Skip to content

JS: Add support for file-scoped MaD models - #22264

Open
asgerf wants to merge 4 commits into
github:mainfrom
asgerf:js/file-local-model
Open

JS: Add support for file-scoped MaD models#22264
asgerf wants to merge 4 commits into
github:mainfrom
asgerf:js/file-local-model

Conversation

@asgerf

@asgerf asgerf commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Makes it possible to write models for specific files within a codebase, by using a package name of form file:<path>. Previously it was only possible to model endpoints across a package-boundary, but now any file can effectively be treated as if it was a package. The model will obviously stop working if the mentioned file is moved/renamed, so it is still better to use real package names if at all possible.

Fixes #22206

asgerf added 3 commits July 31, 2026 14:57
For codebase-specific models it's useful to be able to write models for specific files, without an NPM package boundary around it. But previously it was only possible to use NPM package exports as the starting point of a model.

This adds the type `file:<path>` which uses imports of the given file as the starting point, exactly as it if had been importing aname NPM package.
@asgerf
asgerf marked this pull request as ready for review August 3, 2026 08:18
Copilot AI review requested due to automatic review settings August 3, 2026 08:18
@asgerf
asgerf requested review from a team as code owners August 3, 2026 08:18

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds file-scoped JavaScript models using file:<path> type names.

Changes:

  • Resolves model entry points from repository-relative file imports.
  • Adds source-model test coverage.
  • Documents the new model syntax.
Show a summary per file
File Description
ApiGraphModelsSpecific.qll Resolves file-scoped model entry points.
test.ext.yml Defines a file-scoped source model.
test.expected Records the expected taint-flow result.
importFileBasedModel.js Exercises the modeled import.
foo/bar/baz.js Provides the imported test module.
2026-07-31-file-scoped-models.md Announces the analysis enhancement.
customizing-library-models-for-javascript.rst Documents file-scoped model syntax.

Review details

  • Files reviewed: 7/7 changed files
  • Comments generated: 1
  • Review effort level: Balanced

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

@hvitved hvitved left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me, just one QL doc that may need updating.

)
}

/** Gets the name of the path variable. */

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This QL doc seems a bit weird to me.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants