TheBotique

本地 CodeQL 告警定位与修复验收

Does not run the scan for you. Instead answers "why did CodeQL flag this, and which line must change for it to stop" — variant bisection yields a reproducible causal conclusion. Use when the user says "confirm the taint source / reproduce this CodeQL alert / why does CodeQL flag this

as observed 2026-10-02T07:46:18.975Z
Identifier
codeql-local-triage
Source
ClawHub
Version observed
1.0.4
Source repository
not published
Repository observation
No source repository listed
First observed here
2026-09-25T00:46:42.104Z
Observations recorded
3
Installs (reported upstream)
0
Weekly downloads (upstream)
229
Declared license
MIT-0

Observation history

2026-10-02T07:46:18.975Z

Fields that differed: changelog latestVersion summary

FieldBeforeAfter
changelog "v1.0.2(2026-09-30)SkillHub 评测三项打磨:R1 修 scan_sensitive_sources.py 退出码契约(缺失路径返回2而非误判0)+ SKILL.md 退出码契约说明;R8 bisect_taint.py 的 codeql 调用加30min超时+单次重试;R2 新增 references/faq.md 集中FAQ;R3 "v1.0.4(2026-10-01)合并语言拆分与文档打磨:SKILL.md 纯英文+SKILL.zh.md 纯中文双语并列;R4 增需求矩阵+README/SKILL 去重;R5 running-codeql-cli.md 重写从零安装验证链;R6 国内/离线下载提示。功能零改动,tests/run_tests.py 全量通过。"
latestVersion "1.0.2" "1.0.4"
summary "不替你跑扫描,而是回答「这条 CodeQL 告警为什么报、改哪一行才会消失」——用变体二分给出可复现的因果结论。当用户说「确认 taint 源 / 复现这个 CodeQL 告警 / 为什么 CodeQL 报这个 / 本地跑一次 CodeQL / 验证安全告警是否修好 / 这个告警是不是误报」,或需要判断某个 Code Scanning 告警是真漏洞还是误报 "Does not run the scan for you. Instead answers \"why did CodeQL flag this, and which line must change for it to stop\" — variant bisection yields a reproducible causal conclusion.
2026-10-01T06:47:50.210Z

Fields that differed: changelog displayName latestVersion summary topics

FieldBeforeAfter
changelog "v1.0.0 (2026-09-24): local CodeQL/Code Scanning alert causal triage & fix verification. Instead of running scans, uses variant bisection to answer 'why does this alert fire, which "v1.0.2(2026-09-30)SkillHub 评测三项打磨:R1 修 scan_sensitive_sources.py 退出码契约(缺失路径返回2而非误判0)+ SKILL.md 退出码契约说明;R8 bisect_taint.py 的 codeql 调用加30min超时+单次重试;R2 新增 references/faq.md 集中FAQ;R3
displayName "CodeQL 本地告警因果定位与修复验收" "本地 CodeQL 告警定位与修复验收"
latestVersion "1.0.0" "1.0.2"
summary "不替你跑扫描,而是回答「这条 CodeQL 告警为什么报、改哪一行才会消失」——用变体二分给出可复现的因果结论。当用户说「确认 taint 源 / 复现这个 CodeQL 告警 / 为什么 CodeQL 报这个 / 本地跑一次 CodeQL / 验证安全告警是否修好 / 这个告警是不是误报」,或需要判断某个 Code Scanning 告警是真漏洞还是误报 "不替你跑扫描,而是回答「这条 CodeQL 告警为什么报、改哪一行才会消失」——用变体二分给出可复现的因果结论。当用户说「确认 taint 源 / 复现这个 CodeQL 告警 / 为什么 CodeQL 报这个 / 本地跑一次 CodeQL / 验证安全告警是否修好 / 这个告警是不是误报」,或需要判断某个 Code Scanning 告警是真漏洞还是误报
topics ["code-scanning","codeql","false-positive","sarif","taint-analysis"] ["codeql","false-positive","sarif","static-analysis","taint-tracking"]

Correction

If you maintain this extension and believe anything above is inaccurate, request a correction. Corrections are published, and disputed entries are marked as disputed while under review.