CodeQL adds redundant slash to upload sarif file endpoint
- Dominant language
- CodeQL
- Stars
- 10.1k
- Forks
- 2.1k
- Avg merge
- 2d 15h
- Merged PRs (30d)
- 141
Description
I use Azure DevOps pipeline to perform CodeQL code scanning. It goes well until I try to upload sarif file to github. I use this command to do upload: `echo $(Github.TOKEN) | $(codeql) github upload-results --repository=$(Owner)/$(Repo) --ref=$(Build.SourceBranch) --commit=$(Build.SourceVersion) --sarif=$(sarifOutput) --github-auth-stdin --github-url=https://github.com`. In result CodeQL tries to upload sarif file using endpoint `https://api.github.com//repos/owner_name/repo_name/code-scanning/sarifs`. There is redundant slash in the url so I get 404 response. Do you have idea what is wrong and how to fix?
Contributor guide
Research direction
Start by reproducing the Azure DevOps command with CodeQL's `github upload-results` and compare the generated endpoint with the expected GitHub URL. Trace the upload-results URL construction, then verify that the SARIF upload no longer requests a path with a redundant slash and succeeds against the repository endpoint.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- azure, github
- Domain
- api, ci-cd, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100