github / github/docs

Explain that workflows that submit sarif probably shouldn't fail

Abierto
#38,062 22 comentarios 0 reacciones 0 asignados Ver en GitHub
code security content needs SME
Lenguaje dominante
TypeScript
Estrellas
20.8k
Forks
68.7k
Merge medio
12 h 24 min
PR fusionados (30 d)
105

Descripción

### Code of Conduct

- [x] I have read and agree to the GitHub Docs project's [Code of Conduct](https://github.com/github/docs/blob/main/.github/CODE_OF_CONDUCT.md)

### What article on docs.github.com is affected?

https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/customizing-your-advanced-setup-for-code-scanning

### What part(s) of the article would you like to see updated?

[Uploading code scanning data to GitHub](https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/customizing-your-advanced-setup-for-code-scanning#uploading-code-scanning-data-to-github)

Says:
> GitHub can display code analysis data generated externally by a third-party tool. You can upload code analysis data with the `upload-sarif action`. For more information, see [Uploading a SARIF file to GitHub](https://docs.github.com/en/code-security/code-scanning/integrating-with-code-scanning/uploading-a-sarif-file-to-github).

It doesn't say anything about exit codes for such workflows.

(It doesn't link to the [`upload-sarif action`](https://github.com/github/codeql-action/blob/main/upload-sarif/action.yml), which may be for the best as using that will delay workflows by 6 seconds. -- The action is intentionally **not** listed in the [GitHub Marketplace](https://github.com/marketplace?type=actions) unlike, e.g. [checkout](https://github.com/marketplace/actions/checkout).)

### Additional information

Normally if you want to prevent a pull request from being merged, you'd have your workflow "fail" triggering an ❌.

But, if you do that for a workflow that submits sarifs (at least using some of the apis, especially the [github/codeql-action/upload-sarif](https://github.com/github/codeql-action/blob/main/upload-sarif/action.yml)), then you'll get:

Image

And the status link goes to:
Image

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.