Upgrade github/codeql dependency to 2.22.4 - #1184
Conversation
Update expected test results after frontend update
Update MISRA queries and tests after merging location tables
C++: accept new test results after QL changes
Observe that `sizeof(...)` might not occur as a dataflow node if it has a parent node with a concrete value. That value will be a dataflow node instead. Hence, the query has be changed to check for expressions where `sizeof(...)` is a child of an expression with a concrete value.
Note that we now properly report the offending cast instead of the expression that is being cast.
As it is the dataflow used by `asctime` that is relevant, and not the pointer, use the indirect expression.
Convert a number of queries to use the new dataflow library
Update expected test results for MSC33-C
These use the new dataflow library
Since the new dataflow library uses use-use dataflow and not def-use dataflow, we now need to check for definitions. Note that these queries can probably be improved by using a dataflow configuration - possibly limited to the local context of a function by including `DataFlow::FeatureEqualSourceSinkCallContext`
… new dataflow library
…taflow library
Note this introduces some new results. This seems to be correct, as before the
update the query seemed to have missed problems with code like the following:
```cpp
void f3(int *v1) {
int *v2 = v1;
std::shared_ptr<int> p1(v1); // NON_COMPLIANT
new std::shared_ptr<int>(p1.get()); // NON_COMPLIANT
new std::shared_ptr<int>(v2); // NON_COMPLIANT
}
void f4() {
f3(new int(0));
}
```
…w library Note that this removes - what seems to be - a duplicated test result.
Note that there's a small issue here where the dataflow library causes one of the results to get duplicated.
Update more queries to the new dataflow library
|
/test-performance |
|
🏁 Beep Boop! Performance testing for this PR has been initiated. Please check back later for results. Note that the query package generation step must complete before testing will start so it might be a minute. |
|
🏁 Beep Boop! One or things failed during performance testing. Please check the release engineering repo for details. |
|
/test-performance |
|
🏁 Beep Boop! Performance testing for this PR has been initiated. Please check back later for results. Note that the query package generation step must complete before testing will start so it might be a minute. |
|
/test-performance |
|
🏁 Beep Boop! Performance testing for this PR has been initiated. Please check back later for results. Note that the query package generation step must complete before testing will start so it might be a minute. |
This PR upgrades the CodeQL CLI version to 2.22.4.
CodeQL dependency upgrade checklist:
github/codeqltest cases succeed.github/codeql-coding-standardsrepository.