github / github/codeql

Actions: imprecise action references in model data

Abierto
#19,635 4 comentarios 0 reacciones 0 asignados Ver en GitHub
question
Lenguaje dominante
CodeQL
Estrellas
10.1k
Forks
2.1k
Merge medio
2 d 15 h
PR fusionados (30 d)
141

Descripción

First of all, thanks for your hard work! I'm a huge fan of CodeQL, and I think support for GitHub Actions within it is amazing.

I'm filing this because I recently tried to consume some of CodeQL's "models" in an external tool (https://github.com/zizmorcore/zizmor/pull/849), and noticed what I _think_ is a model imprecision/data quality issue.

## Description

For example, `actions/ql/lib/ext/generated/composite-actions/airbytehq_airbyte.model.yml`:

```yaml
extensions:
- addsTo:
pack: codeql/actions-all
extensible: actionsSinkModel
data:
- ["airbytehq/airbyte", "*", "input.options", "code-injection", "generated"]
- ["airbytehq/airbyte", "*", "input.subcommand", "code-injection", "generated"]
```

([Permalink](https://github.com/github/codeql/blob/f6231a37e119a2a4b263e7d521e61fda40b80ec7/actions/ql/lib/ext/generated/composite-actions/airbytehq_airbyte.model.yml))

This implies that `airbytehq/airbyte` has a top-level `action.ya?ml` definition, but it doesn't: instead, it has a set of actions defined under `airbytehq/airbyte/.github/actions`, of which `run-airbyte-ci` appears to have the relevant injectable inputs:

```yaml
name: "Run Dagger pipeline"
description: "Runs a given dagger pipeline"
inputs:
subcommand:
description: "Subcommand for airbyte-ci"
required: true
```

([Permalink](https://github.com/airbytehq/airbyte/blob/1804c4958793342168b99dd938f781bc764e9c6a/.github/actions/run-airbyte-ci/action.yml))

This appears to be true in most other model files in that directory, at least the ones marked with `"generated"` in their definitions.

## Expected behavior

Given that the inputs in question occur in in an action that isn't at the repository root, I expected the model YAML to look roughly like this:

```yaml
extensions:
- addsTo:
pack: codeql/actions-all
extensible: actionsSinkModel
data:
- ["airbytehq/airbyte/.github/actions/run-airbyte-ci", "*", "input.options", "code-injection", "generated"]
- ["airbytehq/airbyte/.github/actions/run-airbyte-ci", "*", "input.subcommand", "code-injection", "generated"]
```

## Actual behavior

The model YAML lists `airbytehq/airbyte`, leaving it unclear *which* actions within that repository have the injectable inputs.

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

Comienza con actions/ql/lib/ext/generated/composite-actions/airbytehq_airbyte.model.yml y compara su referencia al repositorio con el .github/actions/run-airbyte-ci/action.yml enlazado. Inspecciona otros archivos de modelo generados marcados como "generated" para determinar si el mismo problema de rutas está extendido; se considera terminado cuando las entradas generadas identifican la acción anidada específica que contiene cada input.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
github-actions, yaml
Área
security
Tipo de issue
Error
Dificultad
4/5
Tiempo estimado
3-5 días
Estado de actividad
Estancado
Claridad
Bien especificado
Aptitud para principiantes
38/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.