github / github/codeql

LGTM.com - false positive - Java implicit cast in compound assignment for constants

未关闭
#2,842 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
false-positive Java
主要语言
CodeQL
星标
10.1k
派生
2.1k
平均合并
2 天 15 小时
30 天内合并 PR
141

描述

**Description of the false positive**
The query `java/implicit-cast-in-compound-assignment` incorrectly flags compound statements with numeric literals within the value range of the target type. E.g.:
```
byte b = 1;
b *= 10; // Incorrectly flagged even though it is safe
```

Side note: Literals which exceed the value range should probably be even flagged as error (instead of warning):
```
byte b = 1;
b += 0xFF; // Exceeds 127, but is still in unsigned value range, might be intended: Ok
b += 256; // Very likely not intended: Error
```

Also why doesn't `java/implicit-cast-in-compound-assignment` cover all (arithmetic) compound assignments instead of only addition and multiplication?

**URL to the alert on the project page on LGTM.com**
https://lgtm.com/projects/g/apache/hive/snapshot/48856d424acd0be5fd4e911bbdabd9483a6fb39e/files/ql/src/java/org/apache/hadoop/hive/ql/udf/generic/GenericUDFMaskFirstN.java?sort=name&dir=ASC&mode=heatmap#x348d57efee59c05:1

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。