https://github.com/felickz/codeql-sarif-precision-annotator
Build from: https://docs.github.com/en/actions/sharing-automations/creating-actions/creating-a-javascript-action?learn=create_actions&learnProduct=actions
https://github.com/felickz/codeql-sarif-precision-annotator
Last synced: 3 months ago
JSON representation
Build from: https://docs.github.com/en/actions/sharing-automations/creating-actions/creating-a-javascript-action?learn=create_actions&learnProduct=actions
- Host: GitHub
- URL: https://github.com/felickz/codeql-sarif-precision-annotator
- Owner: felickz
- License: mit
- Created: 2024-12-19T04:18:20.000Z (5 months ago)
- Default Branch: main
- Last Pushed: 2025-02-18T19:25:36.000Z (3 months ago)
- Last Synced: 2025-02-24T03:15:16.599Z (3 months ago)
- Language: JavaScript
- Homepage:
- Size: 1.48 MB
- Stars: 0
- Watchers: 1
- Forks: 0
- Open Issues: 4
-
Metadata Files:
- Readme: README.md
- License: LICENSE
- Codeowners: CODEOWNERS
Awesome Lists containing this project
README
# CodeQL SARIF Precision Annotator
Annotates CodeQL SARIF files with precision information from
[GitHub Code Scanning query list artifact](https://github.com/github/codeql/actions/workflows/query-list.yml?query=branch%3Acodeql-cli%2Flatest)Alert View:
Filter:

## Usage
Configure CodeQL Action to not automatically upload, process the default SARIF, then explicitly upload the new enhanced SARIF.
```yaml
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v3
with:
upload: false
output: sarif-results- name: Annotate CodeQL SARIF with Precision tag
uses: felickz/codeql-sarif-precision-annotator@main
with:
sarif_file: sarif-results/${{matrix.language}}.sarif
output_file: sarif-results/${{matrix.language}}-precision.sarif- name: Upload SARIF
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: sarif-results/${{matrix.language}}-precision.sarif
```## Local Dev
Test via `npx local-action . src/main.js .env.example`