mirror of
https://github.com/BerriAI/litellm.git
synced 2026-09-07 08:26:10 +00:00
ci(codeql): exclude py/log-injection from Python analysis
The Security/CWE-117/LogInjection.ql query has been consistently failing with 'Result set is larger than the limit of 2GiB' on every scheduled and push run for the last several days, breaking CodeQL / Analyze (python) on main and litellm_internal_staging. This is the same known CodeQL scaling limitation already documented for py/clear-text-logging-sensitive-data (CWE-312) and py/polynomial-redos (CWE-730): taint-flow queries produce combinatorial path explosion on codebases with pervasive logging like LiteLLM. Extend the existing exclusion pattern to cover py/log-injection. Co-authored-by: Krrish Dholakia <krrish-berri-2@users.noreply.github.com>
This commit is contained in:
parent
c15891fc98
commit
dbdc7ea7f0
1 changed files with 3 additions and 1 deletions
4
.github/codeql/codeql-config.yml
vendored
4
.github/codeql/codeql-config.yml
vendored
|
|
@ -4,7 +4,7 @@ queries:
|
|||
- uses: security-and-quality
|
||||
|
||||
# Known OOM queries on large Python codebases:
|
||||
# CodeQL builds a full data flow graph in memory. These two queries trace
|
||||
# CodeQL builds a full data flow graph in memory. These queries trace
|
||||
# sensitive data through every log call / regex pattern, causing combinatorial
|
||||
# path explosion on codebases with extensive logging like LiteLLM (>2 GiB
|
||||
# result sets). This is a known CodeQL scaling limitation, not a code issue.
|
||||
|
|
@ -14,6 +14,8 @@ query-filters:
|
|||
id: py/clear-text-logging-sensitive-data # CWE-312
|
||||
- exclude:
|
||||
id: py/polynomial-redos # CWE-730
|
||||
- exclude:
|
||||
id: py/log-injection # CWE-117
|
||||
|
||||
paths-ignore:
|
||||
- tests
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue