fix(sarif): normalize git source URIs for GitHub Code Scanning compatibility#378
Open
cx-ori-bendet wants to merge 1 commit intomasterfrom
Open
fix(sarif): normalize git source URIs for GitHub Code Scanning compatibility#378cx-ori-bendet wants to merge 1 commit intomasterfrom
cx-ori-bendet wants to merge 1 commit intomasterfrom
Conversation
…ibility When scanning git repositories, secret sources are stored as "git show <SHA>:<filepath>" strings. Using these directly as SARIF artifactLocation.uri values causes GitHub Code Scanning to reject the report with "locationFromSarifResult: expected artifact location" because the string contains spaces and is not a valid URI. This fix extracts the file path from git source strings and sets uriBaseId to "%SRCROOT%" so that GitHub Code Scanning can correctly resolve file locations relative to the repository root. Fixes #128 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
|
Great job! No new security vulnerabilities introduced in this pull request |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.








Summary
"git show <SHA>:<filepath>"strings (e.g.,"git show abc123:pkg/foo.go")artifactLocation.uriin SARIF output, causing GitHub Code Scanning to reject the report withlocationFromSarifResult: expected artifact location— because the string contains spaces and is not a valid URIuriBaseId: "%SRCROOT%"so GitHub Code Scanning can correctly resolve file locations relative to the repository rootFixes #128
Test plan
git_source_normalized_to_filepath_with_srcrootinTestGetOutputSarifverifies that a secret withSource: "git show abc1234567:pkg/foo.go"produces a SARIF result withartifactLocation.uri = "pkg/foo.go"andartifactLocation.uriBaseId = "%SRCROOT%"I submit this contribution under the Apache-2.0 license.
🤖 Generated with Claude Code