<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Codeql on Start AI Tools - Presented by Intent Solutions</title><link>https://startaitools.com/tags/codeql/</link><description>Recent content in Codeql on Start AI Tools - Presented by Intent Solutions</description><generator>Hugo</generator><language>en-US</language><copyright>Intent Solutions. All rights reserved.</copyright><lastBuildDate>Sun, 27 Sep 2026 10:00:00 -0500</lastBuildDate><atom:link href="https://startaitools.com/tags/codeql/index.xml" rel="self" type="application/rss+xml"/><item><title>Use the Primitive, Not the Patch: Closing a CodeQL Backlog by Class</title><link>https://startaitools.com/posts/use-the-primitive-not-the-patch-codeql/</link><pubDate>Sun, 27 Sep 2026 10:00:00 -0500</pubDate><guid>https://startaitools.com/posts/use-the-primitive-not-the-patch-codeql/</guid><description>&lt;h2 id="the-pattern-that-kept-recurring"&gt;The pattern that kept recurring&lt;/h2&gt;
&lt;p&gt;The CodeQL queue at the top of the week had twelve open alerts under the same rule name: &lt;code&gt;js/file-system-race&lt;/code&gt;. The sites lived in CI tooling scripts, in the jrig boundary reader, in the validate input readers, in the proofs test, in the auto-bump driver, in the reconstruct-versions stub. Different files, one bug shape: a path gets checked (&lt;code&gt;existsSync&lt;/code&gt;, &lt;code&gt;lstat&lt;/code&gt;, or &lt;code&gt;stat&lt;/code&gt;), then read or written by name in a separate call. The filesystem under the script is not quiescent between the two operations.&lt;/p&gt;</description></item></channel></rss>