Skip to content

feat(sarif): carry the project logo header onto Code Scanning alerts - #1321

Open
sonukapoor wants to merge 2 commits into
mainfrom
feat/issue-1316-sarif-logo-header
Open

sonukapoor wants to merge 2 commits into
mainfrom
feat/issue-1316-sarif-logo-header

Conversation

@sonukapoor

Copy link
Copy Markdown
Collaborator

A Code Scanning alert we produce gives the reader no indication of which tool produced it. The tool name is in the run metadata, which the alert detail view does not surface, so an alert reads as if GitHub raised it.

This puts the same attribution the GitHub App already uses on PR comments onto the SARIF rule help: a linked logo leading help.markdown, and a plain-text line leading help.text, since the text variant cannot carry markup.

Scope is the help object only. A rule with no matching advisory still emits no help at all, rather than a bare logo with nothing under it.

The URLs are duplicated rather than imported from the delta renderer, deliberately, because that file must not import anything from the CLI.

Verified against a real scan: all 24 rules in the emitted SARIF carry the linked logo. The three new tests were each confirmed to fail when the header, the attribution, or just the link around the logo is removed.

Closes #1316

Every rule's help.markdown now opens with the same linked logo the GitHub App
puts on its PR comments, so an alert in the Security tab is recognisably from
this tool rather than from whichever scanner the reader assumed. The plain-text
variant gets a one-line attribution instead, since an HTML image is useless to a
non-GitHub SARIF consumer.

The two URL strings are duplicated from scripts/pr-scan-delta.mjs rather than
shared. That file imports nothing from the CLI on purpose, because the Action's
delta input and the App both deep-import it from the published package, so making
it depend on src/ would break both. A comment in each place says the other exists.

Whether GitHub renders inline HTML in help.markdown is unverified. The self-scan
runs our own Action against this repo and uploads to our own Security tab, so the
next run shows the answer either way; if it is stripped, the text attribution is
the fallback.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(sarif): Code Scanning alerts do not show that CVE Lite CLI produced them

1 participant