Repository navigation
[refactor] Rework analyzer labeling - #5127
Open
gulyasgergely902 wants to merge 1 commit into
Open
gulyasgergely902 wants to merge 1 commit into
gulyasgergely902 wants to merge 1 commit into
Conversation
gulyasgergely902
force-pushed
the
rework-analyzer-labeling
branch
3 times, most recently
from
October 7, 2026 09:31
bfab3bd to
dc342dd
Compare
This change reworks how checker labels are working inside CodeChecker. The guideline files are now separated from the rules. Each type of rule (CWE, Sei-Cert, OWASP, etc.) have a separate file collecting all the rules the given type has. Every rule has its ID and optionally its title and URL. The guideline files are now only serves as a collection of rule IDs. Label files also got reworked: containing less data for any given checker, guideline definitions are discarded and now derived from the rule ID based on which guideline contains the given rule. Every rule is now added by `rule:<rule_name>`. Profiles are also reworked, the generic profiles (default, sensitive and extreme) are now contained in eachother meaning only the smallest set must be defined and the checker will automatically be in every broader set. E.g. if a checker must be in sensitive and extreme, only sensitive has to be defined, it will be in extreme automatically. This change was made to prevent user mistakes when editing labelling, guidelines or rules. Every component (rules, guidelines, labels) has its own source of truth now which makes easier the further development.
gulyasgergely902
force-pushed
the
rework-analyzer-labeling
branch
from
October 7, 2026 09:41
dc342dd to
57bad77
Compare
barnabasdomozi
requested changes
Oct 8, 2026
barnabasdomozi
left a comment
Collaborator
There was a problem hiding this comment.
Please fix the failing test cases.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This change reworks how checker labels are working inside CodeChecker.
The guideline files are now separated from the rules. Each type of rule (CWE, Sei-Cert, OWASP, etc.) have a separate file collecting all the rules the given type has. Every rule has its ID and optionally its title and URL. The guideline files are now only serves as a collection of rule IDs.
Label files also got reworked: containing less data for any given checker, guideline definitions are discarded and now derived from the rule ID based on which guideline contains the given rule. Every rule is now added by
rule:<rule_name>. Profiles are also reworked, the generic profiles (default, sensitive and extreme) are now contained in eachother meaning only the smallest set must be defined and the checker will automatically be in every broader set. E.g. if a checker must be in sensitive and extreme, only sensitive has to be defined, it will be in extreme automatically.This change was made to prevent user mistakes when editing labelling, guidelines or rules. Every component (rules, guidelines, labels) has its own source of truth now which makes easier the further development.