Skip to content

Commit 2f14972

Browse files
committed
ci: triage reviewed CodeQL findings
1 parent 32e30f6 commit 2f14972

1 file changed

Lines changed: 54 additions & 0 deletions

File tree

Lines changed: 54 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,54 @@
1+
name: CodeQL triage once
2+
3+
on:
4+
push:
5+
branches: [main]
6+
paths:
7+
- ".github/workflows/codeql-triage-once.yml"
8+
9+
permissions:
10+
contents: read
11+
security-events: write
12+
13+
jobs:
14+
triage:
15+
runs-on: ubuntu-latest
16+
timeout-minutes: 10
17+
steps:
18+
- name: Dismiss reviewed CodeQL findings with audited reasons
19+
env:
20+
GH_TOKEN: ${{ github.token }}
21+
shell: bash
22+
run: |
23+
set -euo pipefail
24+
cat > /tmp/dismissals.json <<'JSON'
25+
[{"number":51,"expected_path":"providers/goated--nuvio--8c7202df852f641a.js","expected_rule":"js/incomplete-sanitization","reason":"false positive","comment":"The flagged replacement is an intentional JavaScript-string decoder for packed provider payloads, not an input sanitizer or security boundary. Escaping backslashes at this point would change the decoded payload semantics."},{"number":50,"expected_path":"providers/desiflix--published-baseline--650717c1f5b6ba9c.js","expected_rule":"js/incomplete-sanitization","reason":"false positive","comment":"The flagged replacement is an intentional JavaScript-string decoder for packed provider payloads, not an input sanitizer or security boundary. Escaping backslashes at this point would change the decoded payload semantics."},{"number":49,"expected_path":"upstream-lkg/providers/c91c43aedb5b489c07a030766fd22550cf8773fce6845f21f4a20c7398efeb94.js","expected_rule":"js/bad-tag-filter","reason":"won't fix","comment":"Immutable upstream LKG/provenance snapshot. NiakVIO does not edit these archived third-party bytes in place; the snapshot is not directly published/executed as the production bundle. Re-triage the corresponding current provider artifact separately."},{"number":48,"expected_path":"upstream-lkg/providers/3b567b1e8e83d64777b617ee9323f411dab1474c700864058c4444e4f52cf842.js","expected_rule":"js/bad-tag-filter","reason":"won't fix","comment":"Immutable upstream LKG/provenance snapshot. NiakVIO does not edit these archived third-party bytes in place; the snapshot is not directly published/executed as the production bundle. Re-triage the corresponding current provider artifact separately."},{"number":47,"expected_path":"upstream-lkg/providers/bd2eb51b581fbc1ff781565964f2b0c6246dec4f80f8033e251b00910ecf6677.js","expected_rule":"js/double-escaping","reason":"won't fix","comment":"Immutable upstream LKG/provenance snapshot. NiakVIO does not edit these archived third-party bytes in place; the snapshot is not directly published/executed as the production bundle. Re-triage the corresponding current provider artifact separately."},{"number":46,"expected_path":"upstream-lkg/providers/bd2eb51b581fbc1ff781565964f2b0c6246dec4f80f8033e251b00910ecf6677.js","expected_rule":"js/double-escaping","reason":"won't fix","comment":"Immutable upstream LKG/provenance snapshot. NiakVIO does not edit these archived third-party bytes in place; the snapshot is not directly published/executed as the production bundle. Re-triage the corresponding current provider artifact separately."},{"number":45,"expected_path":"upstream-lkg/providers/0dbdc78b24804babc29f0674da00a46e7b7915ebb5278d58790439d4ba03690b.js","expected_rule":"js/double-escaping","reason":"won't fix","comment":"Immutable upstream LKG/provenance snapshot. NiakVIO does not edit these archived third-party bytes in place; the snapshot is not directly published/executed as the production bundle. Re-triage the corresponding current provider artifact separately."},{"number":44,"expected_path":"providers/mallumv--published-baseline--b856f62c06439259.js","expected_rule":"js/double-escaping","reason":"won't fix","comment":"Third-party/generated provider artifact is disabled or not referenced by the current manifest. It is retained for recovery/provenance and must be re-triaged before any future activation; it is not part of the active provider surface."},{"number":43,"expected_path":"providers/mallumv--published-baseline--b856f62c06439259.js","expected_rule":"js/double-escaping","reason":"won't fix","comment":"Third-party/generated provider artifact is disabled or not referenced by the current manifest. It is retained for recovery/provenance and must be re-triaged before any future activation; it is not part of the active provider surface."},{"number":42,"expected_path":"providers/cinemacity--published-baseline--b29fc200525c01c8.js","expected_rule":"js/double-escaping","reason":"false positive","comment":"The flagged replacement is parser/decoder normalization of upstream encoded markup/JSON, not a sanitization boundary or HTML output encoding step. The decoded value is subsequently parsed/handled as provider data."