ã¡ã¢
ãã®ã³ã³ãã³ãã§ã¯ãCodeQL CLI ã®ææ°ãªãªãŒã¹ã«ã€ããŠèª¬æããŸãã ãã®ãªãªãŒã¹ã«ã€ããŠè©³ããã¯ã https://github.com/github/codeql-cli-binaries/releases ãã芧ãã ããã
以åã®ãªãªãŒã¹ã®ããã®ã³ãã³ãã§äœ¿ãããªãã·ã§ã³ã詳ãã確èªããã«ã¯ãã¿ãŒããã«ã§ --help
ãªãã·ã§ã³ãæå®ããŠã³ãã³ããå®è¡ããŠãã ããã
æ§æ
codeql database analyze --format=<format> --output=<output> [--threads=<num>] [--ram=<MB>] <options>... -- <database> <query|dir|suite|pack>...
codeql database analyze --format=<format> --output=<output> [--threads=<num>] [--ram=<MB>] <options>... -- <database> <query|dir|suite|pack>...
説æ
ããŒã¿ããŒã¹ãåæãããœãŒã¹ ã³ãŒãã®ã³ã³ããã¹ãã§æå³ã®ããçµæãçæããŸãã
CodeQL ããŒã¿ããŒã¹ã«å¯ŸããŠã¯ãšãª ã¹ã€ãŒã (ãŸãã¯ããã€ãã®åã ã®ã¯ãšãª) ãå®è¡ããã¢ã©ãŒããŸãã¯ãã¹ãšããŠã¹ã¿ã€ã«èšå®ãããçµæã SARIF ãŸãã¯è§£éãããå¥ã®åœ¢åŒã§çæããŸãã
ãã®ã³ãã³ãã¯ãcodeql database run-queries ãš codeql database interpret-results ã®ã³ãã³ãã®å¹æãçµã¿åããããã®ã§ãã çµæããœãŒã¹ ã³ãŒã ã¢ã©ãŒããšããŠè§£éãããããã®èŠä»¶ã "æºãããªã" ã¯ãšãªãå®è¡ããå Žåã¯ãcodeql database run-queries ãŸã㯠codeql query run ã代ããã«äœ¿çšããŠãããcodeql bqrs decode ã䜿çšããŠçã®çµæãèªã¿åãå¯èœãªè¡šèšã«å€æããŸãã__
[ãªãã·ã§ã³]
äž»ãªãªãã·ã§ã³
<database>
[å¿ é ] ã¯ãšãªãå®è¡ãã CodeQL ããŒã¿ããŒã¹ã®ãã¹ã
<query|dir|suite|pack>...
å®è¡ããã¯ãšãªã ååŒæ°ã¯ãscope/name@range:path
ã®åœ¢åŒã«ãªããŸããããã§ã
scope/name
ã¯ãCodeQL ããã¯ã®ä¿®é£Ÿåã§ããrange
ã¯ãsemver ã®ç¯å²ã§ããpath
ã¯ããã¡ã€ã« ã·ã¹ãã ã®ãã¹ã§ãã
scope/name
ãæå®ããå Žåãrange
ãš path
ã¯çç¥å¯èœã§ãã range
ããªãå Žåã¯ãæå®ããããã¯ã®ææ°ããŒãžã§ã³ãæå³ããŸãã path
ããªãå Žåã¯ãæå®ããããã¯ã®ããã©ã«ãã®ã¯ãšãª ã¹ã€ãŒããæå³ããŸãã
path
ã¯ã*.ql
ã¯ãšãª ãã¡ã€ã«ã1 ã€ãŸãã¯è€æ°ã®ã¯ãšãªãå«ããã£ã¬ã¯ããªããŸã㯠.qls
ã¯ãšãª ã¹ã€ãŒã ãã¡ã€ã«ã®ããããã«ããããšãã§ããŸãã ããã¯åãæå®ããªãå Žåã¯ãpath
ãæå®ããå¿
èŠããããçŸåšã®ããã»ã¹ã®çŸåšã®äœæ¥ãã£ã¬ã¯ããªããã®çžå¯Ÿãã¹ãšããŠè§£éãããŸãã
ãªãã©ã« @
ãŸã㯠:
ãå«ã path
ãæå®ããã«ã¯ãåŒæ°ã®ãã¬ãã£ãã¯ã¹ãšã㊠path:
ã䜿ããŸã (äŸ: path:directory/with:and@/chars
)ã
scope/name
ãš path
ãæå®ããå Žåãpath
ã絶察ãã¹ã«ããããšã¯ã§ããŸããã ããã¯ãCodeQL ããã¯ã®ã«ãŒããåºæºã«ããŠãããšèŠãªãããŸãã
ã¯ãšãªãæå®ããªãå Žåãå®è¡ããé©åãªã¯ãšãª ã»ããã CLI ã«ãã£ãŠèªåçã«æ±ºå®ãããŸãã å
·äœçã«ã¯ãããŒã¿ããŒã¹ã®äœææã« --codescanning-config
ã䜿ã£ãŠ Code Scanning ã®æ§æãã¡ã€ã«ãæå®ããå Žåã¯ããã®ã¯ãšãªã䜿ãããŸãã
ãã以å€ã®å Žåã¯ãåæãããŠããèšèªã®ããã©ã«ãã®ã¯ãšãªã䜿ãããŸãã
--format=<format>
[å¿ é ] çµæãæžã蟌ã圢åŒã ã€ãã®ããããã§ãã
csv
: ã«ãŒã«ãšã¢ã©ãŒã ã¡ã¿ããŒã¿ã®äž¡æ¹ãããåãå«ããæžåŒèšå®ãããã³ã³ãåºåãã®å€ã
sarif-latest
: Static Analysis Results Interchange Format (SARIF)ãéçãªåæçµæãèšè¿°ããããã® JSON ããŒã¹ã®åœ¢åŒã ãã®åœ¢åŒãªãã·ã§ã³ã§ã¯ããµããŒããããŠããææ°ããŒãžã§ã³ (v2.1.0) ã䜿çšãããŸãã ãã®ãªãã·ã§ã³ã¯ãç°ãªã CodeQL ããŒãžã§ã³éã§ç°ãªãããŒãžã§ã³ã® SARIF ãçæããããããèªååã§ã®äœ¿çšã«ã¯é©ããŠããŸããã
sarifv2.1.0
: SARIF v2.1.0ã
graphtext
: ã°ã©ãã衚ãããã¹ã圢åŒã @kind ã°ã©ãã䜿çšããã¯ãšãªãšã®ã¿äºææ§ããããŸãã
dgml
: Directed Graph Markup Languageãã°ã©ããèšè¿°ããããã® XML ããŒã¹ã®åœ¢åŒã @kind ã°ã©ãã䜿çšããã¯ãšãªãšã®ã¿äºææ§ããããŸãã
dot
: Graphviz DOT èšèªãã°ã©ããèšè¿°ããããã®ããã¹ãããŒã¹ã®åœ¢åŒã
@kind ã°ã©ãã䜿çšããã¯ãšãªãšã®ã¿äºææ§ããããŸãã
-o, --output=<output>
[å¿ é ] çµæãæžã蟌ãåºåãã¹ã ã°ã©ã圢åŒã®å Žåãããã¯ãã£ã¬ã¯ããªã§ããå¿ èŠããããçµæ (ãã®ã³ãã³ãã§è€æ°ã®ã¯ãšãªã®è§£éããµããŒããããŠããå Žåã¯è€æ°ã®çµæ) ããã®ãã£ã¬ã¯ããªå ã«æžã蟌ãŸããŸãã
--[no-]rerun
BQRS ã®çµæãæ¢ã«ããŒã¿ããŒã¹ã«æ ŒçŽãããŠãããšèããããã¯ãšãªãè©äŸ¡ããŸãã
--no-print-diagnostics-summary
åæãã蚺æã®æŠèŠãæšæºåºåã«åºåããŸããã
--no-print-metrics-summary
åæããã¡ããªãã¯ã®æŠèŠãæšæºåºåã«åºåããŸããã
--max-paths=<maxPaths>
ãã¹ãå«ãã¢ã©ãŒãããšã«çæãããã¹ã®æå€§æ°ã (ããã©ã«ãå€: 4)
--[no-]sarif-add-file-contents
[SARIF 圢åŒã®ã¿] å°ãªããšã 1 ã€ã®çµæã§åç §ããããã¹ãŠã®ãã¡ã€ã«ã®å®å šãªãã¡ã€ã« ã³ã³ãã³ããå«ããŸãã
--[no-]sarif-add-snippets
[SARIF 圢åŒã®ã¿] çµæã«ç€ºãããŠããåå Žæã®ã³ãŒã ã¹ãããããå«ããŸããå ±åãããå Žæã®ååŸã« 2 è¡ã®ã³ã³ããã¹ãããããŸãã
--[no-]sarif-add-query-help
[SARIF 圢åŒã®ã¿] [éæšå¥š] ãã¹ãŠã®ã¯ãšãªã® Markdown ã¯ãšãª ãã«ããå«ããŸãã /path/to/query.md ãã¡ã€ã«ãã /path/to/query.ql ã®ã¯ãšãª ãã«ããèªã¿èŸŒãŸããŸãã ãã®ãã©ã°ãæå®ãããŠããªãå Žåã®ããã©ã«ãã®åäœã§ã¯ãã«ã¹ã¿ã ã¯ãšãª (`codeql/<lang&rt;-queries` 圢åŒã§ã¯ãªãã¯ãšãª ããã¯å ã®ã¯ãšãª) ã«å¯ŸããŠã®ã¿ãã«ããå«ããŸãã ãã®ãªãã·ã§ã³ã¯ãcodeql bqrs interpret ã«æž¡ããŠã广ã¯ãããŸããã
--sarif-include-query-help=<mode>
[SARIF 圢åŒã®ã¿] SARIF åºåã«ã¯ãšãª ãã«ããå«ãããã©ãããæå®ããŸãã æ¬¡ã®ãããã:
always
: ãã¹ãŠã®ã¯ãšãªã«ã¯ãšãª ãã«ããå«ããŸãã
custom_queries_only
(ããã©ã«ãå€): ã«ã¹ã¿ã ã¯ãšãª (`codeql/<lang&rt;-queries` 圢åŒã§ã¯ãªãã¯ãšãª) ã«ã®ã¿ã¯ãšãª ãã«ããå«ããŸãã
never
: ã©ã®ã¯ãšãªã«ããã«ããå«ããŸããã
ãã®ãªãã·ã§ã³ã¯ãcodeql bqrs interpret ã«æž¡ããŠã广ã¯ãããŸããã
v2.15.2
以éã§äœ¿çšã§ããŸãã
--no-sarif-include-alert-provenance
[詳现èšå®] [SARIF 圢åŒã®ã¿] SARIF åºåã«ã¢ã©ãŒãã®å®çžŸæ å ±ãå«ããªãã§ãã ããã
v2.18.1
以éã§äœ¿çšã§ããŸãã
--[no-]sarif-group-rules-by-pack
[SARIF 圢åŒã®ã¿] <run>.tool.extensions
