Fixed findings

List of Findings

Error: GCC_ANALYZER_WARNING (CWE-457): [#def1]
flatpak-1.16.1/common/flatpak-json-oci-private.h:87:1: warning[-Wanalyzer-use-of-uninitialized-value]: use of uninitialized value ‘versioned’
flatpak-1.16.1/app/flatpak-builtins-build-import-bundle.c:57:1: enter_function: entry to ‘import_oci’
flatpak-1.16.1/app/flatpak-builtins-build-import-bundle.c:74:6: branch_false: following ‘false’ branch...
flatpak-1.16.1/app/flatpak-builtins-build-import-bundle.c:77:11: branch_false: ...to here
flatpak-1.16.1/app/flatpak-builtins-build-import-bundle.c:78:6: branch_false: following ‘false’ branch...
flatpak-1.16.1/app/flatpak-builtins-build-import-bundle.c:81:7: branch_false: ...to here
flatpak-1.16.1/app/flatpak-builtins-build-import-bundle.c:84:10: branch_false: following ‘false’ branch...
flatpak-1.16.1/app/flatpak-builtins-build-import-bundle.c:100:3: branch_false: ...to here
flatpak-1.16.1/app/flatpak-builtins-build-import-bundle.c:105:6: branch_false: following ‘false’ branch...
flatpak-1.16.1/app/flatpak-builtins-build-import-bundle.c:111:58: branch_false: ...to here
flatpak-1.16.1/app/flatpak-builtins-build-import-bundle.c:113:6: branch_false: following ‘false’ branch...
flatpak-1.16.1/app/flatpak-builtins-build-import-bundle.c:116:12: branch_false: ...to here
flatpak-1.16.1/app/flatpak-builtins-build-import-bundle.c:117:6: branch_false: following ‘false’ branch...
flatpak-1.16.1/app/flatpak-builtins-build-import-bundle.c:120:7: branch_false: ...to here
flatpak-1.16.1/app/flatpak-builtins-build-import-bundle.c:120:6: branch_true: following ‘true’ branch...
flatpak-1.16.1/app/flatpak-builtins-build-import-bundle.c:122:7: branch_true: ...to here
flatpak-1.16.1/app/flatpak-builtins-build-import-bundle.c:66:30: call_function: inlined call to ‘glib_autoptr_cleanup_FlatpakOciImage’ from ‘import_oci’
flatpak-1.16.1/app/flatpak-builtins-build-import-bundle.c:65:34: call_function: inlined call to ‘glib_autoptr_cleanup_FlatpakOciVersioned’ from ‘import_oci’
#   85|   
#   86|   #define FLATPAK_TYPE_OCI_VERSIONED flatpak_oci_versioned_get_type ()
#   87|-> G_DECLARE_FINAL_TYPE (FlatpakOciVersioned, flatpak_oci_versioned, FLATPAK_OCI, VERSIONED, FlatpakJson)
#   88|   
#   89|   struct _FlatpakOciVersioned

Error: GCC_ANALYZER_WARNING (CWE-457): [#def2]
flatpak-1.16.1/common/flatpak-json-oci-private.h:177:1: warning[-Wanalyzer-use-of-uninitialized-value]: use of uninitialized value ‘image_config’
flatpak-1.16.1/app/flatpak-builtins-build-import-bundle.c:72:13: throw: if ‘g_file_get_uri’ throws an exception...
flatpak-1.16.1/app/flatpak-builtins-build-import-bundle.c:66:30: call_function: inlined call to ‘glib_autoptr_cleanup_FlatpakOciImage’ from ‘import_oci’
#  175|   
#  176|   #define FLATPAK_TYPE_OCI_IMAGE flatpak_oci_image_get_type ()
#  177|-> G_DECLARE_FINAL_TYPE (FlatpakOciImage, flatpak_oci_image, FLATPAK, OCI_IMAGE, FlatpakJson)
#  178|   
#  179|   typedef struct

Scan Properties

analyzer-version-clippy1.92.0
analyzer-version-cppcheck2.19.1
analyzer-version-gcc16.0.0
analyzer-version-gcc-analyzer16.0.0
analyzer-version-shellcheck0.11.0
analyzer-version-unicontrol0.0.2
diffbase-analyzer-version-clippy1.92.0
diffbase-analyzer-version-cppcheck2.19.1
diffbase-analyzer-version-gcc16.0.0
diffbase-analyzer-version-gcc-analyzer16.0.0
diffbase-analyzer-version-shellcheck0.11.0
diffbase-analyzer-version-unicontrol0.0.2
diffbase-enabled-pluginsclippy, cppcheck, gcc, shellcheck, unicontrol
diffbase-exit-code0
diffbase-hostip-172-16-1-136.us-west-2.compute.internal
diffbase-known-false-positives/usr/share/csmock/known-false-positives.js
diffbase-known-false-positives-rpmknown-false-positives-0.0.0.20250521.132812.g8eff701.main-1.el9.noarch
diffbase-mock-configfedora-rawhide-x86_64
diffbase-project-nameflatpak-1.17.2-1.fc44
diffbase-store-results-to/tmp/tmpu65bgz7j/flatpak-1.17.2-1.fc44.tar.xz
diffbase-time-created2026-01-08 16:26:56
diffbase-time-finished2026-01-08 16:31:08
diffbase-toolcsmock
diffbase-tool-args'/usr/bin/csmock' '-r' 'fedora-rawhide-x86_64' '-t' 'gcc,cppcheck,clippy,shellcheck,unicontrol' '-o' '/tmp/tmpu65bgz7j/flatpak-1.17.2-1.fc44.tar.xz' '--gcc-analyze' '--unicontrol-notests' '--unicontrol-bidi-only' '--install' 'pam' '--gcc-analyzer-bin=/usr/bin/gcc' '/tmp/tmpu65bgz7j/flatpak-1.17.2-1.fc44.src.rpm'
diffbase-tool-versioncsmock-3.8.3.20251215.161544.g62de9a5-1.el9
enabled-pluginsclippy, cppcheck, gcc, shellcheck, unicontrol
exit-code0
hostip-172-16-1-136.us-west-2.compute.internal
known-false-positives/usr/share/csmock/known-false-positives.js
known-false-positives-rpmknown-false-positives-0.0.0.20250521.132812.g8eff701.main-1.el9.noarch
mock-configfedora-rawhide-x86_64
project-nameflatpak-1.16.1-1.fc43
store-results-to/tmp/tmpzftwbftc/flatpak-1.16.1-1.fc43.tar.xz
time-created2026-01-08 16:21:48
time-finished2026-01-08 16:26:22
titleFixed findings
toolcsmock
tool-args'/usr/bin/csmock' '-r' 'fedora-rawhide-x86_64' '-t' 'gcc,cppcheck,clippy,shellcheck,unicontrol' '-o' '/tmp/tmpzftwbftc/flatpak-1.16.1-1.fc43.tar.xz' '--gcc-analyze' '--unicontrol-notests' '--unicontrol-bidi-only' '--install' 'pam' '--gcc-analyzer-bin=/usr/bin/gcc' '/tmp/tmpzftwbftc/flatpak-1.16.1-1.fc43.src.rpm'
tool-versioncsmock-3.8.3.20251215.161544.g62de9a5-1.el9