[Python][Questions] CodeQL security query is not able to detect CWE from given bad example in repository.
Abierto
question
- Lenguaje dominante
- CodeQL
- Estrellas
- 10.1k
- Forks
- 2.1k
- Merge medio
- 2 d 15 h
- PR fusionados (30 d)
- 141
Descripción
I have created codeql database of this python file [https://github.com/github/codeql/blob/main/python/ql/src/Security/CWE-022/examples/tarslip_bad.py](https://github.com/github/codeql/blob/main/python/ql/src/Security/CWE-022/examples/tarslip_bad.py).
But when I analyze database using [https://github.com/github/codeql/blob/main/python/ql/src/Security/CWE-022/TarSlip.ql](https://github.com/github/codeql/blob/main/python/ql/src/Security/CWE-022/TarSlip.ql) this query, I see nothing in query results.
Can someone help me why codeql query is not able to detect CWE-22 from the given example?
Guía de contribución
Evaluación
Este issue todavía no se ha evaluado.