Ver Fonte

Fixes #20484: Configure CodeQL to exclude URL redirect false positives

Jason Novinger há 4 meses atrás
pai
commit
c094699dc0
1 ficheiros alterados com 8 adições e 0 exclusões
  1. 8 0
      .github/codeql/codeql-config.yml

+ 8 - 0
.github/codeql/codeql-config.yml

@@ -1,3 +1,11 @@
 paths-ignore:
   # Ignore compiled JS
   - netbox/project-static/dist
+
+query-filters:
+  # Exclude py/url-redirection: NetBox uses safe_for_redirect() wrapper function
+  # which validates all redirects via Django's url_has_allowed_host_and_scheme().
+  # CodeQL's taint tracking doesn't recognize wrapper functions without custom
+  # query configuration. See #20484.
+  - exclude:
+      id: py/url-redirection