Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[UHxIZ8JO] Add CodeQL (#186) #3212

Merged
merged 3 commits into from
Oct 12, 2022
Merged

[UHxIZ8JO] Add CodeQL (#186) #3212

merged 3 commits into from
Oct 12, 2022

Conversation

AzuObs
Copy link
Contributor

@AzuObs AzuObs commented Oct 11, 2022

  • [UHxIZ8JO] Ignore PRs from JLLeitschuh/security-research

We want to ignore PRs from this security researcher because they do not follow our private disclosure process. These PRs highlight that our code is exploitable before we've had the opportunity to fix it.

However, we will take JLLeitschuh up on his suggestion to add https://github.com/github/codeql-action to run checks in the background.

  • [UHxIZ8JO] Install CodeQL

  • [UHxIZ8JO] Remove unused file

The file was removed because it contained some vulnerabilities, and also because it was not used. It's also not used in APOC Extended.

(cherry picked from commit 6bb8434) (cherry picked from commit 1d174dd)

* [UHxIZ8JO] Ignore PRs from JLLeitschuh/security-research

We want to ignore PRs from this security researcher because they do not follow our private disclosure process. These PRs highlight that our code is exploitable before we've had the opportunity to fix it.

However, we will take JLLeitschuh up on his suggestion to add https://github.com/github/codeql-action to run checks in the background.

* [UHxIZ8JO] Install CodeQL

* [UHxIZ8JO] Remove unused file

The file was removed because it contained some vulnerabilities, and also because it was not used. It's also not used in APOC Extended.

(cherry picked from commit 6bb8434)
(cherry picked from commit 1d174dd)
@AzuObs AzuObs added cherry-picked This PR has been cherry-picked to the other active branches 4.3 labels Oct 11, 2022
@AzuObs AzuObs self-assigned this Oct 11, 2022
@AzuObs AzuObs merged commit 2d9293b into 4.3 Oct 12, 2022
@AzuObs AzuObs deleted the 4.3cp_codeql branch October 12, 2022 16:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
4.3 cherry-picked This PR has been cherry-picked to the other active branches
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant