Skip to content

v0.1.0

Choose a tag to compare

@github-actions github-actions released this 24 May 04:06
· 22 commits to main since this release

[0.1.0] — 2026-05-23 (Phase 1)

Added

  • .github/workflows/release.yml: triggered on v* tag pushes. Builds
    the extractor pack, packages it as codeql-extractor-nix-vX.Y.Z-linux64.tar.gz,
    pulls the matching CHANGELOG section as release notes, and creates a
    GitHub Release with the tarball as an asset.
  • ql/lib/codeql/nix/Scope.qll: lexical scope library porting deadnix's
    fixpoint scope analysis to QL. Exposes Scope, NameReference,
    resolvesTo, and isUnusedBinding predicates handling let-bindings,
    let-attrset bindings, function formals + universal, and inherit
    clauses (with correct outer-scope resolution for inherit name;).
  • ql/src/Security/CWE-563/UnusedBinding.ql: reports defined names
    that have no in-scope reference. Skips rec { } and the legacy
    let { body = …; }'s body attribute (both externally visible);
    exempts identifiers starting with _ (deadnix convention).
  • BuiltinsGetEnv.ql (CWE-807): flags builtins.getEnv and bare getEnv
    calls under with builtins; because they read the host environment during
    evaluation.
  • DeprecatedUriLiteral.ql (CWE-477): flags bare URI literals deprecated by Nix RFC 45 and recommends quoted strings.
  • ql/src/Security/CWE-829/UnpinnedImportFetch.ql (CWE-829, CWE-094): detects
    import of unpinned fetcher results, where network-controlled content is
    fetched and immediately evaluated as Nix code.
  • ql/src/Security/CWE-078/SpaceInFlagString.ql (plus qhelp and tests) to detect flag-list string literals with embedded whitespace that Bash word-splits into multiple argv entries.
  • RecAttrsetMerge.ql (CWE-665): warns when // merges a rec { ... }
    attrset, since recursive references do not see the merged result.
  • DuplicateAttrsetKey.ql (CWE-710): detects duplicate top-level keys in a single attrset literal before evaluation fails.
  • Phase 1 library expansion:
    • ql/lib/codeql/nix/Builtins.qll — BuiltinCall class recognising
      builtins.X invocations and (best-effort) bare X references
      under a with builtins; scope.
    • ql/lib/codeql/nix/Strings.qll — isListElementOfBinding(node, attrName)
      helper plus an isFlagListAttributeName allow-list of mkDerivation
      argv-style attributes.
    • Nix.qll: new aliases (LetExpression, LetAttrsetExpression,
      FunctionExpression, Formals, Formal, WithExpression,
      LookupPath, BareUriLiteral, BinaryExpression), plus
      hasInterpolation, indentedHasInterpolation, isLookupPath
      predicates.
  • NixPathLookup.ql (CWE-829): detects <...>-style search-path lookups
    that depend on the ambient $NIX_PATH.
  • CHANGELOG.md and CONTRIBUTING.md.
  • ql/src/Security/CWE-477/LegacyLetAttrset.ql (CWE-477): flags the deprecated
    legacy let { body = …; } attrset syntax and recommends modern
    let ... in ... instead.