1--- 2# vi: ts=2 sw=2 et syntax=yaml: 3# SPDX-License-Identifier: LGPL-2.1-or-later 4# 5# Note: it is not recommended to directly reference the respective queries from 6# the github/codeql repository, so we have to "dance" around it using 7# a custom QL suite 8# See: 9# - https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/configuring-code-scanning#running-additional-queries 10# - https://github.com/github/codeql-action/issues/430#issuecomment-806092120 11# - https://codeql.github.com/docs/codeql-cli/creating-codeql-query-suites/ 12 13- import: codeql-suites/cpp-lgtm.qls 14 from: codeql/cpp-queries 15- include: 16 id: 17 - cpp/bad-strncpy-size 18 - cpp/declaration-hides-variable 19 - cpp/inconsistent-null-check 20 - cpp/mistyped-function-arguments 21 - cpp/nested-loops-with-same-variable 22 - cpp/sizeof-side-effect 23 - cpp/suspicious-pointer-scaling 24 - cpp/suspicious-pointer-scaling-void 25 - cpp/suspicious-sizeof 26 - cpp/unsafe-strcat 27 - cpp/unsafe-strncat 28 - cpp/unsigned-difference-expression-compared-zero 29 - cpp/unused-local-variable 30 tags: 31 - "security" 32 - "correctness" 33 severity: "error" 34- exclude: 35 id: 36 - cpp/fixme-comment 37