Skip to content

[DO NOT MERGE] Verify CodeQL critical alert handling - #918

Draft
vgvoleg wants to merge 1 commit into
mainfrom
experiment/codeql-critical-check
Draft

vgvoleg wants to merge 1 commit into
mainfrom
experiment/codeql-critical-check

Conversation

@vgvoleg

@vgvoleg vgvoleg commented Oct 6, 2026

Copy link
Copy Markdown
Member

Temporary security-check experiment. DO NOT MERGE.

Adds an isolated Flask example that evaluates an HTTP query parameter as Python code. Expected CodeQL finding: py/code-injection, Critical (security severity 9.3). The example has no server startup and is not imported by the SDK.

Observe whether Code scanning results / CodeQL fails for a new Critical alert while the analysis jobs complete successfully. No repository rulesets are configured for this experiment.

@app.route("/evaluate")
def evaluate_expression():
expression = request.args["expression"]
return str(eval(expression))
@codecov

codecov Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 82.67%. Comparing base (b28a9b5) to head (92c3d23).

Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             main     #918      +/-   ##
==========================================
- Coverage   82.68%   82.67%   -0.01%     
==========================================
  Files          99       99              
  Lines       12961    12961              
  Branches     1269     1269              
==========================================
- Hits        10717    10716       -1     
- Misses       1793     1794       +1     
  Partials      451      451              
Flag Coverage Δ
integration 80.44% <ø> (-0.01%) ⬇️
unit 49.21% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.
see 1 file with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants