Repository navigation
Resolve open code-scanning alerts on main - #13
Merged
Merged
Conversation
Code scanning flagged pypa/gh-action-pypi-publish and softprops/action-gh-release as unpinned, and ci.yml as granting the default token scope. Third-party actions are pinned to the commit SHA of their latest release (v1.14.2 and v3.0.3) per the org rule; ci.yml and release.yml now default to contents: read, with the publish job keeping its own id-token/contents write grant.
The bootstrap launcher test matched URL hosts as substrings of the output, which CodeQL reports as incomplete URL sanitisation. It now extracts the printed URLs and compares parsed hostnames exactly. The intentional swallow of ConfigError when pre-loading the local registry gains a comment explaining why; behaviour is unchanged.
CodeQL still reads a membership test of a hostname literal as substring sanitisation, even against a set of parsed hosts. Equality on each parsed hostname states the intent unambiguously.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes the real code-scanning findings open on
main, which re-surface as an unresolved CodeQL review thread on every Dependabot rebase (e.g. #6).actions/unpinned-tag: pinpypa/gh-action-pypi-publishto v1.14.2 (dc37677b) andsoftprops/action-gh-releaseto v3.0.3 (efb35369), resolved from each repo's latest release and the tag's dereferenced commit.docker/*actions stay on floating major tags per the org rule.actions/missing-workflow-permissions:ci.ymlandrelease.ymldefault tocontents: read; the publish job keeps its ownid-token/contents: write.py/incomplete-url-substring-sanitization: the launcher test now parses printed URLs and compares hostnames exactly.py/empty-except: the intentionalConfigErrorswallow in__main__.pygains an explanatory comment. No behaviour change.