From 94e7443de8ac8b57a74526d0d5222675467deb2f Mon Sep 17 00:00:00 2001 From: Mathew Payne Date: Thu, 2 Feb 2023 19:27:18 +0000 Subject: [PATCH] Add low queries --- python/.data/queries.json | 6 ++++++ python/README.md | 2 +- python/suites/codeql-python.qls | 15 ++++++++++++--- 3 files changed, 19 insertions(+), 4 deletions(-) diff --git a/python/.data/queries.json b/python/.data/queries.json index dd4e989a12..dd20367f94 100644 --- a/python/.data/queries.json +++ b/python/.data/queries.json @@ -374,6 +374,12 @@ "codeql/python/ql/src/Diagnostics/SuccessfullyExtractedFiles.ql", "codeql/python/ql/src/Summary/LinesOfCode.ql", "codeql/python/ql/src/Summary/LinesOfUserCode.ql", + "codeql/python/ql/src/Classes/MaybeUndefinedClassAttribute.ql", + "codeql/python/ql/src/Classes/UndefinedClassAttribute.ql", + "codeql/python/ql/src/Security/CWE-020-ExternalAPIs/UntrustedDataToExternalAPI.ql", + "codeql/python/ql/src/Statements/ExecUsed.ql", + "codeql/python/ql/src/Statements/StringConcatenationInLoop.ql", + "codeql/python/ql/src/Variables/UndefinedGlobal.ql", "codeql/python/ql/src/experimental/Classes/NamingConventionsClasses.ql", "codeql/python/ql/src/experimental/Functions/NamingConventionsFunctions.ql", "codeql/python/ql/src/experimental/Security/CWE-022/ZipSlip.ql", diff --git a/python/README.md b/python/README.md index 9c1a34b29f..bbc761d709 100644 --- a/python/README.md +++ b/python/README.md @@ -8,7 +8,7 @@ | `extended` | 45 | Security Extended Suite | `codeql/python/ql/src/codeql-suites/security-extended` | | `quality` | 167 | Security and Quality Extended Suite | `codeql/python/ql/src/codeql-suites/security-and-quality` | | `local-variants` | 49 | Security Extended with local variants enabled | `advanced-security/codeql-queries/python/suites/codeql-python-local.qls@main` | -| `super-extended` | 80 | Security Extended with Experimental and Custom Queries Suite | `advanced-security/codeql-queries/python/suites/codeql-python.qls@main` | +| `super-extended` | 86 | Security Extended with Experimental and Custom Queries Suite | `advanced-security/codeql-queries/python/suites/codeql-python.qls@main` | | `audit` | 6 | Security Audit Query Suite | `advanced-security/codeql-queries/python/suites/codeql-python-audit.qls@main` | diff --git a/python/suites/codeql-python.qls b/python/suites/codeql-python.qls index b4e1ba8337..c8003daadd 100644 --- a/python/suites/codeql-python.qls +++ b/python/suites/codeql-python.qls @@ -7,6 +7,18 @@ - import: codeql-suites/python-security-extended.qls from: codeql/python-queries +# Include Experimental queries +- queries: '.' + from: codeql/python-queries + +# Include lows +- include: + kind: + - problem + - path-problem + precision: + - low + # Remove debugging, and audit queries - exclude: tags contain: @@ -17,9 +29,6 @@ query path: - /testing\/.*/ -# Include Experimental queries -- queries: '.' - from: codeql/python-queries - include: query path: - /experimental\/.*/