-
-
Notifications
You must be signed in to change notification settings - Fork 847
Closed
Labels
Complexity: MediumFeature: Code Alertsready for dev leadIssues that tech leads or merge team members need to follow up onIssues that tech leads or merge team members need to follow up onrole: back end/devOpsTasks for back-end developersTasks for back-end developersrole: front endTasks for front end developersTasks for front end developerssize: 1ptCan be done in 4-6 hoursCan be done in 4-6 hours
Milestone
Description
Prerequisite
- Be a member of Hack for LA. (There are no fees to join.) If you have not joined yet, please follow the steps on our Getting Started page.
- Before you claim or start working on an issue, please make sure you have read our How to Contribute to Hack for LA Guide.
Overview
We need to analyze CodeQL query alert 25 then either recommend dismissal of the alert or update the code to resolve the alert.
Action Items
- DO NOT DISMISS ANY ALERTS. Dismissal of alerts should be done by dev leads only after review of the recommendation
- Browse to the link in the next Action Item and read the contents. Click "See More" to view Recommendations, Examples and References.
- https://github.com/hackforla/website/security/code-scanning/25
- In a comment in this issue, add your analysis and recommendations. The recommendation can be one of the following:
dismiss as test,dismiss as false positive,dismiss as won't fix, orupdate code. An example of afalse positiveis a report of a JavaScript syntax error that is caused by markdown or liquid symbols such as---or{% - If the recommendation is to dismiss the alert, apply the label
ready for dev leadthen move the issue toQuestions/In Review - If the recommendation is to update code:
- create an issue branch and proceed with the code update
- test using docker to ensure that there are no changes to any affected webpage(s)
- proceed with pull request in the usual manner
For merge team/dev lead
- If recommendation to dismiss is approved, dismiss the alert with a comment, then close the issue as completed.
- If recommendation to update code is approved, move the issue to "In Progress", remove "ready for dev lead" label and notify assignee to proceed
- In either case when this issue is closed please check off the dependency (under "Analysis Issues") in Create Issues for Analysis of CodeQL alerts #5060. If all analysis issues are closed, close Create Issues for Analysis of CodeQL alerts #5060 as completed.
Resources/Instructions
- GitHub CodeQL documentation
- This issue is part of Create Issues for Analysis of CodeQL alerts #5060
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
Complexity: MediumFeature: Code Alertsready for dev leadIssues that tech leads or merge team members need to follow up onIssues that tech leads or merge team members need to follow up onrole: back end/devOpsTasks for back-end developersTasks for back-end developersrole: front endTasks for front end developersTasks for front end developerssize: 1ptCan be done in 4-6 hoursCan be done in 4-6 hours
Type
Projects
Status
Done