fix: resolve the three high code-scanning alerts in the helper scripts - #193
Merged
Merged
Conversation
The ancestor-override test now asserts the whole list, so the external origin's absence and the override's position are both checked and there is no URL membership test left to misread as a substring check. The two clear-text logging sinks carry a codeql marker with the reason: creds.py prints the admin login on a terminal because that is what make creds is for, and every flow traced into _print carries a key name, a committed default or an already-redacted fault.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Clears alert #3 and records why #1 and #2 are not leaks. No behaviour change.
foundis a list, so the oldinwas exact membership, not a substring check. The test now asserts the whole ancestor list, which also covers the external origin being replaced.make credsexists to print the admin login, on a TTY only (README, Makefile help, docs/developing.md, and test_creds.py pins it). The other three flows are key NAMES, not values._print) -- false positive, marked at the line. All nine traced flows are key names, the shipped placeholder defaults, a descriptive string, or the forced-change fault that already redacts the new password (test_post_forced_change.py covers that).# codeql[...]markers will NOT close Investigate: Make vs hyperi-ci for stack lifecycle in dfe-docker #1 and chore: scheduled sync of component defaults (defaults_v<version>.yaml) #2 on merge. Default setup never runs CodeQL's alert-suppression query (this PR's python job loaded 45 queries, none of them AlertSuppression.ql), so both stay open until someone dismisses them or the repo moves to a committed CodeQL workflow. The green PR check says nothing either way -- it only looked at the changed lines.