ããããã£ã®å¯Ÿå¿ãã QL ããã¯ã®äžã«ãåã¯ãšãªã®ã«ãŒã« ãªããžã§ã¯ããé
眮ããŸãã ãã®ãªãã·ã§ã³ã¯ãcodeql bqrs interpret ã«æž¡ããŠã广ã¯ãããŸããã
--[no-]sarif-multicause-markdown
[SARIF 圢åŒã®ã¿] è€æ°ã®åå ãããã¢ã©ãŒãã®å Žåã¯ããã¬ãŒã³æååã«å ããããŒã¯ããŠã³åœ¢åŒã®æçްåããããªã¹ããšããŠåºåã«å«ããŸãã
--no-sarif-minify
[SARIF 圢åŒã®ã¿] åãã©ãŒãããããã SARIF åºåãçæããŸãã æ¢å®ã§ã¯ãSARIF åºåã¯ãããã¡ã€åŠçãããåºåãã¡ã€ã«ã®ãµã€ãºãå°ãããªããŸãã
--sarif-run-property=<String=String>
[SARIF 圢åŒã®ã¿] çæããã SARIF 'run' ãããã㣠ããã°ã«è¿œå ããããŒãšå€ã®ãã¢ã ç¹°ãè¿ãããšãã§ããŸãã
--no-group-results
[SARIF 圢åŒã®ã¿] äžæã®å Žæããšã« 1 ã€ã®çµæã§ã¯ãªããã¡ãã»ãŒãžããšã« 1 ã€ã®çµæãçæããŸãã
--csv-location-format=<csvLocationFormat>
CSV åºåã§å Žæãçæãã圢åŒã 次ã®ãããã: uriãè¡åããªãã»ããé·ã (ããã©ã«ãå€: è¡å)
--dot-location-url-format=<dotLocationUrlFormat>
DOT åºåã§ãã¡ã€ã«ã®å Žæ URL ãçæãã圢åŒãå®çŸ©ããæžåŒèšå®æååã ãã¬ãŒã¹ ãã«ããŒãšããŠã{path} {start:line} {start:column} {end:line} {end:column}ã{offset}ã{length} ã䜿çšã§ããŸã
--[no-]sublanguage-file-coverage
[GitHub.com ããã³ GitHub Enterprise Server v3.12.0 以éã®ã¿] ãµãèšèªã®ãã¡ã€ã« ã«ãã¬ããžæ å ±ã䜿çšããŸãã ããã«ãããC ãš C++ãJava ãš KotlinãJavaScriptãTypeScript ãªã©ã® CodeQL ãšã¯ã¹ãã©ã¯ã¿ãŒãå ±æããèšèªã®åå¥ã®ãã¡ã€ã« ã«ãã¬ããžæ å ±ãèšç®ã衚瀺ããšã¯ã¹ããŒãããŸãã
v2.15.2
以éã§äœ¿çšã§ããŸãã
--sarif-category=<category>
[SARIF 圢åŒã®ã¿] [æšå¥š] SARIF åºåã«å«ãããã®åæã®ã«ããŽãªãæå®ããŸãã ã«ããŽãªã䜿çšããŠãåãã³ããããšãªããžã㪠(ãã ããç°ãªãèšèªãŸãã¯ã³ãŒãã®ç°ãªãéšå) ã§å®è¡ãããè€æ°ã®åæãåºå¥ã§ããŸãã
åãããŒãžã§ã³ã®ã³ãŒã ããŒã¹ãè€æ°ã®ç°ãªãæ¹æ³ã§åæã (ããšãã°ãèšèªãç°ãªãå Žå)ãã³ãŒã ã¹ãã£ã³ã§ãã¬ãŒã³ããŒã·ã§ã³ããããã« GitHub ã«çµæãã¢ããããŒãããå Žåããã®å€ã¯ååæéã§ç°ãªãå¿ èŠããããŸããããã«ãããã³ãŒã ã¹ãã£ã³ã«å¯ŸããŠãåæã§ã¯äºãã« ''眮ãæãã'' ã®ã§ã¯ãªã ''è£è¶³ãã'' ããšã瀺ãããŸã __ __ (ã³ãŒã ããŒã¹ã® ''ç°ãªã'' ããŒãžã§ã³ã«å¯ŸããŠåãåæã®å®è¡éã§å€ã®äžè²«æ§ãä¿ã€å¿ èŠããããŸã)ã__
ãã®å€ã¯ <run>.automationDetails.id
ããããã£ãšããŠè¡šç€ºãããŸã (ååšããªãå Žåã¯æ«å°Ÿã«ã¹ã©ãã·ã¥ã远å ããã)ã
--no-database-extension-packs
[詳现èšå®] ã³ãŒã ã¹ãã£ã³æ§æãã¡ã€ã«ããããŸãã¯åæãããã³ãŒãããŒã¹ã® 'extensions' ãã£ã¬ã¯ããªã«æ ŒçŽãããŠããæ¡åŒµãã¡ã€ã«ããããŒã¿ããŒã¹ãäœæããéã«ãããŒã¿ããŒã¹ã«æ ŒçŽãããŠããæ¡åŒµããã¯ãçç¥ããŸãã
--no-database-threat-models
[詳现èšå®] ã³ãŒã ã¹ãã£ã³æ§æãã¡ã€ã«ããããŒã¿ããŒã¹ãäœæããéã«ãããŒã¿ããŒã¹ã«æ ŒçŽãããŠããè åšã¢ãã«ã®æ§æãçç¥ããŸãã
--[no-]download
åæããåã«ãäžè¶³ããŠããã¯ãšãªãããŠã³ããŒãããŸãã
䜿çšããã¢ãã« ããã¯ãå¶åŸ¡ããããã®ãªãã·ã§ã³
--model-packs=<
name@range>...
