github / github/codeql

Implement CodeQL SARIF file improvements suggested by Microsoft SARIF SDK tool

オープン
#18,477 コメント 1 件 リアクション 1 件 担当者 0 名 GitHub で見る
question
主要言語
CodeQL
スター
10.1k
フォーク
2.1k
平均マージ
2日 15時間
マージ済み PR(30日)
141

説明

Microsoft has a nice SARIF SDK tool which allows you to a bunch of stuff with SARIF files.

It's repo is here: https://github.com/microsoft/sarif-sdk, and there is a basic explanation of how to use it here: https://github.com/microsoft/sarif-sdk/blob/main/docs/multitool-usage.md.

You can easily install it like so:
- npm i -g @microsoft/sarif-multitool (requires Node.js (e.g., npm and node)

And then run it on CodeQL generated SARIF files like so:
- npx @microsoft/sarif-multitool validate Some_CODEQL.sarif --max-file-size-in-kb=some_number_if_needed

When I ran it on a recently generated codeQL SARIF file it generated LOTS of suggested improvements to the SARIF file generated by CodeQL.

I suggest you look at/implement the suggestions that make sense to you, and you might want to build in this 'SARIF validate' function into your maintenance process, to continually maintain/improve the SARIF files generated by CodeQL.

Not urgent, but certainly I think a useful/good maintenance aide for this project.

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

Install @microsoft/sarif-multitool with npm and run its validate command on a recently generated CodeQL SARIF file. Review the reported improvements, determine which suggestions are appropriate for this project, and consider whether SARIF validation should be added to the maintenance process. Done means the sensible improvements are implemented and the validation approach is documented or integrated.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
node.js
領域
security, tooling
issue の種類
機能追加
難易度
5/5
見積もり時間
1週間以上
活発さ
停滞
明瞭さ
説明が足りない
初心者へのやさしさ
25/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。