mirror of
https://github.com/github/codeql-action.git
synced 2025-12-30 19:20:08 +08:00
* Bump the npm group with 11 updates Bumps the npm group with 11 updates: | Package | From | To | | --- | --- | --- | | [@actions/artifact](https://github.com/actions/toolkit/tree/HEAD/packages/artifact) | `1.1.1` | `1.1.2` | | [@actions/core](https://github.com/actions/toolkit/tree/HEAD/packages/core) | `1.10.0` | `1.10.1` | | [uuid](https://github.com/uuidjs/uuid) | `9.0.0` | `9.0.1` | | [@types/uuid](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/uuid) | `9.0.3` | `9.0.4` | | [@types/adm-zip](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/adm-zip) | `0.5.0` | `0.5.1` | | [@types/js-yaml](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/js-yaml) | `4.0.5` | `4.0.6` | | [@types/semver](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/semver) | `7.5.1` | `7.5.2` | | [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `6.5.0` | `6.7.2` | | [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) | `6.6.0` | `6.7.2` | | [eslint](https://github.com/eslint/eslint) | `8.48.0` | `8.49.0` | | [sinon](https://github.com/sinonjs/sinon) | `15.2.0` | `16.0.0` | Updates `@actions/artifact` from 1.1.1 to 1.1.2 - [Changelog](https://github.com/actions/toolkit/blob/main/packages/artifact/RELEASES.md) - [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/artifact) Updates `@actions/core` from 1.10.0 to 1.10.1 - [Changelog](https://github.com/actions/toolkit/blob/main/packages/core/RELEASES.md) - [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/core) Updates `uuid` from 9.0.0 to 9.0.1 - [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md) - [Commits](https://github.com/uuidjs/uuid/compare/v9.0.0...v9.0.1) Updates `@types/uuid` from 9.0.3 to 9.0.4 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/uuid) Updates `@types/adm-zip` from 0.5.0 to 0.5.1 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/adm-zip) Updates `@types/js-yaml` from 4.0.5 to 4.0.6 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/js-yaml) Updates `@types/semver` from 7.5.1 to 7.5.2 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/semver) Updates `@typescript-eslint/eslint-plugin` from 6.5.0 to 6.7.2 - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v6.7.2/packages/eslint-plugin) Updates `@typescript-eslint/parser` from 6.6.0 to 6.7.2 - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v6.7.2/packages/parser) Updates `eslint` from 8.48.0 to 8.49.0 - [Release notes](https://github.com/eslint/eslint/releases) - [Changelog](https://github.com/eslint/eslint/blob/main/CHANGELOG.md) - [Commits](https://github.com/eslint/eslint/compare/v8.48.0...v8.49.0) Updates `sinon` from 15.2.0 to 16.0.0 - [Release notes](https://github.com/sinonjs/sinon/releases) - [Changelog](https://github.com/sinonjs/sinon/blob/main/docs/changelog.md) - [Commits](https://github.com/sinonjs/sinon/compare/v15.2.0...v16.0.0) --- updated-dependencies: - dependency-name: "@actions/artifact" dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm - dependency-name: "@actions/core" dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm - dependency-name: uuid dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm - dependency-name: "@types/uuid" dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm - dependency-name: "@types/adm-zip" dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm - dependency-name: "@types/js-yaml" dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm - dependency-name: "@types/semver" dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm - dependency-name: "@typescript-eslint/eslint-plugin" dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm - dependency-name: "@typescript-eslint/parser" dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm - dependency-name: eslint dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm - dependency-name: sinon dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm ... Signed-off-by: dependabot[bot] <support@github.com> * Update checked-in dependencies --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
186 lines
5.9 KiB
JavaScript
186 lines
5.9 KiB
JavaScript
/**
|
|
* @fileoverview Rule to disallow loops with a body that allows only one iteration
|
|
* @author Milos Djermanovic
|
|
*/
|
|
|
|
"use strict";
|
|
|
|
//------------------------------------------------------------------------------
|
|
// Helpers
|
|
//------------------------------------------------------------------------------
|
|
|
|
const allLoopTypes = ["WhileStatement", "DoWhileStatement", "ForStatement", "ForInStatement", "ForOfStatement"];
|
|
|
|
/**
|
|
* Checks all segments in a set and returns true if any are reachable.
|
|
* @param {Set<CodePathSegment>} segments The segments to check.
|
|
* @returns {boolean} True if any segment is reachable; false otherwise.
|
|
*/
|
|
function isAnySegmentReachable(segments) {
|
|
|
|
for (const segment of segments) {
|
|
if (segment.reachable) {
|
|
return true;
|
|
}
|
|
}
|
|
|
|
return false;
|
|
}
|
|
|
|
/**
|
|
* Determines whether the given node is the first node in the code path to which a loop statement
|
|
* 'loops' for the next iteration.
|
|
* @param {ASTNode} node The node to check.
|
|
* @returns {boolean} `true` if the node is a looping target.