è©äŸ¡ããã¯ãšãªãã«ã¹ã¿ãã€ãºããããã«ã¢ãã« ããã¯ãšããŠäœ¿çšãã CodeQL ããã¯åã®ãªã¹ã (ããããããªãã·ã§ã³ã®ããŒãžã§ã³ç¯å²ãå«ã)ã
䜿çšããè åšã¢ãã«ãå¶åŸ¡ããããã®ãªãã·ã§ã³
--threat-model=<name>...
æå¹ãŸãã¯ç¡å¹ã«ããè åšã¢ãã«ã®äžèЧã
åŒæ°ã¯è åšã¢ãã«ã®ååã§ãããå¿ èŠã«å¿ã㊠'!' ãä»ããããŸãã '!' ãä»ããŠããªãå Žåããã®ååä»ãè åšã¢ãã«ãšãã®ãã¹ãŠã®åå«ãæå¹ã«ãªããŸãã '!' ãä»ããŠããå Žåããã®ååä»ãè åšã¢ãã«ãšãã®ãã¹ãŠã®åå«ãç¡å¹ã«ãªããŸãã
"default" è åšã¢ãã«ã¯ããã©ã«ãã§æå¹ã«ãªã£ãŠããŸããã'--threat-model !default' ãæå®ããããšã§ç¡å¹ã«ããããšãã§ããŸãã
"all" è åšã¢ãã«ã䜿çšããŠããã¹ãŠã®è åšã¢ãã«ãæå¹ãŸãã¯ç¡å¹ã«ããããšãã§ããŸãã
--threat-model ãªãã·ã§ã³ã¯é çªã«åŠçãããŸãã ããšãã°ã'--threat-model local --threat-model !environment' ãæå®ãããšã'environment' è åšã¢ãã«ãé€ãã'local' ã°ã«ãŒãå ã®ãã¹ãŠã®è åšã¢ãã«ãæå¹ã«ãªããŸãã
ãã®ãªãã·ã§ã³ã¯ãè åšã¢ãã«ããµããŒãããèšèªã«ã®ã¿æå¹ã§ãã
v2.15.3
以éã§äœ¿çšã§ããŸãã
ã¯ãšãª ãšããªã¥ãšãŒã¿ãŒãå¶åŸ¡ããããã®ãªãã·ã§ã³
--[no-]tuple-counting
[詳现èšå®] ã¯ãšãª ãšããªã¥ãšãŒã¿ãŒ ãã°ã®åè©äŸ¡ã¹ãããã®ã¿ãã«æ°ã衚瀺ããŸãã --evaluator-log
ãªãã·ã§ã³ãæå®ãããšãã³ãã³ãã§çæãããããã¹ãããŒã¹ã®ãã°ãšæ§é åããã JSON ãã°ã®äž¡æ¹ã«ã¿ãã«æ°ãå«ãŸããŸã (ããã¯ãè€é㪠QL ã³ãŒãã®ããã©ãŒãã³ã¹æé©åã«åœ¹ç«ã¡ãŸã)ã
--timeout=<seconds>
[詳现èšå®] ã¯ãšãªè©äŸ¡ã®ã¿ã€ã ã¢ãŠãã®é·ããç§åäœã§èšå®ããŸãã
ã¿ã€ã ã¢ãŠãæ©èœã¯ãè€éãªã¯ãšãªã®è©äŸ¡ã« "ããªãé·ãæé" ããããã±ãŒã¹ãæ€åºããããšãç®çãšããŠããŸãã ã¯ãšãªã®è©äŸ¡ã«ãããåèšæéãå¶éããã®ã¯å¹æçãªæ¹æ³ã§ã¯ãããŸããã è©äŸ¡ã¯ãèšç®ã®åå¥ã«æéæå®ãããåéšåãã¿ã€ã ã¢ãŠãå ã«å®äºããéãç¶è¡ã§ããŸãã çŸåšããããã®åå¥ã«æéæå®ãããéšåã¯ãæé©åãããã¯ãšãªã® "RA ã¬ã€ã€ãŒ" ã§ãããå°æ¥å€æŽãããå¯èœæ§ããããŸãã
ã¿ã€ã ã¢ãŠããæå®ãããŠããªãå ŽåããŸãã¯ã¿ã€ã ã¢ãŠãã« 0 ãæå®ãããŠããå Žåãã¿ã€ã ã¢ãŠãã¯èšå®ãããŸãã (ããã©ã«ãã®ã¿ã€ã ã¢ãŠãã 5 åã§ãã codeql test run ãé€ããŸã)ã
-j, --threads=<num>
ãã®æ°ã®ã¹ã¬ãããã¯ãšãªã®è©äŸ¡ã«äœ¿çšããŸãã
ããã©ã«ãå€ã¯ 1 ã§ãã 0 ãæž¡ããŠãã³ã³ãã¥ãŒã¿ãŒäžã®ã³ã¢ããšã« 1 ã€ã®ã¹ã¬ããã䜿çšããããN ãæž¡ããŠãN åã®ã³ã¢ãæªäœ¿çšã®ãŸãŸã«ãããããããšãã§ããŸã (ãã ãããã®å Žåã§ããå°ãªããšã 1 ã€ã®ã¹ã¬ããã䜿çšãããŸã)ã
--[no-]save-cache
[詳现èšå®] äžéçµæããã£ã¹ã¯ ãã£ãã·ã¥ã«ç©æ¥µçã«æžã蟌ã¿ãŸãã ããã«ã¯ããå€ãã®æéããããã䜿çšããããã£ã¹ã¯é åã (ã¯ããã«) å€ããªããŸãããåæ§ã®ã¯ãšãªã®åŸç¶ã®å®è¡ãé«éåãããå¯èœæ§ããããŸãã
--[no-]expect-discarded-cache
