github / github/codeql

LGTM.com - false positive - Java implicit cast in compound assignment for constants

未關閉
#2,842 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
false-positive Java
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

**Description of the false positive**
The query `java/implicit-cast-in-compound-assignment` incorrectly flags compound statements with numeric literals within the value range of the target type. E.g.:
```
byte b = 1;
b *= 10; // Incorrectly flagged even though it is safe
```

Side note: Literals which exceed the value range should probably be even flagged as error (instead of warning):
```
byte b = 1;
b += 0xFF; // Exceeds 127, but is still in unsigned value range, might be intended: Ok
b += 256; // Very likely not intended: Error
```

Also why doesn't `java/implicit-cast-in-compound-assignment` cover all (arithmetic) compound assignments instead of only addition and multiplication?

**URL to the alert on the project page on LGTM.com**
https://lgtm.com/projects/g/apache/hive/snapshot/48856d424acd0be5fd4e911bbdabd9483a6fb39e/files/ql/src/java/org/apache/hadoop/hive/ql/udf/generic/GenericUDFMaskFirstN.java?sort=name&dir=ASC&mode=heatmap#x348d57efee59c05:1

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。