Skip to content

Resolve open code-scanning alerts on main - #13

Merged
imanimanyara merged 3 commits into
mainfrom
fix/ci-code-scanning-alerts
Oct 2, 2026
Merged

imanimanyara merged 3 commits into
mainfrom
fix/ci-code-scanning-alerts

Conversation

@imanimanyara

Copy link
Copy Markdown
Member

Fixes the real code-scanning findings open on main, which re-surface as an unresolved CodeQL review thread on every Dependabot rebase (e.g. #6).

  • actions/unpinned-tag: pin pypa/gh-action-pypi-publish to v1.14.2 (dc37677b) and softprops/action-gh-release to v3.0.3 (efb35369), resolved from each repo's latest release and the tag's dereferenced commit. docker/* actions stay on floating major tags per the org rule.
  • actions/missing-workflow-permissions: ci.yml and release.yml default to contents: read; the publish job keeps its own id-token/contents: write.
  • py/incomplete-url-substring-sanitization: the launcher test now parses printed URLs and compares hostnames exactly.
  • py/empty-except: the intentional ConfigError swallow in __main__.py gains an explanatory comment. No behaviour change.

Code scanning flagged pypa/gh-action-pypi-publish and softprops/action-gh-release as unpinned, and ci.yml as granting the default token scope. Third-party actions are pinned to the commit SHA of their latest release (v1.14.2 and v3.0.3) per the org rule; ci.yml and release.yml now default to contents: read, with the publish job keeping its own id-token/contents write grant.
The bootstrap launcher test matched URL hosts as substrings of the output, which CodeQL reports as incomplete URL sanitisation. It now extracts the printed URLs and compares parsed hostnames exactly. The intentional swallow of ConfigError when pre-loading the local registry gains a comment explaining why; behaviour is unchanged.
Copilot AI balanced review requested due to automatic review settings October 2, 2026 10:39

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Comment thread tests/test_bootstrap_launchers.py Fixed
Comment thread tests/test_bootstrap_launchers.py Fixed
CodeQL still reads a membership test of a hostname literal as substring sanitisation, even against a set of parsed hosts. Equality on each parsed hostname states the intent unambiguously.
@imanimanyara
imanimanyara merged commit 23c507b into main Oct 2, 2026
19 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants