MetaMask / MetaMask/action-security-code-scanner

Semgrep Rule ID is Path Based

オープン
#48 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
bug
主要言語
JavaScript
スター
10
フォーク
7
PR マージ指標
30日以内にマージされた PR はありません

説明

Semgrep's ruleID is based on the path where the rule is stored. This means that as we adjust the path the rule lives in, GitHub advanced security will consider it to be a new rule. This can result in existing alerts being closed, with duplicates opened in their place.

Image

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

調査の方向性

ファイル、テスト、エントリポイントはいずれも指定されていません。まず、Semgrep rule IDs が GitHub Advanced Security に渡される箇所を特定し、ルールパスの変更を再現してください。完了の条件は、パスの変更によって既存のアラートが閉じられなくなり、重複が作成されなくなることです。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
github-actions, javascript
領域
devops, security
issue の種類
バグ
難易度
5/5
見積もり時間
1週間以上
活発さ
停滞
明瞭さ
説明が足りない
初心者へのやさしさ
25/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。