github / github/codeql

CodeQL adds redundant slash to upload sarif file endpoint

Open
#15,020 17 comments 0 reactions 0 assignees View on GitHub
question
Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 15h
Merged PRs (30d)
141

Description

I use Azure DevOps pipeline to perform CodeQL code scanning. It goes well until I try to upload sarif file to github. I use this command to do upload: `echo $(Github.TOKEN) | $(codeql) github upload-results --repository=$(Owner)/$(Repo) --ref=$(Build.SourceBranch) --commit=$(Build.SourceVersion) --sarif=$(sarifOutput) --github-auth-stdin --github-url=https://github.com`. In result CodeQL tries to upload sarif file using endpoint `https://api.github.com//repos/owner_name/repo_name/code-scanning/sarifs`. There is redundant slash in the url so I get 404 response. Do you have idea what is wrong and how to fix?

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the Azure DevOps command with CodeQL's `github upload-results` and compare the generated endpoint with the expected GitHub URL. Trace the upload-results URL construction, then verify that the SARIF upload no longer requests a path with a redundant slash and succeeds against the repository endpoint.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure, github
Domain
api, ci-cd, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.