Visitar URL original
JS: Fix `Map` content flow by MathiasVP · Pull Request #22781 · github/codeql · GitHub
Skip to content

JS: Fix Map content flow - #22781

Open
MathiasVP wants to merge 3 commits into
github:mainfrom
MathiasVP:fix-js-map-flow
Open

MathiasVP wants to merge 3 commits into
github:mainfrom
MathiasVP:fix-js-map-flow

Conversation

@MathiasVP

@MathiasVP MathiasVP commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Pulled out of #22765. I'm not sure if there is some subtle thing that both me and Copilot are missing?

@github-actions github-actions Bot added the JS label Oct 8, 2026
@MathiasVP
MathiasVP marked this pull request as ready for review October 8, 2026 10:47
@MathiasVP
MathiasVP requested a review from a team as a code owner October 8, 2026 10:47
Copilot AI balanced review requested due to automatic review settings October 8, 2026 10:47
@MathiasVP MathiasVP added the no-change-note-required This PR does not need a change note label Oct 8, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The replacement drops flow from existing entries() summaries that still produce Member[0/1] paths.

1 open finding
What changed in this PR

Fixes JavaScript data flow through Map constructor entries.

Changes:

  • Models indexed elements in entry arrays.
  • Adds a constructor-flow regression test.
  • Updates consistency expectations.
File Description
Maps.qll Updates Map constructor flow paths.
tst.js Tests value flow from constructor entries.
DataFlowConsistency.expected Updates expected consistency output.

🧠 Review effort: Balanced


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

Comment on lines +23 to +24
input =
"Argument[0]." + ["ArrayElement", "SetElement", "IteratorElement"] + ".ArrayElement[0]" and

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hmm @asgerf this sounds right. What do you say here?

@asgerf

asgerf commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Thanks for flagging this. I have an alternative fix here that I'd like to pursue instead as Member[n] needs to work.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

JS no-change-note-required This PR does not need a change note

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants