github / github/codeql

Java: Improve "Learning CodeQL" docs

未关闭
#3,903 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
Java question
主要语言
CodeQL
星标
10.1k
派生
2.1k
平均合并
2 天 15 小时
30 天内合并 PR
141

描述

# Description
The "Learning CodeQL" / "CodeQL for Java" docs could probably be improved.

**Important:** When changing any queries, make sure to update the respective query console link as well.

## `types-class-hierarchy.rst`
- Could probably use `NullType` instead of checking for name `""`
- Also ignore `Wildcard` because it causes some false positives, or check that upper bound is same type or supertype?

## `annotations.rst`
- `@SuppressWarnings` `value` is an array so not necessarily a Literal, should therefore probably use `Annotation.getAValue(string)`

## `call-graph.rst`
- Says that for singleton pattern private constructor is not being called, however this is incorrect because constructor is called to create the singleton instance; it probably means "utility classes"

## `expressions-statements.rst`
- Why extend `ComparisonExpr` and override `getGreaterOperand` and `getLesserOperand` instead of using them? Would then not require two separate subclasses

## `introduce-libraries-java.rst`
- Might not check method body correctly, it appears there are statments which are the child of a method, but not its body, see [this query](https://lgtm.com/query/4799496553177136320/). However, maybe that it a bug with the extractor, it appears some of the results are for files which exist multiple times for the projects.

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。