github / github/codeql

CodeQL scanning of transitive private repository dependency

Aperta
#18,780 2 commenti 0 reazioni 0 assegnatari Vedi su GitHub
question
Lingua principale
CodeQL
Stelle
10.1k
Fork
2.1k
Merge medio
2g 15h
PR unite (30g)
141

Descrizione

Hi,

Our company manages two separate organization accounts on GitHub.

In Organization A, we successfully use CodeQL to scan our repositories. However, we are encountering an issue when integrating a repository from Organization B into a repository in Organization A using Swift Package Manager.

To access the private repository from Organization B, we have added a keychain entry, which works well for standard builds. Unfortunately, it fails during CodeQL scanning.

I suspect there may be a mechanism in place to prevent circumvention of licensing through transitive scanning. Is this correct? I believe that only Organization A holds the license for CodeQL in private repositories.

The reason for my suspicion, is that before we added the keychain entry, it just failed stating it could not access repo in org B. But now that the keychain entry is in place, it starts downloading from org B, but never succeeds, just stuck on that step.

Thank you for your assistance.

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Start with the CodeQL scanning workflow and the Swift Package Manager dependency fetch that downloads the private repository. Reproduce the scan with the keychain entry, compare it with a standard build, and document whether the cross-organization private dependency is supported and what configuration is required.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
github, swift
Ambito
security
Tipo di issue
Bug
Difficoltà
5/5
Tempo stimato
Più di una settimana
Stato di attività
Ferma
Chiarezza
Da chiarire
Idoneità per principianti
15/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.