Can I register complex sources/sinks/sanitizers entirely inside a custom CodeQL pack?
還沒有人認領這個 Issue。
評估
研究方向
檢查 java-all/lib 下 Java 目標對 Customizations.qll 的使用情況,然後檢查所參照的 qlpack.yml、模組配置以及外部 pack 的命名慣例。確定標準 taint 查詢是否使用外部 pack 中的模型,並記錄最低限度的支援配置或可維護的 workaround。
由索引模型根據 Issue 內容生成。
描述
Short background: I want to put all my custom taint modeling (complex QL predicates, annotation equivalence, sanitizers, and normal model files) into a single custom pack so teams can depend on it — without modifying standard / *-all libs.
Concrete example: in Java I have @CustomAnno and I want it treated exactly like Spring’s @RequestMapping (i.e. methods/classes with @CustomAnno are sources). I can do this in Customizations.qll inside java-all/lib, but I don’t want to change the standard lib.
Two short questions:
-
Is it supported to expose complex QL-based sources/sinks/sanitizers from an external pack so the standard taint queries pick them up? If yes — what minimal files/config (qlpack.yml / module layout / naming) are required?
-
If not supported, what is the recommended minimal workaround that keeps good maintainability?
Environment: Java target. I can attach a minimal repro pack if useful.
Thanks!
- 主要語言
- CodeQL
- 星號
- 10.1k
- 分支
- 2.1k
- 平均合併
- 2 天 16 小時
- 30 天內合併 PR
- 143
貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
github/codeql 的其他 Issue
-
agentic-workflows
難度 2/5 1-3 小時 新手友好度 70/100
-
false-positive javascript
難度 2/5 1-3 小時 新手友好度 84/100
-
難度 2/5 1-3 小時 新手友好度 82/100
-
難度 2/5 1-3 小時 新手友好度 78/100
-
false-positive
難度 2/5 1-3 小時 新手友好度 70/100
相似的 Issue
-
enhancement
難度 2/5 1-3 小時 新手友好度 70/100
canonical/paas-charm#368 · 1 則留言 ·
-
enhancement
難度 2/5 1-3 小時 新手友好度 75/100
palladius/rails8-app-on-gcp#142 ·
-
難度 1/5 1 小時以內 新手友好度 90/100
StevenBlack/hosts#3256 ·
-
難度 2/5 1-3 小時 新手友好度 75/100
corsairdev/corsair#1764 ·
-
oblt-aw/detector/security
難度 2/5 1-3 小時 新手友好度 70/100