible, then I would greatly appreciate help setting up custom CodeQL rule to ignore this false positive.

Guide de contribution

Ouvrir le guide de contribution

Piste de recherche

Start by reproducing the alert with the minimal Apache Airflow Python example in the issue. Read the CodeQL query and Python modeling related to the “Statement has no effect” alert, then determine how overloaded >> expressions are analyzed. Done means the Airflow task-chaining statements are no longer reported while genuine no-effect statements remain detectable.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
python
Domaine
devtools, security
Type d'issue
Bug
Difficulté
4/5
Temps estimé
3-5 jours
Activité
À l'abandon
Clarté
Plutôt claire
Accessibilité débutants
45/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.