From dbdc7ea7f06d6f013c812ca815a4f9b9b787f79d Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Sat, 11 Jul 2026 07:06:25 +0000 Subject: [PATCH] ci(codeql): exclude py/log-injection from Python analysis The Security/CWE-117/LogInjection.ql query has been consistently failing with 'Result set is larger than the limit of 2GiB' on every scheduled and push run for the last several days, breaking CodeQL / Analyze (python) on main and litellm_internal_staging. This is the same known CodeQL scaling limitation already documented for py/clear-text-logging-sensitive-data (CWE-312) and py/polynomial-redos (CWE-730): taint-flow queries produce combinatorial path explosion on codebases with pervasive logging like LiteLLM. Extend the existing exclusion pattern to cover py/log-injection. Co-authored-by: Krrish Dholakia --- .github/codeql/codeql-config.yml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/.github/codeql/codeql-config.yml b/.github/codeql/codeql-config.yml index 36d70c1d746..b167171cc31 100644 --- a/.github/codeql/codeql-config.yml +++ b/.github/codeql/codeql-config.yml @@ -4,7 +4,7 @@ queries: - uses: security-and-quality # Known OOM queries on large Python codebases: -# CodeQL builds a full data flow graph in memory. These two queries trace +# CodeQL builds a full data flow graph in memory. These queries trace # sensitive data through every log call / regex pattern, causing combinatorial # path explosion on codebases with extensive logging like LiteLLM (>2 GiB # result sets). This is a known CodeQL scaling limitation, not a code issue. @@ -14,6 +14,8 @@ query-filters: id: py/clear-text-logging-sensitive-data # CWE-312 - exclude: id: py/polynomial-redos # CWE-730 + - exclude: + id: py/log-injection # CWE-117 paths-ignore: - tests