3 ms·
One of the specific design goals we had was to make sure that the query engine isn't tightly coupled to AST nodes. We started with the AST, since that's ultima
by morgante 3y ago
One of the specific design goals we had was to make sure that the query engine isn't tightly coupled to AST nodes.
We started with the AST, since that's ultimately the foundation for code but the goal is to add more graphs on top. So you could do a query like this to find all cases where a function called `unsafe` is queried with an unknown value:
`unsafe($val)` where $val <: type `unknown`
Is your interest in CodeQL primarily for security scans?
- mdaniel 3y agosecurity is up there, but from reading the examples in CodeQL it just seemed like it would be possible to express some truly great versions of "don't do that" rules in it. I am a total JetBrains fanboi, and their introspections are world-class, but getting Qodana to run to completion before the heat death of the universe has proven to require more glucose than I have to offer it. Thus, I'm always interested in alternate implementations, even though I am acutely aware of the computational complexity of what I'm asking I recalled another link I wish I had included in my question from the SourceGraph folks https://github.com/sourcegraph/scip#scip-code-intelligence-protocol https://github.com/sourcegraph/scip#scip-code-intelligence-p... which started out life as "Language Server Indexing Protocol" and seems to solve some similar project-wide introspection questions but TBH since their rug pull I've been a lot less willing to hitch my wagon to their train
- morgante 3y agoMakes sense, we internally use GritQL as a super linter for some codebase-specific patterns. It's pretty easy to set up: https://docs.grit.io/guides/ci https://docs.grit.io/guides/ci We've looked at both LSIF and SCIP from SourceGraph, though I expect we'll end up building our own index to allow for more complex queries. We're also incorporating some LLM functionality to express conditions you can't program deterministically. If you're interested in being a design partner for some of our auto-review features feel free to email morgante@grit.io.