github / github/codeql

LGTM.com - false positive - Java implicit cast in compound assignment for constants

オープン
#2,842 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る
false-positive Java
主要言語
CodeQL
スター
10.1k
フォーク
2.1k
平均マージ
2日 15時間
マージ済み PR(30日)
141

説明

**Description of the false positive**
The query `java/implicit-cast-in-compound-assignment` incorrectly flags compound statements with numeric literals within the value range of the target type. E.g.:
```
byte b = 1;
b *= 10; // Incorrectly flagged even though it is safe
```

Side note: Literals which exceed the value range should probably be even flagged as error (instead of warning):
```
byte b = 1;
b += 0xFF; // Exceeds 127, but is still in unsigned value range, might be intended: Ok
b += 256; // Very likely not intended: Error
```

Also why doesn't `java/implicit-cast-in-compound-assignment` cover all (arithmetic) compound assignments instead of only addition and multiplication?

**URL to the alert on the project page on LGTM.com**
https://lgtm.com/projects/g/apache/hive/snapshot/48856d424acd0be5fd4e911bbdabd9483a6fb39e/files/ql/src/java/org/apache/hadoop/hive/ql/udf/generic/GenericUDFMaskFirstN.java?sort=name&dir=ASC&mode=heatmap#x348d57efee59c05:1

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。