[詳现èšå®] ã¯ãšãªã®å®è¡åŸã«ãã£ãã·ã¥ãç Žæ£ããããšããåæã«åºã¥ããŠãè©äŸ¡ããè¿°èªãšãã£ã¹ã¯ ãã£ãã·ã¥ã«æžã蟌ãå å®¹ãæ±ºå®ããŸãã
--[no-]keep-full-cache
[詳现èšå®] è©äŸ¡ãå®äºããåŸããã£ã¹ã¯ ãã£ãã·ã¥ãã¯ãªãŒã³ã¢ããããŸããã ããã«ãããåŸã§ codeql dataset cleanup ãŸã㯠codeql database cleanup ãå®è¡ããå Žåã«æéãç¯çŽã§ããŸãã
--max-disk-cache=<MB>
äžéã¯ãšãªçµæã®ãã£ã¹ã¯ ãã£ãã·ã¥ã§äœ¿çšã§ããæå€§å®¹éãèšå®ããŸãã
ãã®ãµã€ãºãæç€ºçã«æ§æãããŠããªãå Žåããšããªã¥ãšãŒã¿ãŒã«ãã£ãŠãããŒã¿ã»ããã®ãµã€ãºãšã¯ãšãªã®è€éãã«åºã¥ãã"劥åœãª" éã®ãã£ãã·ã¥ ã¹ããŒã¹ã䜿ãããšã詊ã¿ãããŸãã ãã®ããã©ã«ãã®äœ¿çšéãããé«ãå¶éãæç€ºçã«èšå®ãããšã远å ã®ãã£ãã·ã¥ãæå¹ã«ãªããåŸã®ã¯ãšãªãé«éåãããŸãã
--min-disk-free=<MB>
[詳现èšå®] ãã¡ã€ã« ã·ã¹ãã ã®ç©ºãé åã®ç®æšéãèšå®ããŸãã
--max-disk-cache
ãæå®ãããŠããªãå Žåããã¡ã€ã« ã·ã¹ãã ã®ç©ºã容éããã®å€ãäžåããšããšããªã¥ãšãŒã¿ãŒã«ãã£ãŠãã£ã¹ã¯ ãã£ãã·ã¥ã®äœ¿çšéãæããããšã詊ã¿ãããŸãã
--min-disk-free-pct=<pct>
[詳现èšå®] ãã¡ã€ã« ã·ã¹ãã ã®ç©ºãé åã®ç®æšå²åãèšå®ããŸãã
--max-disk-cache
ãæå®ãããŠããªãå Žåããã¡ã€ã« ã·ã¹ãã ã®ç©ºã容éããã®å²åãäžåããšããšããªã¥ãšãŒã¿ãŒã¯ãã£ã¹ã¯ ãã£ãã·ã¥ã®äœ¿çšéãæããããšããŸãã
--external=<pred>=<file.csv>
å€éšè¿°èª <pred> ã®è¡ãå«ã CSV ãã¡ã€ã«ã
è€æ°ã® --external
ãªãã·ã§ã³ãæå®ã§ããŸãã
--xterm-progress=<mode>
[詳现èšå®] xterm å¶åŸ¡ã·ãŒã±ã³ã¹ã䜿çšããŠãQL è©äŸ¡äžã«é²è¡ç¶æ³ã®è¿œè·¡ã衚瀺ãããã©ãããå¶åŸ¡ããŸãã æ¬¡ã®ããããã®å€ã«ãªããŸãã
no
: ãã¡ã³ã·ãŒãªé²è¡ç¶æ³ã衚瀺ããŸããããã 端æ«ãšèŠãªããŸãã
auto
(ããã©ã«ãå€): ã³ãã³ããé©åãªã¿ãŒããã«ã§å®è¡ãããŠãããã©ãããèªåæ€åºããŸãã__
yes
: ã¿ãŒããã«ã§ xterm å¶åŸ¡ã·ãŒã±ã³ã¹ãèªèã§ãããšèŠãªããŸãã ãã®æ©èœã¯ã¿ãŒããã«ã® "ãµã€ãº" ãèªåæ€åºã§ããããšã«ãŸã äŸåããŠãã (ç³ãèš³ãããŸããããWindows ã§ã¯å®è£
ãããŠããŸãã)ã-q
ãæå®ãããå Žåãç¡å¹ã«ãªããŸãã__
25x80
(ãŸãã¯ããã«é¡ããå€): yes
ãšåæ§ãã¿ãŒããã«ã®ãµã€ãºãæç€ºçã«æå®ããŸãã (yes
ãšã¯ç°ãªãããã㯠Windows ã§åäœããŸã)ã
25x80:/dev/pts/17
(ãŸãã¯ããã«é¡ããå€): stderr ãšã¯ "ç°ãªã" ã¿ãŒããã«ã«ãã¡ã³ã·ãŒãªé²è¡ç¶æ³ã衚瀺ããŸãã__ äž»ã«å
éšãã¹ãã«åœ¹ç«ã¡ãŸãã
ãšããªã¥ãšãŒã¿ãŒã«é¢ããæ§é åãã°ã®åºåãå¶åŸ¡ããããã®ãªãã·ã§ã³
--evaluator-log=<file>
[詳现èšå®] æå®ããããã¡ã€ã«ã«ãšããªã¥ãšãŒã¿ãŒã®ããã©ãŒãã³ã¹ã«é¢ããæ§é åãã°ãåºåããŸãã ãã®ãã° ãã¡ã€ã«ã®åœ¢åŒã¯ãäºåãªã倿Žãããå ŽåããããŸããã2 ã€ã®æ¹è¡æå (ããã©ã«ã) ãŸã㯠--evaluator-log-minify
ãªãã·ã§ã³ãæž¡ãããå Žå㯠1 ã€ã®æ¹è¡æåã§åºåããã JSON ãªããžã§ã¯ãã®ã¹ããªãŒã ã«ãªããŸãã ãã®ãã¡ã€ã«ã®ããå®å®ããæŠèŠãçæããããã« codeql generate log-summary <file>
