We welcome contributions to our CodeQL libraries and queries. Got an idea for a new check, or how to improve an existing query? Then please go ahead and open a pull request! Contributions to this project are released to the public under the project's open source license.
There is lots of useful documentation to help you write queries, ranging from information about query file structure to tutorials for specific target languages. For more information on the documentation available, see CodeQL queries on codeql.github.com.
Note that the CodeQL for Visual Studio Code documentation has been migrated to https://docs.github.com/en/code-security/codeql-for-vs-code/, but you can still contribute to it via a different repository. For more information, see Contributing to GitHub Docs documentation."
Any nontrivial user-visible change to a query pack or library pack should have a change note. For details on how to add a change note for your change, see this guide.
If you have an idea for a query that you would like to share with other CodeQL users, please open a pull request to add it to this repository. New queries start out in a <language>/ql/src/experimental
directory, to which they can be merged when they meet the following requirements.
-
Directory structure
There are eight language-specific query directories in this repository:
- C/C++:
cpp/ql/src
- C#:
csharp/ql/src
- Go:
go/ql/src
- Java/Kotlin:
java/ql/src
- JavaScript:
javascript/ql/src
- Python:
python/ql/src
- Ruby:
ruby/ql/src
- Swift:
swift/ql/src
Each language-specific directory contains further subdirectories that group queries based on their
@tags
or purpose.- Experimental queries and libraries are stored in the
experimental
subdirectory within each language-specific directory in the CodeQL repository. For example, experimental Java queries and libraries are stored injava/ql/src/experimental
and any corresponding tests injava/ql/test/experimental
. - Experimental queries need to include
experimental
in their@tags
- The structure of an
experimental
subdirectory mirrors the structure of its parent directory. - Select or create an appropriate directory in
experimental
based on the existing directory structure ofexperimental
or its parent directory.
- C/C++:
-
Query metadata
- The query
@id
must conform to all the requirements in the guide on query metadata. In particular, it must not clash with any other queries in the repository, and it must start with the appropriate language-specific prefix. - The query must have a
@name
and@description
to explain its purpose. - The query must have a
@kind
and@problem.severity
as required by CodeQL tools.
For details, see the guide on query metadata.
Make sure the
select
statement is compatible with the query@kind
. See About CodeQL queries on codeql.github.com. - The query
-
Formatting
- The queries and libraries must be autoformatted, for example using the "Format Document" command in CodeQL for Visual Studio Code.
If you prefer, you can either:
- install the pre-commit framework and install the configured hooks on this repo via
pre-commit install
, or - use this pre-commit hook that automatically checks whether your files are correctly formatted.
See the pre-commit hook installation guide for instructions on the two approaches.
-
Compilation
- Compilation of the query and any associated libraries and tests must be resilient to future development of the supported libraries. This means that the functionality cannot use internal libraries, cannot depend on the output of
getAQlClass
, and cannot make use of regexp matching ontoString
. - The query and any associated libraries and tests must not cause any compiler warnings to be emitted (such as use of deprecated functionality or missing
override
annotations).
- Compilation of the query and any associated libraries and tests must be resilient to future development of the supported libraries. This means that the functionality cannot use internal libraries, cannot depend on the output of
-
Results
- The query must have at least one true positive result on some revision of a real project.
-
Query help files and unit tests
- Query help (
.qhelp
) files and unit tests are optional (but strongly encouraged!) for queries in theexperimental
directories. For more information about contributing query help files and unit tests, see Supported CodeQL queries and libraries.
- Query help (
Experimental queries and libraries may not be actively maintained as the supported libraries evolve. They may also be changed in backwards-incompatible ways or may be removed entirely in the future without deprecation warnings.
After the experimental query is merged, we welcome pull requests to improve it. Before a query can be moved out of the experimental
subdirectory, it must satisfy the requirements for being a supported query.
If you contribute to this project, we will record your name and email address (as provided by you with your contributions) as part of the code repositories, which are public. We might also use this information to contact you in relation to your contributions, as well as in the normal course of software development. We also store records of CLA agreements signed in the past, but no longer require contributors to sign a CLA. Under GDPR legislation, we do this on the basis of our legitimate interest in creating the CodeQL product.
Please do get in touch ([email protected]) if you have any questions about this or our data protection policies.
Please notice that any bazel targets and definitions in this repository are currently experimental and for internal use only.