github / github/codeql

Incorrect escaping of SARIF message.text

Đang mở
#14,128 1 bình luận 0 reaction 1 người được giao Được @aeisenberg nhận Xem trên GitHub
question
Ngôn ngữ chính
CodeQL
Star
10.1k
Fork
2.1k
Merge trung bình
2 ngày 15 giờ
Pull request đã merge (30 ngày)
141

Mô tả

**Description of the issue**

Hello, after uploading a SARIF log to GitHub and opening the results using Code Scanning, I found that the message content had been altered before display: backquotes were not displayed in the message, and underscores were escaped.

For example:

```
"message": {
"text": "Some issue with `backquoted expression`, and path `some.path_with.underscore_suffix` on line 100"
},
```

and the result displayed on GitHub is:
```
Some issue with backquoted expression, and path some.path\_with.underscore\_suffix on line 100
```

This seems to be a bug, I did not see any requirement about this kind of escaping in the [SARIF specification](https://docs.oasis-open.org/sarif/sarif/v2.1.0/os/sarif-v2.1.0-os.html). As far as I understand the text should be rendered as is.
However in section "K.4 Comprehensive SARIF file" I see in the example:

```
"text": "Variable \"{0}\" was used without being initialized.

It was declared [here]({1}).",

"markdown": "Variable `{0}` was used without being initialized.

It was declared [here]({1})."
```
so it seems more correct to use `"\` instead of backquotes in the plain text string, and use backquotes in the markdown string. I have tried that, and the Code Scanning displayed results did not have any issue this time (they seem to use the markdown string), so the markdown version can be used as a workaround.

Although there was no special highlighting of the escaped \`string\`, contrary to what would be expected in Markdown rendering, so that could be improved.

Thanks

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.