ã䜿çšãããã¡ã€ã«ãçŽæ¥è§£æããªãããã«ããŠãã ããã ãã¡ã€ã«ãæ¢ã«ååšããŠããå Žåã¯äžæžããããŸãã
--evaluator-log-minify
[詳现èšå®] --evaluator-log
ãªãã·ã§ã³ãæž¡ãããå Žåããã®ãªãã·ã§ã³ãæž¡ããããšãçæããã JSON ãã°ã®ãµã€ãºã¯æå°éã«æããããŸããã人éãå€èªãã«ãããã®ã«ãªããŸãã
RAM ã®äœ¿çšãå¶åŸ¡ããããã®ãªãã·ã§ã³
-M, --ram=<MB>
ã¯ãšãª ãšããªã¥ãšãŒã¿ãŒã¯ãåèšã¡ã¢ãªäœ¿çšéããã®å€æªæºã«ç¶æããããšåªããŸãã (ãã ããå€§èŠæš¡ãªããŒã¿ããŒã¹ã§ã¯ãã¡ã¢ãªäžè¶³ã®å Žåã«ãã£ã¹ã¯ã«ã¹ã¯ããã§ãããã¡ã€ã« ããã¯ã¢ãã ã¡ã¢ãªãããã«ããããããå€ãç Žãããå¯èœæ§ããããŸã)ã
å€ã¯ 2048 MB (ã¡ã¬ãã€ã) 以äžã«ããå¿ èŠããããŸããå°ããå€ã¯ãééçã«åãäžããããŸãã
QL ã³ã³ãã€ã«ãå¶åŸ¡ããããã®ãªãã·ã§ã³
--warnings=<mode>
QL ã³ã³ãã€ã©ããã®èŠåãåŠçããæ¹æ³ã ã€ãã®ããããã§ãã
hide
: èŠåã衚瀺ããŸããã
show
(ããã©ã«ãå€): èŠåãåºåããŸãããã³ã³ãã€ã«ãç¶è¡ããŸãã__
error
: èŠåããšã©ãŒãšããŠæ±ããŸãã
--no-debug-info
ãããã°ç®çã§ RA ã«ãœãŒã¹ã®å Žææ å ±ãåºåããªãã§ãã ããã
--[no-]fast-compilation
[éæšå¥š] [詳现èšå®] ç¹ã«é床ã®é ãæé©åæé ãçç¥ããŸãã
--no-release-compatibility
[詳现èšå®] ç§»æ€æ§ãç ç²ã«ããŠãææ°ã®ã³ã³ãã€ã©æ©èœã䜿çšããŸãã
å Žåã«ãã£ãŠã¯ãæ°ãã QL èšèªæ©èœãšãšããªã¥ãšãŒã¿ãŒã®æé©åãããããã QL ã³ã³ãã€ã©ã«ãããŠããã©ã«ãã§æå¹ã«ãªãæ°ãªãªãŒã¹åã«ãQL ãšããªã¥ãšãŒã¿ãŒã«ãã£ãŠãµããŒããããŸãã ããã«ãããææ°ã® CodeQL ãªãªãŒã¹ã§ã¯ãšãªãéçºãããšãã«çããããã©ãŒãã³ã¹ããã³ãŒã ã¹ãã£ã³ãŸã㯠CI çµ±åã«ãŸã 䜿çšãããŠããå¯èœæ§ãããå°ãå€ããªãªãŒã¹ãšäžèŽãããããšãã§ããŸãã
ã¯ãšãªãä»ã® (以åãŸãã¯ä»¥éã®) CodeQL ãªãªãŒã¹ãšäºææ§ããããã©ãããæ°ã«ããå¿ èŠããªãå Žåã¯ããã®ãã©ã°ã䜿çšããŠã³ã³ãã€ã©ã®æè¿ã®æ¹åãæ©æã«æå¹ã«ããããšã§ãããã©ãŒãã³ã¹ãå€å°åäžãããããšãã§ããŸãã
ãªãªãŒã¹ã«æå¹ã«ãã¹ãæè¿ã®æ¹åããªãå Žåããã®ãªãã·ã§ã³ã¯éç¥ããããšãªãäœãå®è¡ããŸããã ãã®ãããã°ããŒãã« CodeQL æ§æãã¡ã€ã«ã§äžåºŠã«ãã¹ãŠèšå®ããŠãå®å šã§ãã
v2.11.1
以éã§äœ¿çšã§ããŸãã
--[no-]local-checking
䜿çšããã QL ãœãŒã¹ã®éšåã«å¯ŸããŠã®ã¿æåã®ãã§ãã¯ãå®è¡ããŸãã
--no-metadata-verification
QLDoc ã³ã¡ã³ãã«åã蟌ãŸããã¯ãšãª ã¡ã¿ããŒã¿ã®æå¹æ§ã¯ãã§ãã¯ãããŸããã
--compilation-cache-size=<MB>
[詳现èšå®] ã³ã³ãã€ã« ãã£ãã·ã¥ ãã£ã¬ã¯ããªã®ãããã©ã«ãã®æå€§ãµã€ãºããªãŒããŒã©ã€ãããŸãã
--fail-on-ambiguous-relation-name
[詳现èšå®] ã³ã³ãã€ã«äžã«ãããŸããªé¢ä¿åãçæãããå Žåãã³ã³ãã€ã«ã倱æãšããŸãã
ã³ã³ãã€ã«ç°å¢ãèšå®ããããã®ãªãã·ã§ã³
--search-path=<dir>[:<dir>...]
