Skip to content

Commit 4f5ecf1

Browse files
Init
0 parents  commit 4f5ecf1

19 files changed

Lines changed: 456 additions & 0 deletions

‎.github/workflows/codeql.yml‎

Lines changed: 99 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,99 @@
1+
# For most projects, this workflow file will not need changing; you simply need
2+
# to commit it to your repository.
3+
#
4+
# You may wish to alter this file to override the set of languages analyzed,
5+
# or to provide custom queries or build logic.
6+
#
7+
# ******** NOTE ********
8+
# We have attempted to detect the languages in your repository. Please check
9+
# the `language` matrix defined below to confirm you have the correct set of
10+
# supported CodeQL languages.
11+
#
12+
name: "CodeQL Advanced"
13+
14+
on:
15+
push:
16+
branches: [ "main" ]
17+
pull_request:
18+
branches: [ "main" ]
19+
schedule:
20+
- cron: '31 1 * * 3'
21+
22+
jobs:
23+
analyze:
24+
name: Analyze (${{ matrix.language }})
25+
# Runner size impacts CodeQL analysis time. To learn more, please see:
26+
# - https://gh.io/recommended-hardware-resources-for-running-codeql
27+
# - https://gh.io/supported-runners-and-hardware-resources
28+
# - https://gh.io/using-larger-runners (GitHub.com only)
29+
# Consider using larger runners or machines with greater resources for possible analysis time improvements.
30+
runs-on: ${{ (matrix.language == 'swift' && 'macos-latest') || 'ubuntu-latest' }}
31+
permissions:
32+
# required for all workflows
33+
security-events: write
34+
35+
# required to fetch internal or private CodeQL packs
36+
packages: read
37+
38+
# only required for workflows in private repositories
39+
actions: read
40+
contents: read
41+
42+
strategy:
43+
fail-fast: false
44+
matrix:
45+
include:
46+
- language: java-kotlin
47+
build-mode: none # This mode only analyzes Java. Set this to 'autobuild' or 'manual' to analyze Kotlin too.
48+
# CodeQL supports the following values keywords for 'language': 'actions', 'c-cpp', 'csharp', 'go', 'java-kotlin', 'javascript-typescript', 'python', 'ruby', 'rust', 'swift'
49+
# Use `c-cpp` to analyze code written in C, C++ or both
50+
# Use 'java-kotlin' to analyze code written in Java, Kotlin or both
51+
# Use 'javascript-typescript' to analyze code written in JavaScript, TypeScript or both
52+
# To learn more about changing the languages that are analyzed or customizing the build mode for your analysis,
53+
# see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/customizing-your-advanced-setup-for-code-scanning.
54+
# If you are analyzing a compiled language, you can modify the 'build-mode' for that language to customize how
55+
# your codebase is analyzed, see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages
56+
steps:
57+
- name: Checkout repository
58+
uses: actions/checkout@v4
59+
60+
# Add any setup steps before running the `github/codeql-action/init` action.
61+
# This includes steps like installing compilers or runtimes (`actions/setup-node`
62+
# or others). This is typically only required for manual builds.
63+
# - name: Setup runtime (example)
64+
# uses: actions/setup-example@v1
65+
66+
# Initializes the CodeQL tools for scanning.
67+
- name: Initialize CodeQL
68+
uses: github/codeql-action/init@v4
69+
with:
70+
languages: ${{ matrix.language }}
71+
build-mode: ${{ matrix.build-mode }}
72+
# If you wish to specify custom queries, you can do so here or in a config file.
73+
# By default, queries listed here will override any specified in a config file.
74+
# Prefix the list here with "+" to use these queries and those in the config file.
75+
76+
# For more details on CodeQL's query packs, refer to: https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/configuring-code-scanning#using-queries-in-ql-packs
77+
queries: security-extended,security-and-quality
78+
79+
# If the analyze step fails for one of the languages you are analyzing with
80+
# "We were unable to automatically build your code", modify the matrix above
81+
# to set the build mode to "manual" for that language. Then modify this step
82+
# to build your code.
83+
# ℹ️ Command-line programs to run using the OS shell.
84+
# 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun
85+
- name: Run manual build steps
86+
if: matrix.build-mode == 'manual'
87+
shell: bash
88+
run: |
89+
echo 'If you are using a "manual" build mode for one or more of the' \
90+
'languages you are analyzing, replace this with the commands to build' \
91+
'your code, for example:'
92+
echo ' make bootstrap'
93+
echo ' make release'
94+
exit 1
95+
96+
- name: Perform CodeQL Analysis
97+
uses: github/codeql-action/analyze@v4
98+
with:
99+
category: "/language:${{matrix.language}}"

