Commit cb3d21c
committed
chore(codeql): add paths-ignore for vendored bundles, shadow src, audit tools
Three categories of code surfacing CodeQL alerts that aren't appropriate
to fix in-tree:
- book/quarto/tools/scripts/socratiQ/collaborative-widget-bridge.{js,umd.cjs}:
minified upstream socratiQ widget bundle. Alerts (XSS, prototype
pollution, tainted format string, insecure randomness, clear-text
storage) live in vendored third-party code; report upstream rather
than patch a build artifact.
- socratiq/src_shadow/**: shadow copy of socratiq client source for the
shadow-DOM rendering path, parallel to socratiq/js/. Not part of the
live web surface.
- tools/audit/**: local audit/maintenance scripts that operate on the
user's own Quarto build output. Regex HTML strip is intentional for
speed and safe given trusted input.
Default-setup CodeQL picks up .github/codeql/codeql-config.yml on next
weekly scan; pre-existing alerts on these paths still need manual
dismissal in the Security tab.1 parent a8acabd commit cb3d21c
1 file changed
Lines changed: 20 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
0 commit comments