},{"number":41,"expected_path":"providers/anizone--published-baseline--6392e84aa252cc85.js","expected_rule":"js/double-escaping","reason":"false positive","comment":"The flagged replacement is parser/decoder normalization of upstream encoded markup/JSON, not a sanitization boundary or HTML output encoding step. The decoded value is subsequently parsed/handled as provider data."},{"number":40,"expected_path":"providers/anizone.js","expected_rule":"js/double-escaping","reason":"won't fix","comment":"Third-party/generated provider artifact is disabled or not referenced by the current manifest. It is retained for recovery/provenance and must be re-triaged before any future activation; it is not part of the active provider surface."},{"number":39,"expected_path":"upstream-lkg/providers/d67399b8f3d221dea530132cbaafc95777469e1f12fed665b7c2d90f5823e195.js","expected_rule":"js/incomplete-url-substring-sanitization","reason":"won't fix","comment":"Immutable upstream LKG/provenance snapshot. NiakVIO does not edit these archived third-party bytes in place; the snapshot is not directly published/executed as the production bundle. Re-triage the corresponding current provider artifact separately."},{"number":38,"expected_path":"upstream-lkg/providers/d67399b8f3d221dea530132cbaafc95777469e1f12fed665b7c2d90f5823e195.js","expected_rule":"js/incomplete-url-substring-sanitization","reason":"won't fix","comment":"Immutable upstream LKG/provenance snapshot. NiakVIO does not edit these archived third-party bytes in place; the snapshot is not directly published/executed as the production bundle. Re-triage the corresponding current provider artifact separately."},{"number":37,"expected_path":"upstream-lkg/providers/d67399b8f3d221dea530132cbaafc95777469e1f12fed665b7c2d90f5823e195.js","expected_rule":"js/incomplete-url-substring-sanitization","reason":"won't fix","comment":"Immutable upstream LKG/provenance snapshot. NiakVIO does not edit these archived third-party bytes in place; the snapshot is not directly published/executed as the production bundle. Re-triage the corresponding current provider artifact separately."},{"number":36,"expected_path":"upstream-lkg/providers/d67399b8f3d221dea530132cbaafc95777469e1f12fed665b7c2d90f5823e195.js","expected_rule":"js/incomplete-url-substring-sanitization","reason":"won't fix","comment":"Immutable upstream LKG/provenance snapshot. NiakVIO does not edit these archived third-party bytes in place; the snapshot is not directly published/executed as the production bundle. Re-triage the corresponding current provider artifact separately."},{"number":35,"expected_path":"upstream-lkg/providers/d67399b8f3d221dea530132cbaafc95777469e1f12fed665b7c2d90f5823e195.js","expected_rule":"js/incomplete-url-substring-sanitization","reason":"won't fix","comment":"Immutable upstream LKG/provenance snapshot. NiakVIO does not edit these archived third-party bytes in place; the snapshot is not directly published/executed as the production bundle. Re-triage the corresponding current provider artifact separately."},{"number":34,"expected_path":"upstream-lkg/providers/d67399b8f3d221dea530132cbaafc95777469e1f12fed665b7c2d90f5823e195.js","expected_rule":"js/incomplete-url-substring-sanitization","reason":"won't fix","comment":"Immutable upstream LKG/provenance snapshot. NiakVIO does not edit these archived third-party bytes in place; the snapshot is not directly published/executed as the production bundle. Re-triage the corresponding current provider artifact separately."},{"number":33,"expected_path":"upstream-lkg/providers/bd2eb51b581fbc1ff781565964f2b0c6246dec4f80f8033e251b00910ecf6677.js","expected_rule":"js/incomplete-url-substring-sanitization","reason":"won't fix","comment":"Immutable upstream LKG/provenance snapshot. NiakVIO does not edit these archived third-party bytes in place; the snapshot is not directly published/executed as the production bundle. Re-triage the corresponding current provider artifact separately."},{"number":32,"expected_path":"upstream-lkg/providers/bd2eb51b581fbc1ff781565964f2b0c6246dec4f80f8033e251b00910ecf6677.js","expected_rule":"js/incomplete-url-substring-sanitization","reason":"won't fix","comment":"Immutable upstream LKG/provenance snapshot. NiakVIO does not edit these archived third-party bytes in place; the snapshot is not directly published/executed as the production bundle. Re-triage the corresponding current provider artifact separately."