Display vulnerabilities that are ignored in pull requests
Maintainer antworten meist innerhalb von 1 Tag
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 5/5
- Geschätzter Aufwand
- Über eine Woche
- Anfängerfreundlichkeit
- 20/100
- Issue-Typ
- Feature
- Klarheit
- Muss geklärt werden
- Aktivitätsstatus
- Veraltet
- Tech-Stack
- github-actions
- Bereich
- security
Rechercherichtung
Die Anfrage betrifft SARIF-Ergebnisse, die für Pull-Request- und Push-Ereignisse hochgeladen werden, sowie verworfene Findings in der code-scanning UI. Es werden keine Dateien oder Tests genannt; bestimme zunächst, ob diese Verhaltensweisen zu codeql-action oder zum Code-Scanning-Dienst von GitHub gehören. Erledigt wäre eine Auswahlmöglichkeit beim Verwerfen, die Findings für den Default-Branch beibehält, sowie eine Möglichkeit, zuvor verworfene Ergebnisse zu suchen.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
I have an action that I'd like to work on both pull requests and push events.
The SARIF is uploaded in both cases. When results of a pull request scan contain problems, it blocks the PR, which is great. The user is presented with a list of options: "Won't Fix", "false positive", "Unit tests". If they click "Won't Fix", the PR can be merged. However, the results never show up in the default branch's scanning results anymore. I think that's intended.
What I'd like is an additional option to the effect of "Will fix in another pull request" or "Won't fix in this pull request" to inform GitHub that it's fine to ignore the results to merge this PR, but that I intend to fix it later so I want the problem to show up on the default branch's scanning results. This is really important: imagine the problem has low criticality, I may want to allow merging the pull request and live with the vulnerability for a few days. If I cannot find the vulnerability on the dashboard, I will for-ever forget to fix it.
In addition: any results that are discarded ("Won't Fix", etc) are very hard to find in the UI. For example, as a security engineer, I may want to review all previous "Won''t Fix" in a branch. I can search for "is:closed" by branch, but I don't seem to be able to find those marked as "Won't Fix", etc. We all make mistakes, so giving the ability search through past choices is useful.
- Vorherrschende Sprache
- TypeScript
- Sterne
- 1.6k
- Forks
- 493
- Ø Merge
- 1 T. 9 Std.
- Gemergte PRs (30 T.)
- 46
Entwicklungsumgebung
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus github/codeql-action
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 68/100
github/codeql-action#4052 · 4 Kommentare ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 48/100
github/codeql-action#4173 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 45/100
github/codeql-action#4078 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 48/100
github/codeql-action#4008 · 9 Kommentare ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 52/100
github/codeql-action#3978 · 4 Kommentare · 1 Reaktion ·
Maintainer antworten meist innerhalb von 1 Tag
Alle Issues in github/codeql-action
Ähnliche Issues
-
triage
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 90/100
Maintainer antworten meist innerhalb von 1 Tag
-
bug
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 68/100
mermaid-js/mermaid-live-editor#2053 ·
Maintainer antworten meist innerhalb von 1 Tag
-
factory
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
jessepollak/home#1455 ·
Maintainer antworten meist innerhalb von 1 Tag
-
community first-timers-only good first issue hacktoberfest help wanted low hanging fruit up-for-grabs
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 95/100
lingdojo/kana-dojo#31227 · 1 Kommentar · 5 Reaktionen ·
Maintainer antworten meist innerhalb von 1 Tag
-
mobile: device viewer shows dark status bar icons on its dark backdrop in light mode (Android)Offen
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 92/100
appandflow/stim#1838 ·
Maintainer antworten meist innerhalb von 1 Tag