JS: Add support for file-scoped MaD models - #22264
Open
asgerf wants to merge 5 commits into
Open
Conversation
For codebase-specific models it's useful to be able to write models for specific files, without an NPM package boundary around it. But previously it was only possible to use NPM package exports as the starting point of a model. This adds the type `file:<path>` which uses imports of the given file as the starting point, exactly as it if had been importing aname NPM package.
Contributor
There was a problem hiding this comment.
Pull request overview
Adds file-scoped JavaScript models using file:<path> type names.
Changes:
- Resolves model entry points from repository-relative file imports.
- Adds source-model test coverage.
- Documents the new model syntax.
Show a summary per file
| File | Description |
|---|---|
ApiGraphModelsSpecific.qll |
Resolves file-scoped model entry points. |
test.ext.yml |
Defines a file-scoped source model. |
test.expected |
Records the expected taint-flow result. |
importFileBasedModel.js |
Exercises the modeled import. |
foo/bar/baz.js |
Provides the imported test module. |
2026-07-31-file-scoped-models.md |
Announces the analysis enhancement. |
customizing-library-models-for-javascript.rst |
Documents file-scoped model syntax. |
Review details
- Files reviewed: 7/7 changed files
- Comments generated: 1
- Review effort level: Balanced
Co-authored-by: Copilot Autofix powered by AI <[email protected]>
hvitved
previously approved these changes
Aug 3, 2026
hvitved
left a comment
Contributor
There was a problem hiding this comment.
Looks good to me, just one QL doc that may need updating.
| ) | ||
| } | ||
|
|
||
| /** Gets the name of the path variable. */ |
Contributor
There was a problem hiding this comment.
This QL doc seems a bit weird to me.
Contributor
Author
There was a problem hiding this comment.
You're right, that was a bit of copy pasta. Fixed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Makes it possible to write models for specific files within a codebase, by using a package name of form
file:<path>. Previously it was only possible to model endpoints across a package-boundary, but now any file can effectively be treated as if it was a package. The model will obviously stop working if the mentioned file is moved/renamed, so it is still better to use real package names if at all possible.Fixes #22206