QL ããã¯ãèŠã€ããå¯èœæ§ããããã£ã¬ã¯ããªã®äžèЧã åãã£ã¬ã¯ããªã¯ãQL ãã㯠(ãŸãã¯ã«ãŒãã« .codeqlmanifest.json
ãã¡ã€ã«ãå«ãããã¯ã®ãã³ãã«)ããŸã㯠1 ã€ä»¥äžã®ãã®ãããªãã£ã¬ã¯ããªã®çŽæ¥ã®èŠªãã£ã¬ã¯ããªã®ããããã§ãã
ãã¹ã«è€æ°ã®ãã£ã¬ã¯ããªãå«ããå Žåã¯ããããã®é åºã§ããããã®éã®åªå é äœãå®çŸ©ããŸãã解決ããå¿ èŠãããããã¯åãè€æ°ã®ãã£ã¬ã¯ã㪠ããªãŒã§äžèŽããå Žåã¯ãæåã«æå®ãããã®ãåªå ãããŸãã
ãªãŒãã³ãœãŒã¹ã® CodeQL ãªããžããªã®ãã§ãã¯ã¢ãŠãã§ãããæå®ãããšãããã«ããèšèªã® 1 ã€ãç §äŒãããšãã«æ©èœããã¯ãã§ãã
CodeQL ãªããžããªããã¢ã³ããã¯ããã CodeQL ããŒã«ãã§ãŒã³ã®å
åŒãšããŠãã§ãã¯ã¢ãŠãããŠããå Žåããã®ãªãã·ã§ã³ãæå®ããå¿
èŠã¯ãããŸããããã®ãããªå
åŒãã£ã¬ã¯ããªã¯ãä»ã®æ¹æ³ã§ã¯èŠã€ãããªã QL ããã¯ã«ã€ããŠåžžã«æ€çŽ¢ãããŸã (ãã®ããã©ã«ããæ©èœããªãå Žåã¯ããŠãŒã¶ãŒããšã®æ§æãã¡ã€ã«ã§ --search-path
ãäžåºŠã ãèšå®ããããšã匷ããå§ãããŸã)ã
(泚: Windows ã§ã¯ããã¹ã®åºåãèšå·ã¯ ;
ã§ã)ã
--additional-packs=<dir>[:<dir>...]
ãã®ãã£ã¬ã¯ã㪠ãªã¹ããæå®ããå Žåããã£ã¬ã¯ããªã¯ã--search-path
ã§æå®ãããã®ããåã«ãããã¯ã«ã€ããŠæ€çŽ¢ãããŸãã ãããã®éã®é åºã¯éèŠã§ã¯ãããŸããããã®ãªã¹ãã® 2 ãæã§ããã¯åãèŠã€ãã£ãå Žåã¯ããšã©ãŒã§ãã
ããã¯ãããã©ã«ãã®ãã¹ã«ã衚瀺ãããæ°ããããŒãžã§ã³ã®ããã¯ãäžæçã«éçºããŠããå Žåã«åœ¹ç«ã¡ãŸãã äžæ¹ãæ§æãã¡ã€ã«ã§ãã®ãªãã·ã§ã³ããªãŒããŒã©ã€ãããããšã¯ "ãå§ãããŸãã"ãå éšã¢ã¯ã·ã§ã³ã«ãã£ãŠã¯ããã®ãªãã·ã§ã³ããªã³ã¶ãã©ã€ã§è¿œå ãããæ§ææžã¿ã®å€ããªãŒããŒã©ã€ããããŸãã__
(泚: Windows ã§ã¯ããã¹ã®åºåãèšå·ã¯ ;
ã§ã)ã
--library-path=<dir>[:<dir>...]
