CodeQL fails to detect rust/insecure-cookie in Rust code

未关闭
#3,915 6 条评论 3 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
3/5
预计耗时
1-2 天
新手友好度
48/100
Issue 类型
缺陷
描述清晰度
基本清楚
活跃度
冷清
技术栈
rust
领域
security

调研方向

使用最小 Rust 项目和文档中的代码示例重现该问题,然后运行所示的 codeql database createcodeql database analyze 命令。检查 codeql.sarif,并将其结果与预期的 rust/insecure-cookie finding 进行比较;当 finding 被输出时即表示完成。

由索引模型根据 Issue 内容生成。

描述

Steps to reproduce

  • Download latest CodeQL bundle (v2.25.4 at the moment).
  • Have a minimal Rust project with rust/insecure-cookie in it (take the code example from the official documentation).
  • Run the following command in the directory with the Rust project:
codeql database create --build-mode=none --language=rust .codeql-db
codeql database analyze --format=sarifv2.1.0 --output=codeql.sarif .codeql-db
  • Look at the produced codeql.sarif

Expected behavior

results field should have 1 finding with rust/insecure-cookie id.

Actual behavior

results field is empty

Notes

The same codeql version with the same Rust code worked as expected on May 18, 2026, 2:31 PM GMT+9.

主要语言
TypeScript
星标
1.6k
派生
493
平均合并
1 天 13 小时
30 天内合并 PR
44

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

github/codeql-action 的其他 Issue

查看 github/codeql-action 的全部 Issue

相似的 Issue

更多 TypeScript Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。