|
|
*/
|
|
function isLoopingTarget(node) {
|
|
const parent = node.parent;
|
|
|
|
if (parent) {
|
|
switch (parent.type) {
|
|
case "WhileStatement":
|
|
return node === parent.test;
|
|
case "DoWhileStatement":
|
|
return node === parent.body;
|
|
case "ForStatement":
|
|
return node === (parent.update || parent.test || parent.body);
|
|
case "ForInStatement":
|
|
case "ForOfStatement":
|
|
return node === parent.left;
|
|
|
|
// no default
|
|
}
|
|
}
|
|
|
|
return false;
|
|
}
|
|
|
|
/**
|
|
* Creates an array with elements from the first given array that are not included in the second given array.
|
|
* @param {Array} arrA The array to compare from.
|
|
* @param {Array} arrB The array to compare against.
|
|
* @returns {Array} a new array that represents `arrA \ arrB`.
|
|
*/
|
|
function getDifference(arrA, arrB) {
|
|
return arrA.filter(a => !arrB.includes(a));
|
|
}
|
|
|
|
//------------------------------------------------------------------------------
|
|
// Rule Definition
|
|
//------------------------------------------------------------------------------
|
|
|
|
/** @type {import('../shared/types').Rule} */
|
|
module.exports = {
|
|
meta: {
|
|
type: "problem",
|
|
|
|
docs: {
|
|
description: "Disallow loops with a body that allows only one iteration",
|
|
recommended: false,
|
|
url: "https://eslint.org/docs/latest/rules/no-unreachable-loop"
|
|
},
|
|
|
|
schema: [{
|
|
type: "object",
|
|
properties: {
|
|
ignore: {
|
|
type: "array",
|
|
items: {
|
|
enum: allLoopTypes
|
|
},
|
|
uniqueItems: true
|
|
}
|
|
},
|
|
additionalProperties: false
|
|
}],
|
|
|
|
messages: {
|
|
invalid: "Invalid loop. Its body allows only one iteration."
|
|
}
|
|
},
|
|
|
|
create(context) {
|
|
const ignoredLoopTypes = context.options[0] && context.options[0].ignore || [],
|
|
loopTypesToCheck = getDifference(allLoopTypes, ignoredLoopTypes),
|
|
loopSelector = loopTypesToCheck.join(","),
|
|
loopsByTargetSegments = new Map(),
|
|
loopsToReport = new Set();
|
|
|
|
const codePathSegments = [];
|
|
let currentCodePathSegments = new Set();
|
|
|
|
return {
|
|
|
|
onCodePathStart() {
|
|
codePathSegments.push(currentCodePathSegments);
|
|
currentCodePathSegments = new Set();
|
|
},
|
|
|
|
onCodePathEnd() {
|
|
currentCodePathSegments = codePathSegments.pop();
|
|
},
|
|
|
|
onUnreachableCodePathSegmentStart(segment) {
|
|
currentCodePathSegments.add(segment);
|
|
},
|
|
|
|
onUnreachableCodePathSegmentEnd(segment) {
|
|
currentCodePathSegments.delete(segment);
|
|
},
|
|
|
|
onCodePathSegmentEnd(segment) {
|
|
currentCodePathSegments.delete(segment);
|
|
},
|
|
|
|
onCodePathSegmentStart(segment, node) {
|
|
|
|
currentCodePathSegments.add(segment);
|
|
|
|
if (isLoopingTarget(node)) {
|
|
const loop = node.parent;
|
|
|
|
loopsByTargetSegments.set(segment, loop);
|
|
}
|
|
},
|
|
|
|
onCodePathSegmentLoop(_, toSegment, node) {
|
|
const loop = loopsByTargetSegments.get(toSegment);
|
|
|
|
/**
|
|
* The second iteration is reachable, meaning that the loop is valid by the logic of this rule,
|
|
* only if there is at least one loop event with the appropriate target (which has been already
|
|
* determined in the `loopsByTargetSegments` map), raised from either:
|
|
*
|
|
* - the end of the loop's body (in which case `node === loop`)
|
|
* - a `continue` statement
|
|
*
|
|
* This condition skips loop events raised from `ForInStatement > .right` and `ForOfStatement > .right` nodes.
|
|
*/
|
|
if (node === loop || node.type === "ContinueStatement") {
|
|
|
|
// Removes loop if it exists in the set. Otherwise, `Set#delete` has no effect and doesn't throw.
|
|
loopsToReport.delete(loop);
|
|
}
|
|
},
|
|
|
|
[loopSelector](node) {
|
|
|
|
/**
|
|
* Ignore unreachable loop statements to avoid unnecessary complexity in the implementation, or false positives otherwise.
|
|
* For unreachable segments, the code path analysis does not raise events required for this implementation.
|
|
*/
|
|
if (isAnySegmentReachable(currentCodePathSegments)) {
|
|
loopsToReport.add(node);
|
|
}
|
|
},
|
|
|
|
|
|
"Program:exit"() {
|
|
loopsToReport.forEach(
|
|
node => context.report({ node, messageId: "invalid" })
|
|
);
|
|
}
|
|
};
|
|
}
|
|
};
|