github / github/codeql

CodeQL: Setting paths in Github Advanced Security for Azure Devops

Offen
#18,372 6 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
question
Vorherrschende Sprache
CodeQL
Sterne
10.1k
Forks
2.1k
Ø Merge
2 T. 15 Std.
Gemergte PRs (30 T.)
141

Beschreibung

I'm using Github Advanced Security in Azure devops in a monorepo. With the given folder structure:

```
.
└── apps/
├── frontend/
│ ├── green-app
│ └── red-app
└── backend/
├── green-app
└── red-app
```

By default the codeql task will scan the ENTIRE code base. Which is not what I want.

**How can I configure Github advanced security to only scan one project? For example the front-end and backend folder for the green-app.**

I tried setting the sources folder to the back-end folder. But then I'm not able to "reach" the front-end folder when I set the codeqlpathstoinclude parameter. When I try this:
```
- task: AdvancedSecurity-Codeql-Init@1
condition: and(succeededOrFailed(), ${{parameters.runGithubAdvancedSecurity}})
displayName: 'Github Advanced Security: Initialize 🛡'
inputs:
languages: 'csharp,javascript'
sourcesfolder: '$(System.DefaultWorkingDirectory)/apps/backend/green-app'
codeqlpathstoinclude: '../frontend/green-app'
```
_(Following the [docs](https://learn-microsoft-com.translate.goog/en-us/azure/devops/pipelines/tasks/reference/advanced-security-codeql-init-v1?view=azure-pipelines&_x_tr_sl=en&_x_tr_tl=nl&_x_tr_hl=nl&_x_tr_pto=sc): "The paths must be relative to the sourcesfolder where CodeQL is running, which defaults to the Build.SourcesDirectory pipeline environment variable. For example, to include the $(Build.SourcesDirectory)/app directory, set codeqlpathstoinclude: app rather than codeqlpathstoinclude: $(Build.SourcesDirectory)/app.")_

I get:
> Only found JavaScript or TypeScript files that were empty or contained syntax errors

Wildcards are also giving issues:
`apps/*/green-app/**/*`

What am I doing wrong here? Any other way i can accomplish this?

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Beginnen Sie mit der Dokumentation zur Pipelineaufgabe AdvancedSecurity-Codeql-Init@1 und den dort gezeigten Einstellungen für sourcesfolder und codeqlpathstoinclude. Überprüfen Sie, wie relative Pfade und Wildcards aufgelöst werden, und bestätigen Sie anschließend, dass nur die Frontend- und Backend-Pfade von green-app gescannt werden, ohne die gemeldeten JavaScript- oder TypeScript-Fehler.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
azure, csharp, javascript
Bereich
devops, security
Issue-Typ
Bug
Schwierigkeit
3/5
Geschätzter Aufwand
1-2 Tage
Aktivitätsstatus
Veraltet
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
35/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.