github / github/codeql

LGTM.com - false positive - unused import + eval

Đang mở
#2,292 0 bình luận 0 reaction 0 người được giao Xem trên GitHub
false-positive Python
Ngôn ngữ chính
CodeQL
Star
10.1k
Fork
2.1k
Merge trung bình
2 ngày 15 giờ
Pull request đã merge (30 ngày)
141

Mô tả

**Description of the false positive**

The import is not unused. If I delete it, I get the error

```
Traceback (most recent call last):
File "examples/bootstrap.py", line 53, in
app.layout = html.Div([navbar.run(), body.run()])
File "/Users/jks/code/htexpr/htexpr/htexpr.py", line 88, in run
return eval(self.code, {**frame.f_globals, **frame.f_locals, **bindings})
File "", line 1, in
NameError: name 'dcc' is not defined
```

The point of this liibrary is that it compiles strings into Python code objects, which are then evaluated. This is probably difficult to analyze statically without executing the code, so I wouldn't assign a high priority to this, but since the page asked me to report false positives, here goes.

**URL to the alert on the project page on LGTM.com**

https://lgtm.com/projects/g/jkseppan/htexpr/snapshot/4e3172505e73dfbb54169f9906460b17b5a10260/files/examples/bootstrap.py?sort=name&dir=ASC&mode=heatmap#x64fc00e52918b221:1

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.