Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

LGTM.com - false positive - missing names imported by function #9642

Open
jlaehne opened this issue Jun 21, 2022 · 2 comments
Open

LGTM.com - false positive - missing names imported by function #9642

jlaehne opened this issue Jun 21, 2022 · 2 comments

Comments

@jlaehne
Copy link

@jlaehne jlaehne commented Jun 21, 2022

Description of the false positive

The name 'eds' is exported by __all__ but is not defined.

This and the other missing names are imported by a function below and thus not recognized.

URL to the alert on the project page on LGTM.com
https://lgtm.com/projects/g/hyperspy/hyperspy/snapshot/508d6caf0efc5c0a258c67f5c2ecab8a977c413e/files/hyperspy/api_nogui.py?sort=name&dir=ASC&mode=heatmap#xadcdd5256a8f42d0:1

@RasmusWL
Copy link
Member

@RasmusWL RasmusWL commented Jun 22, 2022

Indeed, this looks like a false positive. Thank you for reporting it!

Our current focus is on improving our security analysis. Because your report does not relate to a security query, we will put this on our backlog and prioritize it if we get enough reports of the same underlying issue in other projects. If you think that your report is related to our security analysis, please clarify that in a comment. Either way, we'll let you know here as soon as it's fixed!

I also want to point out that both GitHub Code Scanning and LGTM.com have facilities for suppressing individual alerts or disabling a query.

@jlaehne jlaehne changed the title LGTM.com - false positive LGTM.com - false positive - missing names imported by function Jun 22, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants