diff --git a/.github/codeql-queries/PotentiallyDangerousFunction.ql b/.github/codeql-queries/PotentiallyDangerousFunction.ql index 40e2bbb6f9e..abd3f87a342 100644 --- a/.github/codeql-queries/PotentiallyDangerousFunction.ql +++ b/.github/codeql-queries/PotentiallyDangerousFunction.ql @@ -52,6 +52,12 @@ predicate potentiallyDangerousFunction(Function f, string message) { ) or ( f.getQualifiedName() = "basename" and message = "Call basename() is icky. Use path_extract_filename() instead." + ) or ( + f.getQualifiedName() = "setmntent" and + message = "Libmount parser is used instead, specifically libmount_parse_fstab()." + ) or ( + f.getQualifiedName() = "getmntent" and + message = "Libmount parser is used instead, specifically mnt_table_next_fs()." ) }