-
Couldn't load subscription status.
- Fork 7.3k
Exclude 3rd party license compliance content from GHAS scanning #11127
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. Weβll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Exclude 3rd party license compliance content from GHAS scanning #11127
Conversation
These changes will cause GitHub Advanced Security to ignore the auto-generated content around 3rd party dependencies used by `cli/cli` from static code analysis and secret scanning. For more information: - https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/customizing-your-advanced-setup-for-code-scanning - https://docs.github.com/en/code-security/secret-scanning/using-advanced-secret-scanning-and-push-protection-features/excluding-folders-and-files-from-secret-scanning
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Pull Request Overview
This PR configures GitHub Advanced Security to skip auto-generated third-party dependency content and associated license files during code scanning and secret scanning.
- Adds
paths-ignorepatterns to the CodeQL workflow to excludethird-party/**and license Markdown files. - Introduces a secret scanning config file that excludes the same paths from secret scanning.
Reviewed Changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| .github/workflows/codeql.yml | Added a config block under the CodeQL analysis step to ignore third-party/** and Markdown license files |
| .github/secret_scanning.yml | New file defining paths-ignore for secret scanning to exclude the third-party directory and license files |
Comments suppressed due to low confidence (1)
.github/secret_scanning.yml:1
- According to GitHubβs secret scanning schema, the config file should include a
versionfield and wrappaths-ignoreunder the proper top-level key (e.g.,push_protectionorsecret_scanning). Please update the file to match the expected structure.
paths-ignore:
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM thanks!
This MR contains the following updates: | Package | Update | Change | |---|---|---| | [cli/cli](https://github.com/cli/cli) | patch | `v2.74.1` -> `v2.74.2` | MR created with the help of [el-capitano/tools/renovate-bot](https://gitlab.com/el-capitano/tools/renovate-bot). **Proposed changes to behavior should be submitted there as MRs.** --- ### Release Notes <details> <summary>cli/cli (cli/cli)</summary> ### [`v2.74.2`](https://github.com/cli/cli/releases/tag/v2.74.2): GitHub CLI 2.74.2 [Compare Source](cli/cli@v2.74.1...v2.74.2) #### What's Changed ##### π Fixes - Fix assignees being dropped from `gh pr edit` by [@​BagToad](https://github.com/BagToad) in cli/cli#11065 - Add accurate context when run rerun fails by [@​leudz](https://github.com/leudz) in cli/cli#10774 - Avoid requesting MR reviewer twice by [@​williammartin](https://github.com/williammartin) in cli/cli#11099 - Quote filenames suggested at the end of worklow run by [@​williammartin](https://github.com/williammartin) in cli/cli#11134 - Fix expected error output of TestRepo/repo-rename-transfer-ownership by [@​aconsuegra](https://github.com/aconsuegra) in cli/cli#10888 ##### π Docs & Chores - Add instructions for MidnightBSD installation by [@​laffer1](https://github.com/laffer1) in cli/cli#10699 - docs: update install command for Debian by [@​MagneticNeedle](https://github.com/MagneticNeedle) in cli/cli#10935 - Fix step order for CodeQL workflow by [@​BagToad](https://github.com/BagToad) in cli/cli#11145 - Add workflow to check `help wanted` labelling by [@​williammartin](https://github.com/williammartin) in cli/cli#11105 - Quote workflow conditional by [@​williammartin](https://github.com/williammartin) in cli/cli#11122 - Fix script path for help-wanted check by [@​BagToad](https://github.com/BagToad) in cli/cli#11125 - Exclude 3rd party license compliance content from GHAS scanning by [@​andyfeller](https://github.com/andyfeller) in cli/cli#11127 - Second fix for file not found in help-wanted check by [@​BagToad](https://github.com/BagToad) in cli/cli#11128 - Ensure gh executes in workflow check script by [@​williammartin](https://github.com/williammartin) in cli/cli#11133 - Improve help wanted check skipping logic by [@​BagToad](https://github.com/BagToad) in cli/cli#11135 #####Dependencies - Bump go to 1.24 by [@​williammartin](https://github.com/williammartin) in cli/cli#11142 - chore(deps): bump mislav/bump-homebrew-formula-action from 3.2 to 3.4 by [@​dependabot](https://github.com/dependabot) in cli/cli#11066 - chore(deps): bump github.com/sigstore/protobuf-specs from 0.4.2 to 0.4.3 by [@​dependabot](https://github.com/dependabot) in cli/cli#11092 - chore(deps): bump google.golang.org/grpc from 1.72.0 to 1.72.2 by [@​dependabot](https://github.com/dependabot) in cli/cli#11033 - chore(deps): bump actions/attest-build-provenance from 2.3.0 to 2.4.0 by [@​dependabot](https://github.com/dependabot) in cli/cli#11107 - chore(deps): bump github.com/in-toto/attestation from 1.1.1 to 1.1.2 by [@​dependabot](https://github.com/dependabot) in cli/cli#11123 - chore(deps): bump github.com/google/go-containerregistry from 0.20.3 to 0.20.6 by [@​dependabot](https://github.com/dependabot) in cli/cli#11120 - Bump golangci-lint to v2 by [@​williammartin](https://github.com/williammartin) in cli/cli#11121 #### New Contributors - [@​MagneticNeedle](https://github.com/MagneticNeedle) made their first contribution in cli/cli#10935 - [@​laffer1](https://github.com/laffer1) made their first contribution in cli/cli#10699 **Full Changelog**: cli/cli@v2.74.1...v2.74.2 </details> --- ### Configuration π **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). π¦ **Automerge**: Enabled. β» **Rebasing**: Whenever MR is behind base branch, or you tick the rebase/retry checkbox. π **Ignore**: Close this MR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this MR, check this box --- This MR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MC42MC4xIiwidXBkYXRlZEluVmVyIjoiNDAuNjAuMSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiUmVub3ZhdGUgQm90Il19-->
Fixes #11126
Relates #11047
These changes will cause GitHub Advanced Security to ignore the auto-generated content around 3rd party dependencies used by
cli/clifrom static code analysis and secret scanning.For more information: