Repository navigation
Analyse the repository with CodeQL - #203
Conversation
Advanced setup instead of the default one: this site needs path exclusions that the default setup cannot express. Languages: - actions: the two workflows. Finds wide token permissions, actions pinned to a tag, and untrusted input inside expressions. - javascript: our two scripts in themes/pybcn_theme/assets/js/ and the inline scripts in the Hugo templates. The vendor folder and the frozen snapshots under static/archives/ are excluded. CodeQL skips *.min.js by default, which covers cookieconsent.min.js. - python: bin/check-content and bin/check-html-safety. They have no .py extension. The CodeQL Python extractor accepts an extensionless file when its first line matches "#!... python". The security-extended suite is on because actions/unpinned-tag has medium precision and the default suite does not run it. The token gets contents: read and security-events: write only. Every action is pinned to a commit, with the version in a comment. A weekly run on Monday 05:37 UTC catches old code with new queries.
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
|
The first run checked the two things that were assumptions when I wrote this. CodeQL does find the Python scripts. They have no and none of the five shell scripts next to them. When the open stack merges there will be five Python scripts in The workflow analyses itself and passes. All seven checks are green. What to expect once this mergesThe first successful run on I expect one alert, on One thing not to do afterwards: in There is also a Unrelated, while we were in that screenSecret scanning and push protection are now on for this repository. They were off. Push protection is the one that earns its keep: it rejects a The first scan of the full history since 2013 found zero alerts, which is worth knowing: nothing has ever been leaked here. |
Turns on code scanning with a workflow rather than with the default setup, because this repository needs path exclusions that the default cannot express.
This one is independent of the open stack: it comes off
editionand touches one new file, so it can be reviewed and merged on its own.Three languages, and the reason for each:
actionsis the most useful one here. The queries find a token with wider permissions than the job needs, an action pinned to a tag instead of a commit, and untrusted input inside a workflow expression. Note that the query for an unpinned action has medium precision, so the default query suite does not run it: this workflow asks forsecurity-extendedso that it does. Expect it to report one thing we already know about,contents: writeingh-pages.yml, which the deploy tomasterneeds.pythoncoversbin/check-contentandbin/check-html-safety. They have no.pyextension, only a shebang, so whether CodeQL finds them at all was checked against the extractor source rather than assumed: it accepts a file with no extension when its first bytes match a python shebang, and the five shell scripts inbin/correctly do not match. In the first run, the python job's log should report two files.javascriptcovers our own scripts and the inline scripts in the templates. The vendored libraries underthemes/pybcn_theme/assets/vendor/and the frozen snapshots understatic/archives/are excluded. Those are jQuery, Bootstrap and two retired sites, committed as they are and never edited, and findings in code nobody will touch are how a security tool gets ignored. CodeQL skips*.min.json its own.Every action is pinned to a full commit SHA with its version in a comment, which is the style
pr.ymlandgh-pages.ymlalready use, and each SHA was checked against the GitHub API rather than written from memory. The job getscontents: readandsecurity-events: writeand nothing else.It runs on push and on pull request against
edition, and weekly on Monday at 05:37 UTC. The odd minute is on purpose: GitHub queues every top-of-the-hour schedule together and delays or drops them under load.After the merge
The first successful run turns code scanning on by itself, so there is nothing to enable first. Results appear under the Security tab, with one entry per language.
One thing not to do: in Settings, under Code security, do not click "Set up" on the default CodeQL configuration. Default setup rejects the results of an advanced workflow, so it would turn this off.