github / github/codeql

Whether there are Python SDK for Programmatic Access to CodeQL Database Facts

Đang mở
#22,411 2 bình luận 0 reaction 0 người được giao Xem trên GitHub
question
Ngôn ngữ chính
CodeQL
Star
10.1k
Fork
2.1k
Merge trung bình
2 ngày 15 giờ
Pull request đã merge (30 ngày)
141

Mô tả

CodeQL provides powerful built-in analyses and program representations, such as AST, CFG, data flow, call graphs, and class hierarchies. However, these representations are currently primarily accessed through QL queries after a CodeQL database has been created.

For more complex analyses or for extending CodeQL's existing analyses (e.g., custom data-flow or alias analyses), implementing everything directly in QL can become quite difficult and cumbersome.

Currently, I use the following workaround:

- Build a CodeQL database for the target project.
- Write basic QL queries to export selected facts to CSV., such as:
* Interested AST nodes and their relationships
* Class/interface information and inheritance relationships
* Call sites and call relationships
* Other program facts relevant to my analysis

Define my own schema and load the CSV facts into memory.
Implement more sophisticated analyses using Python and custom algorithms.

This works, but it requires an additional export/import layer and also means that I have to manually reconstruct program representations that CodeQL already maintains internally. Would it be possible to provide an official Python SDK/API (or another programmatic API) that allows users to directly access the facts stored in a CodeQL database?

For example, something along the lines of:

```python
db = codeql.Database("my-project-db")

ast = db.ast()
cfg = db.cfg()
dataflow = db.dataflow()
classes = db.class_hierarchy()
calls = db.call_graph()
```

The exact API is not important; the key idea is that Python code could directly access the program facts represented in the CodeQL database, without first exporting them through QL queries. This would make it possible to use CodeQL as a powerful program representation and fact extraction backend, while implementing more complex or experimental analyses in Python.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

No files, tests, or entry points are named. Start by reviewing the existing CodeQL database and QL-query interfaces, then compare them with the proposed Python access model and the current CSV export/import workaround. Done would require an agreed API scope and an implementation plan, rather than a localized change.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
python
Lĩnh vực
developer-experience, tooling
Loại issue
Tính năng
Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức độ hoạt động
Sôi nổi
Độ rõ ràng
Cần làm rõ
Mức phù hợp với người mới
25/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.