Repository navigation
feat(sarif): carry the project logo header onto Code Scanning alerts - #1321
Open
sonukapoor wants to merge 2 commits into
Open
sonukapoor wants to merge 2 commits into
sonukapoor wants to merge 2 commits into
Conversation
Every rule's help.markdown now opens with the same linked logo the GitHub App puts on its PR comments, so an alert in the Security tab is recognisably from this tool rather than from whichever scanner the reader assumed. The plain-text variant gets a one-line attribution instead, since an HTML image is useless to a non-GitHub SARIF consumer. The two URL strings are duplicated from scripts/pr-scan-delta.mjs rather than shared. That file imports nothing from the CLI on purpose, because the Action's delta input and the App both deep-import it from the published package, so making it depend on src/ would break both. A comment in each place says the other exists. Whether GitHub renders inline HTML in help.markdown is unverified. The self-scan runs our own Action against this repo and uploads to our own Security tab, so the next run shows the answer either way; if it is stripped, the text attribution is the fallback.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A Code Scanning alert we produce gives the reader no indication of which tool produced it. The tool name is in the run metadata, which the alert detail view does not surface, so an alert reads as if GitHub raised it.
This puts the same attribution the GitHub App already uses on PR comments onto the SARIF rule help: a linked logo leading
help.markdown, and a plain-text line leadinghelp.text, since the text variant cannot carry markup.Scope is the
helpobject only. A rule with no matching advisory still emits nohelpat all, rather than a bare logo with nothing under it.The URLs are duplicated rather than imported from the delta renderer, deliberately, because that file must not import anything from the CLI.
Verified against a real scan: all 24 rules in the emitted SARIF carry the linked logo. The three new tests were each confirmed to fail when the header, the attribution, or just the link around the logo is removed.
Closes #1316