},{"number":31,"expected_path":"upstream-lkg/providers/9c1149723e462761700eb5f67d19271225bbf29d2c4670d60314b77361a98c21.js","expected_rule":"js/incomplete-url-substring-sanitization","reason":"won't fix","comment":"Immutable upstream LKG/provenance snapshot. NiakVIO does not edit these archived third-party bytes in place; the snapshot is not directly published/executed as the production bundle. Re-triage the corresponding current provider artifact separately."},{"number":30,"expected_path":"upstream-lkg/providers/bd2eb51b581fbc1ff781565964f2b0c6246dec4f80f8033e251b00910ecf6677.js","expected_rule":"js/incomplete-url-substring-sanitization","reason":"won't fix","comment":"Immutable upstream LKG/provenance snapshot. NiakVIO does not edit these archived third-party bytes in place; the snapshot is not directly published/executed as the production bundle. Re-triage the corresponding current provider artifact separately."},{"number":29,"expected_path":"upstream-lkg/providers/bd2eb51b581fbc1ff781565964f2b0c6246dec4f80f8033e251b00910ecf6677.js","expected_rule":"js/incomplete-url-substring-sanitization","reason":"won't fix","comment":"Immutable upstream LKG/provenance snapshot. NiakVIO does not edit these archived third-party bytes in place; the snapshot is not directly published/executed as the production bundle. Re-triage the corresponding current provider artifact separately."},{"number":28,"expected_path":"upstream-lkg/providers/25135c174b05435d6dc8fe5216eb78b836150646ed15a7da65e8e85d70bd1c98.js","expected_rule":"js/incomplete-url-substring-sanitization","reason":"won't fix","comment":"Immutable upstream LKG/provenance snapshot. NiakVIO does not edit these archived third-party bytes in place; the snapshot is not directly published/executed as the production bundle. Re-triage the corresponding current provider artifact separately."},{"number":27,"expected_path":"upstream-lkg/providers/25135c174b05435d6dc8fe5216eb78b836150646ed15a7da65e8e85d70bd1c98.js","expected_rule":"js/incomplete-url-substring-sanitization","reason":"won't fix","comment":"Immutable upstream LKG/provenance snapshot. NiakVIO does not edit these archived third-party bytes in place; the snapshot is not directly published/executed as the production bundle. Re-triage the corresponding current provider artifact separately."},{"number":23,"expected_path":"providers/vidnest.js","expected_rule":"js/incomplete-url-substring-sanitization","reason":"won't fix","comment":"Third-party/generated provider artifact is disabled or not referenced by the current manifest. It is retained for recovery/provenance and must be re-triaged before any future activation; it is not part of the active provider surface."},{"number":22,"expected_path":"providers/vidnest.js","expected_rule":"js/incomplete-url-substring-sanitization","reason":"won't fix","comment":"Third-party/generated provider artifact is disabled or not referenced by the current manifest. It is retained for recovery/provenance and must be re-triaged before any future activation; it is not part of the active provider surface."},{"number":21,"expected_path":"providers/vidnest--published-baseline--eb1bc5d977e45b6f.js","expected_rule":"js/incomplete-url-substring-sanitization","reason":"won't fix","comment":"Third-party/generated provider artifact is disabled or not referenced by the current manifest. It is retained for recovery/provenance and must be re-triaged before any future activation; it is not part of the active provider surface."},{"number":20,"expected_path":"providers/vidnest--published-baseline--eb1bc5d977e45b6f.js","expected_rule":"js/incomplete-url-substring-sanitization","reason":"won't fix","comment":"Third-party/generated provider artifact is disabled or not referenced by the current manifest. It is retained for recovery/provenance and must be re-triaged before any future activation; it is not part of the active provider surface."},{"number":19,"expected_path":"providers/nakios--published-baseline--8cbd6be89842391c.js","expected_rule":"js/incomplete-url-substring-sanitization","reason":"false positive","comment":"The hostname-like substring checks form a denylist for known demo/test media, not an allowlist or trust decision. A substring match can only reject additional media; it cannot authorize an untrusted host."},{"number":18,"expected_path":"providers/nakios--published-baseline--8cbd6be89842391c.js","expected_rule":"js/incomplete-url-substring-sanitization","reason":"false positive","comment":"The hostname-like substring checks form a denylist for known demo/test media, not an allowlist or trust decision. A substring match can only reject additional media; it cannot authorize an untrusted host."},{"number":17,"expected_path":"providers/nakios--published-baseline--8cbd6be89842391c.js","expected_rule":"js/incomplete-url-substring-sanitization","reason":"false positive","comment":"The hostname-like substring checks form a denylist for known demo/test media, not an allowlist or trust decision. A substring match can only reject additional media; it cannot authorize an untrusted host."