github / github/codeql

Implement CodeQL SARIF file improvements suggested by Microsoft SARIF SDK tool

未關閉
#18,477 1 則留言 1 個 reaction 已指派 0 人 在 GitHub 檢視
question
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

Microsoft has a nice SARIF SDK tool which allows you to a bunch of stuff with SARIF files.

It's repo is here: https://github.com/microsoft/sarif-sdk, and there is a basic explanation of how to use it here: https://github.com/microsoft/sarif-sdk/blob/main/docs/multitool-usage.md.

You can easily install it like so:
- npm i -g @microsoft/sarif-multitool (requires Node.js (e.g., npm and node)

And then run it on CodeQL generated SARIF files like so:
- npx @microsoft/sarif-multitool validate Some_CODEQL.sarif --max-file-size-in-kb=some_number_if_needed

When I ran it on a recently generated codeQL SARIF file it generated LOTS of suggested improvements to the SARIF file generated by CodeQL.

I suggest you look at/implement the suggestions that make sense to you, and you might want to build in this 'SARIF validate' function into your maintenance process, to continually maintain/improve the SARIF files generated by CodeQL.

Not urgent, but certainly I think a useful/good maintenance aide for this project.

貢獻指南

開啟貢獻指南

研究方向

Install @microsoft/sarif-multitool with npm and run its validate command on a recently generated CodeQL SARIF file. Review the reported improvements, determine which suggestions are appropriate for this project, and consider whether SARIF validation should be added to the maintenance process. Done means the sensible improvements are implemented and the validation approach is documented or integrated.

由索引模型根據 Issue 內容生成。

評估

技術堆疊
node.js
領域
security, tooling
Issue 類型
功能
難度
5/5
預估耗時
一週以上
活躍度
停滯
描述清晰度
需要釐清
新手友好度
25/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。