github / github/codeql

False positive: Dereferenced variable may be null ignore NRT attributes

Offen
#20,828 2 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
C# false-positive
Vorherrschende Sprache
CodeQL
Sterne
10.1k
Forks
2.1k
Ø Merge
2 T. 15 Std.
Gemergte PRs (30 T.)
141

Beschreibung

**Description of the false positive**

NRT attributes appear to be ignored by CodeQL. This results in lots of noise as we have to explicitly mark each point of use as a false positive and so safe.

**Code samples or links to source code**

```cs
if (TryConvertContractState(tradingPhase, state, out Models.ContractState? contractState))
return contractState.Value;
```
when it is defined as:
```cs
private static bool TryConvertContractState(
string tradingPhase, string state,
[NotNullWhen(true)] out PersistedModels.ContractState? cdmState)
{}
```

**URL to the alert on GitHub code scanning (optional)**

Private Repo, but the view query source goes to: https://github.com/github/codeql/blob/aa3000df1310b332ba1c84afec3bacb0aeb4dbbd/csharp/ql/src/CSI/NullMaybe.ql

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Start with csharp/ql/src/CSI/NullMaybe.ql, the query source linked in the report, and review how it handles the C# sample using [NotNullWhen(true)]. Reproduce the reported alert with the provided TryConvertContractState example; done means the valid contractState.Value dereference is no longer reported as a nullability issue.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
csharp
Bereich
security
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Veraltet
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
38/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.