Skip to content

ER: CodeQL did not raise alerts on each instance of "Potentially unsafe external link" #6485

@roslynwythe

Description

@roslynwythe

Dependencies

The issue could be resolved with:

Emergent Requirement - Problem

  • The file _includes/current_guides.html contained two instances of "Potentially unsafe external links" but only one CodeQL alert was raised.
  • The file _includes/about-page/about-card-sponsors contained four instance of ""Potentially unsafe external links" but only one CodeQL alert was raised

Details

Regarding _includes/current_guides.html:

Issue you discovered this emergent requirement in

Date discovered

3/4/2024

Did you have to do something temporarily

Who was involved

@djbradleyii

What happens if this is not addressed

code security/quality issues may be missed

Resources

Recommended Action Items

  • Make a new issue
  • Discuss with team
  • Let a Team Lead know

Potential solutions [draft]

  • We are aware that CodeQL runs into errors scanning Javascript code files with liquid statements. In both files in which CodeQL failed to report errors, liquid code was found. Therefore I suggest putting this ER on hold, with a dependency on update project profile food oasis reorder leadership member #6387
  • Search/audit the codebase for any other instances of "Potentially unsafe external link" that are not detected by CodeQL
  • resarch to determine possible reasons why CodeQL did not create an alert for this instance of "Potentially unsafe external link"

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Status

    Ice box

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions