forked from github/codeql
-
Notifications
You must be signed in to change notification settings - Fork 20
Jb1/ap1 maturity #315
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
bdrodes
wants to merge
58
commits into
main
Choose a base branch
from
jb1/ap1-maturity
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Jb1/ap1 maturity #315
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
…to a more precise ignorable operation analysis. Ignorable operations that flow to a possible source also invalidate that source. Also added a root source finder to get the earliest source if many exist. Modified the leap year checker finder to use a new dataflow mechanic that flows from a YearFieldAccess.
… constant being a literal, but a known value variable or literal.
… ignore certain opeartions. Also added an ignorable function class to be used to ignore operation sources.
…ure they are actually necessary or providing much utility.
…iewing the unit tests and conversations about how to handle some of the fp/fn cases observed. Updated the unit tests to use InlineExpectationsTestQuery.ql so it is easier to detect FP/FNs.
…eds to be generally reassessed but recent test changes alter the expected results.
… year, similar to what was done for month.
…anup. Updated expected file.
…a new false positive scenario currently unaccounted for in a new test case.
…se positive we currently do not have a solution for, marked as SPURIOUS.
… for handing mktime and other variants that convert the time automatically without the need for a check if the date is an incorrect leap year date.
ropwareJB
reviewed
Jan 30, 2026
ropwareJB
reviewed
Jan 30, 2026
cpp/ql/src/Likely Bugs/Leap Year/UncheckedLeapYearAfterYearModification.ql
Show resolved
Hide resolved
ropwareJB
reviewed
Jan 30, 2026
cpp/ql/src/Likely Bugs/Leap Year/UncheckedLeapYearAfterYearModification.ql
Show resolved
Hide resolved
ropwareJB
reviewed
Jan 30, 2026
cpp/ql/src/Likely Bugs/Leap Year/UncheckedLeapYearAfterYearModification.ql
Show resolved
Hide resolved
…ification.ql Co-authored-by: Josh Brown <jb1@microsoft.com>
…ification.ql Co-authored-by: Josh Brown <jb1@microsoft.com>
…ification.ql Co-authored-by: Josh Brown <jb1@microsoft.com>
ropwareJB
reviewed
Feb 2, 2026
cpp/ql/src/Likely Bugs/Leap Year/UncheckedLeapYearAfterYearModification.ql
Outdated
Show resolved
Hide resolved
ropwareJB
approved these changes
Feb 2, 2026
…ification.ql Co-authored-by: Josh Brown <jb1@microsoft.com>
…into jb1/ap1-maturity
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
False positive clean up for cpp/microsoft/public/leap-year/unchecked-after-arithmetic-year-modification.