github / github/codeql

LGTM.com - false positive: not all domains are in URLs

Open
#3,153 0 comments 0 reactions 0 assignees View on GitHub
false-positive Python
Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 15h
Merged PRs (30d)
141

Description

**Description of the false positive**

It says "'kopf.zalando.org/' may be at an arbitrary position in the sanitized URL."

Code snippet (a part of https://github.com/zalando-incubator/kopf/pull/331):

```python
annotations = essence.get('metadata', {}).get('annotations', {})
for annotation in list(annotations):
if annotation == LAST_SEEN_ANNOTATION:
del annotations[annotation]
elif annotation.startswith('kopf.zalando.org/'):
del annotations[annotation]
elif annotation == 'kubectl.kubernetes.io/last-applied-configuration':
del annotations[annotation]
```

Here, `kopf.zalando.org/` is NOT a URL, not is a namespace according to Kubernetes's (and not only) convention to use domains as namespaces.

**URL to the alert on the project page on LGTM.com**

* https://lgtm.com/projects/g/zalando-incubator/kopf/snapshot/4f667550c166a7746f07520c4c382ce124617eb4/files/kopf/storage/diffbase.py?sort=name&dir=ASC&mode=heatmap#x8ea36093c73ed5c5:1

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.