yoff

Results 46 comments of yoff

> As a different opt-in mechanism, we could have a command to run rather than a setting. Either would work fine for a user examining their code before submission. Yes,...

Interesting. There are a few instances of `Node has multiple PostUpdateNodes.` The rest are missing `toString`s.

Another alternative, which may amount to the same thing, is to say that importing the request object is not a case of remote input, but reading from it is. I...

It seems we have very few failure modes: - `Call should have one enclosing callable but has 0.` (Lots) - `Node steps to itself` (Lots) - `Store step does not...

> same problem as #1403 Ah, so updating should fix it.

As far as I can tell from the evaluation, it gets slightly more noisy, adding 21 alerts and losing 14. All of the added and lost alerts seem to be...

The `qhelp` file has an issue, see: https://github.com/github/codeql/actions/runs/8255777397/job/22602805894?pr=15319#step:7:25.

> One detail please, I've got this unusual error : > > ``` > Could not evaluate queries in /home/sim4n6/Desktop/GhSec/codeql-fork-final/python/ql/test/experimental/query-tests/Security/CWE-770: com.semmle.util.concurrent.UnhandledAsyncException: 1 asynchronous exceptions caught > A fatal error occurred:...

Test failures look good...in that you now catch two more bad results :-) So just update the expected file.