Display vulnerabilities that are ignored in pull requests
維護者通常 1 天內回覆
還沒有人認領這個 Issue。
評估
- 難度
- 5/5
- 預估耗時
- 一週以上
- 新手友好度
- 20/100
- Issue 類型
- 功能
- 描述清晰度
- 需要釐清
- 活躍度
- 停滯
- 技術堆疊
- github-actions
- 領域
- security
研究方向
此請求涉及為 pull request 和 push 事件上傳的 SARIF 結果,以及 code-scanning UI 中已捨棄的 findings。未指定任何檔案或測試;首先確定這些行為屬於 codeql-action 還是 GitHub 的 code scanning 服務。完成後應包括一個在捨棄時保留預設分支 findings 的選項,以及一種搜尋先前已捨棄結果的方式。
由索引模型根據 Issue 內容生成。
描述
I have an action that I'd like to work on both pull requests and push events.
The SARIF is uploaded in both cases. When results of a pull request scan contain problems, it blocks the PR, which is great. The user is presented with a list of options: "Won't Fix", "false positive", "Unit tests". If they click "Won't Fix", the PR can be merged. However, the results never show up in the default branch's scanning results anymore. I think that's intended.
What I'd like is an additional option to the effect of "Will fix in another pull request" or "Won't fix in this pull request" to inform GitHub that it's fine to ignore the results to merge this PR, but that I intend to fix it later so I want the problem to show up on the default branch's scanning results. This is really important: imagine the problem has low criticality, I may want to allow merging the pull request and live with the vulnerability for a few days. If I cannot find the vulnerability on the dashboard, I will for-ever forget to fix it.
In addition: any results that are discarded ("Won't Fix", etc) are very hard to find in the UI. For example, as a security engineer, I may want to review all previous "Won''t Fix" in a branch. I can search for "is:closed" by branch, but I don't seem to be able to find those marked as "Won't Fix", etc. We all make mistakes, so giving the ability search through past choices is useful.
- 主要語言
- TypeScript
- 星號
- 1.7k
- 分支
- 495
- 平均合併
- 1 天 2 小時
- 30 天內合併 PR
- 47
環境準備
- 沒有 Dockerfile 或 Docker Compose 檔案
- 有 Pull Request 範本
- 閱讀貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
github/codeql-action 的其他 Issue
-
難度 2/5 1-3 小時 新手友好度 68/100
github/codeql-action#4052 · 4 則留言 ·
維護者通常 1 天內回覆
-
難度 4/5 3-5 天 新手友好度 45/100
github/codeql-action#4185 · 1 則留言 ·
維護者通常 1 天內回覆
-
難度 4/5 3-5 天 新手友好度 48/100
github/codeql-action#4173 · 2 則留言 ·
維護者通常 1 天內回覆
-
難度 4/5 3-5 天 新手友好度 45/100
github/codeql-action#4078 · 1 則留言 ·
維護者通常 1 天內回覆
-
難度 4/5 3-5 天 新手友好度 48/100
github/codeql-action#4008 · 9 則留言 ·
維護者通常 1 天內回覆
查看 github/codeql-action 的全部 Issue
相似的 Issue
-
enhancement providers-api ui-dashboard
難度 2/5 1-3 小時 新手友好度 61/100
維護者通常 1 天內回覆
-
難度 2/5 1-3 小時 新手友好度 88/100
維護者通常 1 天內回覆
-
external-issue to-triage
難度 1/5 1 小時以內 新手友好度 90/100
維護者通常 1 天內回覆
-
needs triage
難度 1/5 1 小時以內 新手友好度 88/100
homarr-labs/homarr#6976 · 2 則留言 ·
維護者通常 1 天內回覆
-
難度 2/5 1-3 小時 新手友好度 78/100
維護者通常 1 天內回覆