github / github/codeql

Actions: imprecise action references in model data

未关闭
#19,635 4 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
question
主要语言
CodeQL
星标
10.1k
派生
2.1k
平均合并
2 天 15 小时
30 天内合并 PR
141

描述

First of all, thanks for your hard work! I'm a huge fan of CodeQL, and I think support for GitHub Actions within it is amazing.

I'm filing this because I recently tried to consume some of CodeQL's "models" in an external tool (https://github.com/zizmorcore/zizmor/pull/849), and noticed what I _think_ is a model imprecision/data quality issue.

## Description

For example, `actions/ql/lib/ext/generated/composite-actions/airbytehq_airbyte.model.yml`:

```yaml
extensions:
- addsTo:
pack: codeql/actions-all
extensible: actionsSinkModel
data:
- ["airbytehq/airbyte", "*", "input.options", "code-injection", "generated"]
- ["airbytehq/airbyte", "*", "input.subcommand", "code-injection", "generated"]
```

([Permalink](https://github.com/github/codeql/blob/f6231a37e119a2a4b263e7d521e61fda40b80ec7/actions/ql/lib/ext/generated/composite-actions/airbytehq_airbyte.model.yml))

This implies that `airbytehq/airbyte` has a top-level `action.ya?ml` definition, but it doesn't: instead, it has a set of actions defined under `airbytehq/airbyte/.github/actions`, of which `run-airbyte-ci` appears to have the relevant injectable inputs:

```yaml
name: "Run Dagger pipeline"
description: "Runs a given dagger pipeline"
inputs:
subcommand:
description: "Subcommand for airbyte-ci"
required: true
```

([Permalink](https://github.com/airbytehq/airbyte/blob/1804c4958793342168b99dd938f781bc764e9c6a/.github/actions/run-airbyte-ci/action.yml))

This appears to be true in most other model files in that directory, at least the ones marked with `"generated"` in their definitions.

## Expected behavior

Given that the inputs in question occur in in an action that isn't at the repository root, I expected the model YAML to look roughly like this:

```yaml
extensions:
- addsTo:
pack: codeql/actions-all
extensible: actionsSinkModel
data:
- ["airbytehq/airbyte/.github/actions/run-airbyte-ci", "*", "input.options", "code-injection", "generated"]
- ["airbytehq/airbyte/.github/actions/run-airbyte-ci", "*", "input.subcommand", "code-injection", "generated"]
```

## Actual behavior

The model YAML lists `airbytehq/airbyte`, leaving it unclear *which* actions within that repository have the injectable inputs.

贡献指南

打开贡献指南

调研方向

Start with actions/ql/lib/ext/generated/composite-actions/airbytehq_airbyte.model.yml and compare its repository reference with the linked .github/actions/run-airbyte-ci/action.yml. Inspect other generated model files marked "generated" to determine whether the same path issue is widespread; done means generated entries identify the specific nested action containing each input.

由索引模型根据 Issue 内容生成。

评估

技术栈
github-actions, yaml
领域
security
Issue 类型
缺陷
难度
4/5
预计耗时
3-5 天
活跃度
停滞
描述清晰度
描述清楚
新手友好度
38/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。