Ensure that upgrades can be resolved even when the upgrades pack is not in the workspace. This is the situation when the core libraries are resolved from the package cache. This change works because `qlProgram.libraryPath` is the resolved search path for compiling the query. We are guaranteed that the appropriate core libraries are included in this query. Note that this change avoids using extra source folders from the workspace. Previously without using packages, we assume that all relevant query paths are already inside the workspace. With packaging, this is no longer the case. It is theoretically possible that there will be extra upgrade scripts that are not on the resolved search path, but are included in the workspace. This situation would have worked in the past.This is not a situation that we expect to happen in practice. And if this does happen, I believe this is an error and all upgrades should be added explicitly to the search path. An open question is if this will work with downgrade scripts. If it does not, then I don't think this change makes things any worse than before.
CodeQL for Visual Studio Code
This project is an extension for Visual Studio Code that adds rich language support for CodeQL. It's used to find problems in code bases using CodeQL. It's written primarily in TypeScript.
The extension is released. You can download it from the Visual Studio Marketplace.
To see what has changed in the last few versions of the extension, see the Changelog.
Features
- Enables you to use CodeQL to query databases and discover problems in codebases.
- Shows the flow of data through the results of path queries, which is essential for triaging security results.
- Provides an easy way to run queries from the large, open source repository of CodeQL security queries.
- Adds IntelliSense to support you writing and editing your own CodeQL query and library files.
Project goals and scope
This project will track new feature development in CodeQL and, whenever appropriate, bring that functionality to the Visual Studio Code experience.
Contributing
This project welcomes contributions. See CONTRIBUTING.md for details on how to build, install, and contribute.
License
The CodeQL extension for Visual Studio Code is licensed under the MIT License. The version of CodeQL used by the CodeQL extension is subject to the CodeQL Research Terms & Conditions.
When using the GitHub logos, be sure to follow the GitHub logo guidelines.