本地 CodeQL 告警定位与修复验收
Does not run the scan for you. Instead answers "why did CodeQL flag this, and which line must change for it to stop" — variant bisection yields a reproducible causal conclusion. Use when the user says "confirm the taint source / reproduce this CodeQL alert / why does CodeQL flag this
as observed 2026-10-02T07:46:18.975Z- Identifier
codeql-local-triage- Source
- ClawHub
- Version observed
- 1.0.4
- Source repository
- not published
- Repository observation
- No source repository listed
- First observed here
- 2026-09-25T00:46:42.104Z
- Observations recorded
- 3
- Installs (reported upstream)
- 0
- Weekly downloads (upstream)
- 229
- Declared license
- MIT-0
Observation history
2026-10-02T07:46:18.975Z
Fields that differed: changelog latestVersion summary
| Field | Before | After |
|---|---|---|
changelog |
"v1.0.2(2026-09-30)SkillHub 评测三项打磨:R1 修 scan_sensitive_sources.py 退出码契约(缺失路径返回2而非误判0)+ SKILL.md 退出码契约说明;R8 bisect_taint.py 的 codeql 调用加30min超时+单次重试;R2 新增 references/faq.md 集中FAQ;R3 | "v1.0.4(2026-10-01)合并语言拆分与文档打磨:SKILL.md 纯英文+SKILL.zh.md 纯中文双语并列;R4 增需求矩阵+README/SKILL 去重;R5 running-codeql-cli.md 重写从零安装验证链;R6 国内/离线下载提示。功能零改动,tests/run_tests.py 全量通过。" |
latestVersion |
"1.0.2" | "1.0.4" |
summary |
"不替你跑扫描,而是回答「这条 CodeQL 告警为什么报、改哪一行才会消失」——用变体二分给出可复现的因果结论。当用户说「确认 taint 源 / 复现这个 CodeQL 告警 / 为什么 CodeQL 报这个 / 本地跑一次 CodeQL / 验证安全告警是否修好 / 这个告警是不是误报」,或需要判断某个 Code Scanning 告警是真漏洞还是误报 | "Does not run the scan for you. Instead answers \"why did CodeQL flag this, and which line must change for it to stop\" — variant bisection yields a reproducible causal conclusion. |
2026-10-01T06:47:50.210Z
Fields that differed: changelog displayName latestVersion summary topics
| Field | Before | After |
|---|---|---|
changelog |
"v1.0.0 (2026-09-24): local CodeQL/Code Scanning alert causal triage & fix verification. Instead of running scans, uses variant bisection to answer 'why does this alert fire, which | "v1.0.2(2026-09-30)SkillHub 评测三项打磨:R1 修 scan_sensitive_sources.py 退出码契约(缺失路径返回2而非误判0)+ SKILL.md 退出码契约说明;R8 bisect_taint.py 的 codeql 调用加30min超时+单次重试;R2 新增 references/faq.md 集中FAQ;R3 |
displayName |
"CodeQL 本地告警因果定位与修复验收" | "本地 CodeQL 告警定位与修复验收" |
latestVersion |
"1.0.0" | "1.0.2" |
summary |
"不替你跑扫描,而是回答「这条 CodeQL 告警为什么报、改哪一行才会消失」——用变体二分给出可复现的因果结论。当用户说「确认 taint 源 / 复现这个 CodeQL 告警 / 为什么 CodeQL 报这个 / 本地跑一次 CodeQL / 验证安全告警是否修好 / 这个告警是不是误报」,或需要判断某个 Code Scanning 告警是真漏洞还是误报 | "不替你跑扫描,而是回答「这条 CodeQL 告警为什么报、改哪一行才会消失」——用变体二分给出可复现的因果结论。当用户说「确认 taint 源 / 复现这个 CodeQL 告警 / 为什么 CodeQL 报这个 / 本地跑一次 CodeQL / 验证安全告警是否修好 / 这个告警是不是误报」,或需要判断某个 Code Scanning 告警是真漏洞还是误报 |
topics |
["code-scanning","codeql","false-positive","sarif","taint-analysis"] | ["codeql","false-positive","sarif","static-analysis","taint-tracking"] |
Correction
If you maintain this extension and believe anything above is inaccurate, request a correction. Corrections are published, and disputed entries are marked as disputed while under review.