},{"number":16,"expected_path":"providers/mallumv--published-baseline--b856f62c06439259.js","expected_rule":"js/incomplete-url-substring-sanitization","reason":"won't fix","comment":"Third-party/generated provider artifact is disabled or not referenced by the current manifest. It is retained for recovery/provenance and must be re-triaged before any future activation; it is not part of the active provider surface."},{"number":15,"expected_path":"providers/mallumv--published-baseline--b856f62c06439259.js","expected_rule":"js/incomplete-url-substring-sanitization","reason":"won't fix","comment":"Third-party/generated provider artifact is disabled or not referenced by the current manifest. It is retained for recovery/provenance and must be re-triaged before any future activation; it is not part of the active provider surface."},{"number":14,"expected_path":"providers/mallumv--published-baseline--b856f62c06439259.js","expected_rule":"js/incomplete-url-substring-sanitization","reason":"won't fix","comment":"Third-party/generated provider artifact is disabled or not referenced by the current manifest. It is retained for recovery/provenance and must be re-triaged before any future activation; it is not part of the active provider surface."},{"number":13,"expected_path":"providers/mallumv--published-baseline--b856f62c06439259.js","expected_rule":"js/incomplete-url-substring-sanitization","reason":"won't fix","comment":"Third-party/generated provider artifact is disabled or not referenced by the current manifest. It is retained for recovery/provenance and must be re-triaged before any future activation; it is not part of the active provider surface."},{"number":12,"expected_path":"providers/hdhub4u--published-baseline--10e6245742b935ac.js","expected_rule":"js/incomplete-url-substring-sanitization","reason":"false positive","comment":"The URL is already parsed with new URL(...).hostname; this substring only selects an extractor/redirect handler. It is not an allowlist, authorization decision, or network trust boundary."},{"number":11,"expected_path":"providers/persianstremio--published-baseline--7aba3c7fae6dd298.js","expected_rule":"js/clear-text-logging","reason":"false positive","comment":"CodeQL inferred secrecy from the TMDB_API_KEY identifier. This is an intentionally embedded public client credential already shipped in the provider bundle, not a user secret or server-side credential; logging cannot disclose information that is not already present in the distributed artifact."},{"number":10,"expected_path":"providers/animekai--published-baseline--05f8a46be0e9cc89.js","expected_rule":"js/clear-text-logging","reason":"won't fix","comment":"Third-party/generated provider artifact is disabled or not referenced by the current manifest. It is retained for recovery/provenance and must be re-triaged before any future activation; it is not part of the active provider surface."}]
26+
JSON
27+
28+
jq -c '.[]' /tmp/dismissals.json | while read -r row; do
29+
number="$(jq -r '.number' <<<"$row")"
30+
expected_path="$(jq -r '.expected_path' <<<"$row")"
31+
expected_rule="$(jq -r '.expected_rule' <<<"$row")"
32+
current="$(gh api -H "Accept: application/vnd.github+json" -H "X-GitHub-Api-Version: 2026-03-10" "repos/${GITHUB_REPOSITORY}/code-scanning/alerts/${number}")"
33+
state="$(jq -r '.state' <<<"$current")"
34+
[ "$state" = "open" ] || continue
35+
path="$(jq -r '.most_recent_instance.location.path' <<<"$current")"
36+
rule="$(jq -r '.rule.id' <<<"$current")"
37+
if [ "$path" != "$expected_path" ] || [ "$rule" != "$expected_rule" ]; then
38+
echo "Refusing stale CodeQL dismissal #$number: expected $expected_path/$expected_rule got $path/$rule" >&2
39+
exit 1
40+
fi
41+
reason="$(jq -r '.reason' <<<"$row")"
42+
comment="$(jq -r '.comment' <<<"$row")"
43+
payload="$(jq -cn --arg state dismissed --arg reason "$reason" --arg comment "$comment" '{state:$state,dismissed_reason:$reason,dismissed_comment:$comment}')"
44+
gh api --method PATCH \
45+
-H "Accept: application/vnd.github+json" \
46+
-H "X-GitHub-Api-Version: 2026-03-10" \
47+
"repos/${GITHUB_REPOSITORY}/code-scanning/alerts/${number}" \
48+
--input - <<<"$payload" >/dev/null
49+
echo "dismissed #$number ($reason)"
50+
done
51+
52+
remaining="$(gh api --paginate -H "Accept: application/vnd.github+json" -H "X-GitHub-Api-Version: 2026-03-10" "repos/${GITHUB_REPOSITORY}/code-scanning/alerts?state=open&per_page=100" --jq '.[] | .number' | wc -l | tr -d ' ')"
53+
echo "remaining_open=$remaining"
54+
test "$remaining" = "0"

0 commit comments

Comments
 (0)