-
-
Notifications
You must be signed in to change notification settings - Fork 847
Open
Labels
Complexity: MediumDependencyAn issue is blocking the completion or starting of another issueAn issue is blocking the completion or starting of another issueFeature: Code AlertsP-Feature: Wins Pagehttps://www.hackforla.org/wins/https://www.hackforla.org/wins/role: front endTasks for front end developersTasks for front end developerssize: 1ptCan be done in 4-6 hoursCan be done in 4-6 hours
Milestone
Description
Dependency
- Update codeql.yml to exclude YAML front-matter and Liquid code #6548
Explanation: it is likely that the alert is a false positive and will be resolved when CodeQL excludes liquid statements.
Prerequisite
- Be a member of Hack for LA. (There are no fees to join.) If you have not joined yet, please follow the steps on our Getting Started page.
- Before you claim or start working on an issue, please make sure you have read our How to Contribute to Hack for LA Guide.
Overview
We need to resolve the new alert (34) and either recommend dismissal of the alert or update the code files to resolve the alert.
Action Items
- The following action item serves to "link" this issue as the "tracking issue" for the CodeQL alert and to provide more details regarding the alert: https://github.com/hackforla/website/security/code-scanning/34
- In a comment in this issue, add your analysis and recommendations. The recommendation can be one of the following:
dismiss as test,dismiss as false positive,dismiss as won't fix, orupdate code. An example of afalse positiveis a report of a JavaScript syntax error that is caused by markdown or liquid symbols such as---or{% - If the recommendation is to dismiss the alert:
- Apply the label
ready for dev lead - Move the issue to
Questions/In Review
- Apply the label
- If the recommendation is to update code:
- Create an issue branch and proceed with the code update
- Test using docker to ensure that there are no changes to any affected webpage(s). For testing guidance see Create wiki page providing guidance how to test the WINS page #6680 (comment)
- Proceed with pull request in the usual manner
Resources/Instructions
- HfLA website: CodeQL scan alert audits - issue 5005
- Code scanning results page
- CodeQL query help for JavaScript
- How to manage CodeQL alerts
This issue was automatically generated from the codeql.yml workflow
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
Complexity: MediumDependencyAn issue is blocking the completion or starting of another issueAn issue is blocking the completion or starting of another issueFeature: Code AlertsP-Feature: Wins Pagehttps://www.hackforla.org/wins/https://www.hackforla.org/wins/role: front endTasks for front end developersTasks for front end developerssize: 1ptCan be done in 4-6 hoursCan be done in 4-6 hours
Type
Projects
Status
Ice box