Skip to content

v0.3.0

Latest

Choose a tag to compare

@github-actions github-actions released this 25 May 03:42
· 5 commits to main since this release

[0.3.0] — 2026-05-25 (Phase 3a)

Added

  • ql/lib/codeql/nix/Derivation.qll: recognises calls to nixpkgs-style
    derivation wrappers (stdenv.mkDerivation, stdenvNoCC.mkDerivation,
    buildPythonPackage, buildPythonApplication — faithful to
    nixpkgs-hammering's scope) and exposes getKind, getAttrs,
    hasAttr, getDirectBinding, getADirectBinding, and
    getNthAttrName. getAttrs peels through parens, the
    (finalAttrs: { … }) callback shape, and let … in { … } bodies.
    Foundation for the Phase 3a nixpkgs-hammering-port queries.
  • ql/test/library-tests/Derivation/: library-level test covering 12
    derivation-call shapes including callback, callback+rec, callback+let,
    parens, plain rec, both Python wrappers, and inherit / inherit-from
    cases.
  • ql/src/Security/CWE-1078/MesonAndCmake.ql (plus qhelp and
    ql/test/queries/CodeQuality/MesonAndCmake/): ports
    nixpkgs-hammering's meson-cmake rule. Flags derivations whose
    nativeBuildInputs declare both meson and cmake, where nixpkgs
    convention is to pick one primary configure-phase build system.
  • ql/src/Security/CWE-1078/NameInsteadOfPnameVersion.{ql,qhelp}: ports
    nixpkgs-hammering's name-and-version rule, flagging derivations that
    set name and version without pname; includes a CodeQuality qltest
    fixture covering direct, inherit, callback, and buildPythonPackage
    forms.
  • ql/src/Security/CWE-1078/ExplicitPhases.ql plus qhelp and query tests:
    ports nixpkgs-hammering's explicit-phases rule, reporting direct
    overrides of configurePhase, buildPhase, checkPhase, and
    installPhase while leaving hook-based customization and unrelated
    phases to their dedicated rules.
  • ql/src/Security/CWE-1078/ProtectedPhaseOverride.ql (plus qhelp and
    ql/test/queries/CodeQuality/ProtectedPhaseOverride/): ports
    nixpkgs-hammering's fixup-phase and patch-phase rules. Flags
    derivations that override fixupPhase or patchPhase directly
    instead of extending the default phase with pre* / post* hooks.
  • ql/src/Security/CWE-1078/MissingPhaseHooks.ql (plus qhelp and
    ql/test/queries/CodeQuality/MissingPhaseHooks/): ports
    nixpkgs-hammering's missing-phase-hooks rule for
    configurePhase, buildPhase, checkPhase, and installPhase.
    Flags string-literal phase overrides that omit the corresponding
    runHook preX and/or runHook postX calls.
  • ql/src/Security/CWE-1078/AttributeTypo.ql (plus qhelp and
    ql/test/queries/CodeQuality/AttributeTypo/): ports the narrow Phase
    3a variant of nixpkgs-hammering's attribute-typo rule. Flags
    likely top-level derivation-attribute typos when they are either
    case-only mistakes or members of a handwritten typo allow-list; leaves
    unrelated custom attributes alone.
  • ql/src/Security/CWE-1078/DuplicateCheckInputs.ql (plus qhelp and
    ql/test/queries/CodeQuality/DuplicateCheckInputs/): ports
    nixpkgs-hammering's duplicate-check-inputs rule. Flags
    derivations that repeat a package from propagatedBuildInputs in
    checkInputs or nativeCheckInputs, where the check-time copy is
    redundant.
  • ql/src/Security/CWE-1078/AttributeOrdering.ql (plus qhelp and
    ql/test/queries/CodeQuality/AttributeOrdering/): ports
    nixpkgs-hammering's attribute-ordering rule. Flags derivation
    attributes that appear before the canonical predecessor they should
    follow, while ignoring unknown attributes and inherit clauses.
  • ql/src/Security/CWE-1078/UnclearGpl.ql (plus qhelp and
    ql/test/queries/CodeQuality/UnclearGpl/): ports
    nixpkgs-hammering's unclear-gpl rule. Flags deprecated ambiguous
    GNU license aliases in derivation meta.license bindings and
    recommends the explicit Only / Plus variant instead.
  • ql/src/Security/CWE-1078/EnvVarsAtTopLevel.ql (plus qhelp and
    ql/test/queries/CodeQuality/EnvVarsAtTopLevel/): ports
    nixpkgs-hammering's environment-variables-go-to-env rule. Flags
    selected environment variables declared as top-level derivation
    attributes and recommends moving them under env.
  • ql/src/Security/CWE-1078/UnnecessaryParallelBuilding.ql (plus qhelp
    and ql/test/queries/CodeQuality/UnnecessaryParallelBuilding/): ports
    nixpkgs-hammering's unnecessary-parallel-building rule. Flags
    redundant enableParallelBuilding = true; when Meson, CMake, or qmake
    already enables parallel builds through the default configure hook.
  • ql/src/Security/CWE-1078/BuildToolsInBuildInputs.ql (plus qhelp and
    ql/test/queries/CodeQuality/BuildToolsInBuildInputs/): ports
    nixpkgs-hammering's build-tools-in-build-inputs rule. Flags
    build-only tooling declared in buildInputs and recommends moving it
    to nativeBuildInputs.
  • ql/src/codeql-suites/nix-code-quality.qls: new suite that bundles
    the Phase 3a nixpkgs-hammering ports for opt-in style/quality
    scanning. Disjoint by tag from nix-code-scanning.qls.

Changed

  • ql/src/codeql-suites/nix-code-scanning.qls: now excludes queries
    tagged quality. Existing queries (tagged maintainability /
    correctness) are unaffected; Phase 3a quality lints are picked up
    by the new nix-code-quality.qls suite instead.