[詳现èšå®] QL ã©ã€ãã©ãªã®çã€ã³ããŒãæ€çŽ¢ãã¹ã«è¿œå ãããªãã·ã§ã³ã®ãã£ã¬ã¯ã㪠ãªã¹ãã ããã䜿ãå¿ èŠãããã®ã¯ãQL ããã¯ãšããŠããã±ãŒãžåãããŠããªã QL ã©ã€ãã©ãªã䜿çšããå Žåã®ã¿ã§ãã
(泚: Windows ã§ã¯ããã¹ã®åºåãèšå·ã¯ ;
ã§ã)ã
--dbscheme=<file>
[詳现èšå®] ã©ã® dbscheme ã¯ãšãªã«å¯ŸããŠã³ã³ãã€ã«ããå¿ èŠãããããæç€ºçã«å®çŸ©ããŸãã ããã¯ãèªåãäœãããŠãããã確信ããŠããåŒã³åºãå ã®ã¿ãæå®ããå¿ èŠããããŸãã
--compilation-cache=<dir>
[詳现èšå®] ã³ã³ãã€ã« ãã£ãã·ã¥ãšããŠäœ¿çšãã远å ã®ãã£ã¬ã¯ããªãæå®ããŸãã
--no-default-compilation-cache
[詳现èšå®] ã¯ãšãªãå«ã QL ããã¯ã CodeQL ããŒã«ãã§ãŒã³ ãã£ã¬ã¯ããªãªã©ã®æšæºã®å Žæã§ã³ã³ãã€ã« ãã£ãã·ã¥ã䜿çšããŸããã
CodeQL ããã±ãŒãž ãããŒãžã£ãŒãæ§æããããã®ãªãã·ã§ã³
--registries-auth-stdin
<registry_url>=<token> ãã¢ã®ã³ã³ãåºåãã®ãªã¹ããæž¡ããŠãGitHub Enterprise Server ã³ã³ãã㌠ã¬ãžã¹ããªã«å¯ŸããŠèªèšŒãè¡ããŸãã
ããšãã°ãhttps://containers.GHEHOSTNAME1/v2/=TOKEN1,https://containers.GHEHOSTNAME2/v2/=TOKEN2
ãæž¡ããŠã
2 ã€ã® GitHub Enterprise Server ã€ã³ã¹ã¿ã³ã¹ã«å¯ŸããŠèªèšŒãè¡ãããšãã§ããŸãã
ããã䜿ã£ãŠãCODEQL_REGISTRIES_AUTH ããã³ GITHUB_TOKEN ç°å¢å€æ°ããªãŒããŒã©ã€ãããŸãã github.com ã³ã³ãã㌠ã¬ãžã¹ããªã«å¯ŸããèªèšŒã®ã¿ãå¿
èŠãªå Žåã¯ã代ããã«ãããåçŽãª --github-auth-stdin
ãªãã·ã§ã³ã䜿ã£ãŠèªèšŒã§ããŸãã
--github-auth-stdin
æšæºå ¥åãä»ã㊠github.com GitHub Apps ããŒã¯ã³ãŸãã¯å人çšã¢ã¯ã»ã¹ ããŒã¯ã³ãæž¡ããŠãgithub.com ã³ã³ãã㌠ã¬ãžã¹ããªã«å¯ŸããŠèªèšŒãè¡ããŸãã
GitHub Enterprise Server ã³ã³ãã㌠ã¬ãžã¹ããªã«å¯ŸããŠèªèšŒãè¡ãã«ã¯ã--registries-auth-stdin
ãæž¡ãããCODEQL_REGISTRIES_AUTH ç°å¢å€æ°ã䜿ããŸãã
ããã䜿ã£ãŠãGITHUB_TOKEN ç°å¢å€æ°ããªãŒããŒã©ã€ãããŸãã
å ±éãªãã·ã§ã³
-h, --help
ãã®ãã«ã ããã¹ãã衚瀺ããŸãã
-J=<opt>
[詳现èšå®] ã³ãã³ããå®è¡ããŠãã JVM ã«ãªãã·ã§ã³ãæå®ããŸã
(ã¹ããŒã¹ãå«ããªãã·ã§ã³ã¯æ£ããåŠçãããªãããšã«æ³šæããŠãã ãã)ã
-v, --verbose
åºåãããé²è¡ç¶æ³ã¡ãã»ãŒãžã®æ°ã段éçã«å¢ãããŸãã
-q, --quiet
åºåãããé²è¡ç¶æ³ã¡ãã»ãŒãžã®æ°ã段éçã«æžãããŸãã
--verbosity=<level>
[詳现èšå®] 詳现ã¬ãã«ããerrorsãwarningsãprogressãprogress+ãprogress++ãprogress+++ ã®ããããã«æç€ºçã«èšå®ããŸãã -v
ãš -q
ããªãŒããŒã©ã€ããããŸãã
--logdir=<dir>
[詳现èšå®] ã¿ã€ã ã¹ã¿ã³ããšå®è¡äžã®ãµãã³ãã³ãã®ååãå«ãçæãããååã䜿çšããŠãæå®ããããã£ã¬ã¯ããªå ã® 1 ã€ãŸãã¯è€æ°ã®ãã¡ã€ã«ã«è©³çްãªãã°ãæžã蟌ã¿ãŸã
(å®å
šã«å¶åŸ¡ã§ããååã§ãã° ãã¡ã€ã«ãæžã蟌ãã«ã¯ã代ããã« --log-to-stderr
ãæå®ããå¿
èŠã«å¿ã㊠stderr ããªãã€ã¬ã¯ãããŸã)ã
--common-caches=<dir>
[[詳现èšå®] ããŠã³ããŒããã QL ããã¯ãã³ã³ãã€ã«æžã¿ã¯ãšãª ãã©ã³ãªã©ãCLI ã®è€æ°ã®å®è¡éã«ä¿æãããããã£ã¹ã¯äžã§ãã£ãã·ã¥ãããããŒã¿ã®å Žæãå¶åŸ¡ããŸãã æç€ºçã«èšå®ãããªãå Žåãããã©ã«ãã§ã¯ãŠãŒã¶ãŒã®ããŒã ãã£ã¬ã¯ããªã«ååãä»ãããã .codeql
ãã£ã¬ã¯ããªã«ãªããŸãããŸã ååšããªãå Žåã¯äœæãããŸãã
v2.15.2
以éã§äœ¿çšã§ããŸãã