You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
ql/lib/codeql/nix/Derivation.qll: recognises calls to nixpkgs-style
derivation wrappers (stdenv.mkDerivation, stdenvNoCC.mkDerivation, buildPythonPackage, buildPythonApplication — faithful to nixpkgs-hammering's scope) and exposes getKind, getAttrs, hasAttr, getDirectBinding, getADirectBinding, and getNthAttrName. getAttrs peels through parens, the (finalAttrs: { … }) callback shape, and let … in { … } bodies.
Foundation for the Phase 3a nixpkgs-hammering-port queries.
ql/test/library-tests/Derivation/: library-level test covering 12
derivation-call shapes including callback, callback+rec, callback+let,
parens, plain rec, both Python wrappers, and inherit / inherit-from
cases.
ql/src/Security/CWE-1078/MesonAndCmake.ql (plus qhelp and ql/test/queries/CodeQuality/MesonAndCmake/): ports nixpkgs-hammering's meson-cmake rule. Flags derivations whose nativeBuildInputs declare both meson and cmake, where nixpkgs
convention is to pick one primary configure-phase build system.
ql/src/Security/CWE-1078/NameInsteadOfPnameVersion.{ql,qhelp}: ports
nixpkgs-hammering's name-and-version rule, flagging derivations that
set name and version without pname; includes a CodeQuality qltest
fixture covering direct, inherit, callback, and buildPythonPackage
forms.
ql/src/Security/CWE-1078/ExplicitPhases.ql plus qhelp and query tests:
ports nixpkgs-hammering's explicit-phases rule, reporting direct
overrides of configurePhase, buildPhase, checkPhase, and installPhase while leaving hook-based customization and unrelated
phases to their dedicated rules.
ql/src/Security/CWE-1078/ProtectedPhaseOverride.ql (plus qhelp and ql/test/queries/CodeQuality/ProtectedPhaseOverride/): ports nixpkgs-hammering's fixup-phase and patch-phase rules. Flags
derivations that override fixupPhase or patchPhase directly
instead of extending the default phase with pre* / post* hooks.
ql/src/Security/CWE-1078/MissingPhaseHooks.ql (plus qhelp and ql/test/queries/CodeQuality/MissingPhaseHooks/): ports nixpkgs-hammering's missing-phase-hooks rule for configurePhase, buildPhase, checkPhase, and installPhase.
Flags string-literal phase overrides that omit the corresponding runHook preX and/or runHook postX calls.
ql/src/Security/CWE-1078/AttributeTypo.ql (plus qhelp and ql/test/queries/CodeQuality/AttributeTypo/): ports the narrow Phase
3a variant of nixpkgs-hammering's attribute-typo rule. Flags
likely top-level derivation-attribute typos when they are either
case-only mistakes or members of a handwritten typo allow-list; leaves
unrelated custom attributes alone.
ql/src/Security/CWE-1078/DuplicateCheckInputs.ql (plus qhelp and ql/test/queries/CodeQuality/DuplicateCheckInputs/): ports nixpkgs-hammering's duplicate-check-inputs rule. Flags
derivations that repeat a package from propagatedBuildInputs in checkInputs or nativeCheckInputs, where the check-time copy is
redundant.
ql/src/Security/CWE-1078/AttributeOrdering.ql (plus qhelp and ql/test/queries/CodeQuality/AttributeOrdering/): ports nixpkgs-hammering's attribute-ordering rule. Flags derivation
attributes that appear before the canonical predecessor they should
follow, while ignoring unknown attributes and inherit clauses.
ql/src/Security/CWE-1078/UnclearGpl.ql (plus qhelp and ql/test/queries/CodeQuality/UnclearGpl/): ports nixpkgs-hammering's unclear-gpl rule. Flags deprecated ambiguous
GNU license aliases in derivation meta.license bindings and
recommends the explicit Only / Plus variant instead.
ql/src/Security/CWE-1078/EnvVarsAtTopLevel.ql (plus qhelp and ql/test/queries/CodeQuality/EnvVarsAtTopLevel/): ports nixpkgs-hammering's environment-variables-go-to-env rule. Flags
selected environment variables declared as top-level derivation
attributes and recommends moving them under env.
ql/src/Security/CWE-1078/UnnecessaryParallelBuilding.ql (plus qhelp
and ql/test/queries/CodeQuality/UnnecessaryParallelBuilding/): ports nixpkgs-hammering's unnecessary-parallel-building rule. Flags
redundant enableParallelBuilding = true; when Meson, CMake, or qmake
already enables parallel builds through the default configure hook.
ql/src/Security/CWE-1078/BuildToolsInBuildInputs.ql (plus qhelp and ql/test/queries/CodeQuality/BuildToolsInBuildInputs/): ports nixpkgs-hammering's build-tools-in-build-inputs rule. Flags
build-only tooling declared in buildInputs and recommends moving it
to nativeBuildInputs.
ql/src/codeql-suites/nix-code-quality.qls: new suite that bundles
the Phase 3a nixpkgs-hammering ports for opt-in style/quality
scanning. Disjoint by tag from nix-code-scanning.qls.
Changed
ql/src/codeql-suites/nix-code-scanning.qls: now excludes queries
tagged quality. Existing queries (tagged maintainability / correctness) are unaffected; Phase 3a quality lints are picked up
by the new nix-code-quality.qls suite instead.