github / github/codeql

General issue - RandonUsedOnce.ql treated as a critical security issue

Open
#7,601 2 comments 0 reactions 0 assignees View on GitHub
question
Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 15h
Merged PRs (30d)
141

Description

**Description of the issue**
The following query is reported in Github alerts as a Critical severity security issue (with a severity of 9.8).
However there is no 'security' tag.

The impact is that other tools (e.g. LGTM) that parse the query differently do not treat this as a security issue. Can this be clarified?

https://github.com/github/codeql/blob/main/java/ql/src/Likely%20Bugs/Arithmetic/RandomUsedOnce.ql

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.