Files
sencho/.github/codeql/codeql-config.yml
T
Anso a3033a848e ci: scope CodeQL e2e tmpfile suppression via paths-ignore (#1346)
The js/insecure-temporary-file rule fires on e2e Playwright specs that
seed fixtures into the backend's COMPOSE_DIR (a fixed /tmp path) so the
API under test can read them back. A randomized mkdtemp cannot apply
there: the backend resolves paths against its own COMPOSE_DIR, so a
fixture written elsewhere would be invisible to it.

The prior suppression used a paths key inside a query-filters exclude,
which CodeQL ignores: query-filters match on query metadata, not source
path. That left the rule firing on every new e2e spec. Move the
exclusion to a top-level paths-ignore, the only mechanism that scopes
analysis by source path, so the e2e specs stop tripping the rule.
2026-06-09 21:52:27 -04:00

30 lines
1.5 KiB
YAML

data_extensions:
- .github/codeql/extensions/safeLog.model.yml
# End-to-end Playwright specs are test-harness code, not shipped product code.
# They seed fixture files directly into the backend's COMPOSE_DIR (a fixed path
# under /tmp: both the spec fallback and the CI start-app default are
# /tmp/compose) so the API under test can read them back, which CodeQL flags as
# js/insecure-temporary-file. A randomized mkdtemp does not apply: the backend
# resolves paths against its own COMPOSE_DIR, so a fixture written elsewhere
# would be invisible to it, and the predictable-temp-path threat is moot on the
# ephemeral, single-tenant CI runners. paths-ignore is used (not a query-filters
# entry) because only paths-ignore scopes analysis by source path; a paths key
# inside a query-filters exclude is ignored, since query-filters match on query
# metadata rather than file location.
paths-ignore:
- e2e/**
query-filters:
# API tokens are 256-bit CSPRNG random; sha256 of the raw token is the
# correct construction. js/insufficient-password-hash exists to catch weak
# hashing of low-entropy human passwords, which is irrelevant for these
# high-entropy opaque keys. Scoped to the token-handling files only, so
# real user-password code (bcrypt-hashed elsewhere) is still analyzed.
- exclude:
id: js/insufficient-password-hash
paths:
- backend/src/utils/apiTokenFormat.ts
- backend/src/routes/apiTokens.ts
- backend/src/__tests__/**