Open
Description
Description of the false positive
CodeQL incorrectly identifies dataflow occurring from a constant value when a tuple is being destructured.
Code samples or links to source code
Here's it's very clear that status
will always be 200
on this data flow path, but CodeQL incorrectly believes there is dataflow from the res.json()
to the status
variable.
https://github.com/Chainguard-Wolfi-Bites-Back/istio__istio/security/code-scanning/5