‎pom.xml‎

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
<?xml version="1.0" encoding="UTF-8"?>
2+
<project xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd" xmlns="http://maven.apache.org/POM/4.0.0"
3+
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
4+
<modelVersion>4.0.0</modelVersion>
5+
<groupId>es.uniovi.reflection</groupId>
6+
<artifactId>SyntheticProgram_CMU_DCL53</artifactId>
7+
<version>1.0-SNAPSHOT</version>
8+
9+
<properties>
10+
<maven.compiler.release>22</maven.compiler.release>
11+
</properties>
12+
</project>
Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
package es.uniovi.reflection.dcl_53.compliant;
2+
3+
public class AuxiliaryCompliant {
4+
public OtherAuxCompliant otherAuxComplex;
5+
public AuxiliaryCompliant aux;
6+
7+
}
Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
package es.uniovi.reflection.dcl_53.compliant;
2+
3+
4+
public class DCL_53CompliantObjects {
5+
public AuxiliaryCompliant auxiliary;
6+
public OtherAuxCompliant otherAux;
7+
8+
public void sameObject() {
9+
this.otherAux = new OtherAuxCompliant();
10+
System.out.println(this.otherAux);
11+
}
12+
13+
public void differentObjects4() {
14+
DCL_53CompliantObjects obj = new DCL_53CompliantObjects();
15+
obj.auxiliary.otherAuxComplex.field = 5;
16+
System.out.println(obj.otherAux.field);
17+
}
18+
}
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
package es.uniovi.reflection.dcl_53.compliant;
2+
3+
4+
public class DCL_53CompliantObjects2 {
5+
public AuxiliaryCompliant auxiliary;
6+
public OtherAuxCompliant otherAux;
7+
8+
public void differentObjects2() {
9+
auxiliary.otherAuxComplex = new OtherAuxCompliant();
10+
System.out.println(otherAux);
11+
}
12+
}
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
package es.uniovi.reflection.dcl_53.compliant;
2+
3+
4+
public class DCL_53CompliantObjects3 {
5+
public AuxiliaryCompliant auxiliary, aux;
6+
7+
8+
public void differentObjects3() {
9+
this.auxiliary.aux.otherAuxComplex = new OtherAuxCompliant();
10+
System.out.println(this.aux.aux.otherAuxComplex);
11+
}
12+
13+
}
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
package es.uniovi.reflection.dcl_53.compliant;
2+
3+
4+
public class DCL_53CompliantObjects4 {
5+
public AuxiliaryCompliant auxiliary;
6+
7+
public void usedOutside() {
8+
auxiliary.otherAuxComplex = new OtherAuxCompliant();
9+
System.out.println(auxiliary.otherAuxComplex);
10+
}
11+
12+
}
Lines changed: 72 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,72 @@
1+
package es.uniovi.reflection.dcl_53.compliant;
2+
3+
public class DLC_53Compliant {
4+
private int oneUseAndFiveUnconds;
5+
private int threeUncondsButOneCond;
6+
private int usedBeforeAssignedInLoop;
7+
private int twoUncondsButOneUseWithNewObject;
8+
private int oneUncondButOneAccessFromField;
9+
public int publicAttr;
10+
protected int protectedAttr;
11+
private int neverReferencedAttr;
12+
13+
public void attrScope() {
14+
DLC_53Compliant z = null;
15+
z.oneUseAndFiveUnconds = 0;
16+
this.threeUncondsButOneCond = 7;
17+
System.out.println(z.oneUseAndFiveUnconds + threeUncondsButOneCond);
18+
}
19+
public void ifTest(String p) {
20+
21+
if (p == null) {
22+
for (;;) {//
23+
p = p + "OO";//
24+
if (oneUseAndFiveUnconds == 4) {//
25+
p = null;//
26+
System.out.println("");//
27+
} else
28+
System.out.println(p);
29+
System.out.println("KK");//
30+
}
31+
}
32+
System.out.println("LAST");//
33+
}
34+
35+
public void attrScopeBis() {
36+
oneUseAndFiveUnconds = 3;
37+
if ("NJHI".length() == 8)
38+
threeUncondsButOneCond = 4;
39+
System.out.println(oneUseAndFiveUnconds + threeUncondsButOneCond);
40+
}
41+
42+
public void attrScopeBisBis() {
43+
if ("NJHI".length() == 8) {
44+
threeUncondsButOneCond = 4;
45+
oneUseAndFiveUnconds = 3;
46+
System.out.println(oneUseAndFiveUnconds + threeUncondsButOneCond);
47+
}
48+
}
49+
50+
public void attrScopeLoop() {
51+
52+
for (int i = 0; i < 50; i++) {
53+
oneUseAndFiveUnconds = 3;
54+
55+
System.out.println(oneUseAndFiveUnconds + this.usedBeforeAssignedInLoop);
56+
57+
usedBeforeAssignedInLoop = 4;
58+
}
59+
}
60+
private DLC_53Compliant z, y;
61+
public void attrUse() {
62+
y.oneUncondButOneAccessFromField = 3;
63+
System.out.println(z.oneUncondButOneAccessFromField + y.oneUncondButOneAccessFromField);
64+
}
65+
66+
public void setA(int i) {
67+
oneUseAndFiveUnconds = i;
68+
new DLC_53Compliant().twoUncondsButOneUseWithNewObject = 3;
69+
twoUncondsButOneUseWithNewObject = 4;
70+
System.out.println(new DLC_53Compliant().twoUncondsButOneUseWithNewObject);
71+
}
72+
}
Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
package es.uniovi.reflection.dcl_53.compliant;
2+
3+
public class DLC_53CompliantSwitch {
4+
private final int FINAL_INT=0;
5+
private final int OTHER_FINAL ;
6+
7+
public DLC_53CompliantSwitch(){
8+
OTHER_FINAL=1;
9+
}
10+
11+
public Object attrUsedInSwitch(int value) {
12+
switch (value) {
13+
case FINAL_INT:
14+
return new Object();
15+
case 2:
16+
return OTHER_FINAL;
17+
case 3:
18+
return new DLC_53CompliantSwitch();
19+
}
20+
return null;
21+
}
22+
}
Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
package es.uniovi.reflection.dcl_53.compliant;
2+
3+
public class OtherAuxCompliant {
4+
public int field;
5+
6+
}

0 commit comments

Comments
 (0)