github / github/codeql

Java: Improve "Learning CodeQL" docs

未關閉
#3,903 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
Java question
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

# Description
The "Learning CodeQL" / "CodeQL for Java" docs could probably be improved.

**Important:** When changing any queries, make sure to update the respective query console link as well.

## `types-class-hierarchy.rst`
- Could probably use `NullType` instead of checking for name `""`
- Also ignore `Wildcard` because it causes some false positives, or check that upper bound is same type or supertype?

## `annotations.rst`
- `@SuppressWarnings` `value` is an array so not necessarily a Literal, should therefore probably use `Annotation.getAValue(string)`

## `call-graph.rst`
- Says that for singleton pattern private constructor is not being called, however this is incorrect because constructor is called to create the singleton instance; it probably means "utility classes"

## `expressions-statements.rst`
- Why extend `ComparisonExpr` and override `getGreaterOperand` and `getLesserOperand` instead of using them? Would then not require two separate subclasses

## `introduce-libraries-java.rst`
- Might not check method body correctly, it appears there are statments which are the child of a method, but not its body, see [this query](https://lgtm.com/query/4799496553177136320/). However, maybe that it a bug with the extractor, it appears some of the results are for files which exist multiple times for the projects.

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。