github / github/docs

Explain that workflows that submit sarif probably shouldn't fail

Ouverte
#38,062 22 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
code security content needs SME
Langage dominant
TypeScript
Étoiles
20.8k
Forks
68.7k
Merge moyen
12 h 24 min
PR mergées (30 j)
105

Description

### Code of Conduct

- [x] I have read and agree to the GitHub Docs project's [Code of Conduct](https://github.com/github/docs/blob/main/.github/CODE_OF_CONDUCT.md)

### What article on docs.github.com is affected?

https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/customizing-your-advanced-setup-for-code-scanning

### What part(s) of the article would you like to see updated?

[Uploading code scanning data to GitHub](https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/customizing-your-advanced-setup-for-code-scanning#uploading-code-scanning-data-to-github)

Says:
> GitHub can display code analysis data generated externally by a third-party tool. You can upload code analysis data with the `upload-sarif action`. For more information, see [Uploading a SARIF file to GitHub](https://docs.github.com/en/code-security/code-scanning/integrating-with-code-scanning/uploading-a-sarif-file-to-github).

It doesn't say anything about exit codes for such workflows.

(It doesn't link to the [`upload-sarif action`](https://github.com/github/codeql-action/blob/main/upload-sarif/action.yml), which may be for the best as using that will delay workflows by 6 seconds. -- The action is intentionally **not** listed in the [GitHub Marketplace](https://github.com/marketplace?type=actions) unlike, e.g. [checkout](https://github.com/marketplace/actions/checkout).)

### Additional information

Normally if you want to prevent a pull request from being merged, you'd have your workflow "fail" triggering an ❌.

But, if you do that for a workflow that submits sarifs (at least using some of the apis, especially the [github/codeql-action/upload-sarif](https://github.com/github/codeql-action/blob/main/upload-sarif/action.yml)), then you'll get:

Image

And the status link goes to:
Image

Guide de contribution

Ouvrir le guide de contribution

Évaluation

Cette issue n'a pas encore été évaluée.

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.