upload-sarif always warns when setting partialFingerprints

オープン 初心者向け
#4,052 コメント 4 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
2/5
見積もり時間
1〜3時間
初心者へのやさしさ
68/100
issue の種類
バグ
明瞭さ
おおむね明確
活発さ
静か
技術スタック
typescript
領域
security

調査の方向性

まず src/fingerprints.ts の171行目付近を読み、警告がいつ出力されるのかを理解するために SARIF のアップロード経路を追ってください。事前計算済みの partialFingerprints を含むアップロードでこの警告が発生しなくなり、引き続き対応が必要なケースの警告はそのまま維持されれば完了です。

索引モデルが issue の本文から書いたものです。

説明

The documentation recommends calculating partialFingerprints before uploading:

To avoid seeing duplicate alerts, you should calculate fingerprint data and populate the partialFingerprints property before you upload the SARIF file.

However, this always results in a warning in the output with no way to suppress it. If calculating the fingerprint is the recommendation then we should not be seeing a warning for it.

主要言語
TypeScript
スター
1.6k
フォーク
493
平均マージ
1日 13時間
マージ済み PR(30日)
44

コントリビューションガイド

コントリビューションガイドを開く

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

github/codeql-action のほかの issue

github/codeql-action の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。