docs: correct the exec.exec comment - no inline CodeQL suppression exists

My previous commit's comment used a `codeql[js/command-line-injection]`
prefix as if it were a suppression directive. Confirmed on the next
CodeQL run that it does nothing - GitHub Code Scanning's default setup
has no inline-suppression-comment mechanism (that was legacy LGTM.com
behavior, not something the current product supports). Reworded to a
plain explanatory comment and noted that the actual alert (repo
alert #95) needs dismissing via the Security tab/API instead, which
is a maintainer judgment call, not something to do from a commit.

No functional change - comment only.
This commit is contained in:
frostebite
2026-08-24 20:42:49 +01:00
parent b3b4352c80
commit c8afce7158
3 changed files with 23 additions and 19 deletions
Generated Vendored
+11 -9
View File
@@ -477,15 +477,17 @@ async function run() {
const args = (0, build_args_1.buildCliArgs)({
getInput: (name) => (name === 'projectPath' ? projectPath : core.getInput(name)),
});
// codeql[js/command-line-injection] - args is an array of discrete argv
// entries, not a concatenated shell string, and @actions/exec's
// toolrunner.js passes it straight to child_process.spawn(fileName, args,
// options) (verified by reading node_modules/@actions/exec/lib/toolrunner.js)
// - no shell is ever invoked to (mis)parse it, so classic shell/command
// injection via metacharacters isn't reachable here. CodeQL's static
// analysis can't see through @actions/exec's internals to confirm that,
// which is why it still flags this generic "user input reaches an
// exec-family call" pattern.
// CodeQL flags this line (js/command-line-injection) since args
// ultimately derives from Action inputs. Verified false positive: args
// is an array of discrete argv entries, not a concatenated shell
// string, and @actions/exec's toolrunner.js passes it straight to
// child_process.spawn(fileName, args, options) - verified by reading
// node_modules/@actions/exec/lib/toolrunner.js - never a shell string,
// never shell-parsed. CodeQL's static analysis can't see through
// @actions/exec's internals to confirm that. This comment does not
// suppress the alert (GitHub Code Scanning's default setup has no
// inline-suppression-comment mechanism - that was legacy LGTM.com
// behavior); the alert needs dismissing via the Security tab/API.
const exitCode = await exec.exec(cliPath, args, { ignoreReturnCode: true });
// Matches the original action's engineExitCode output: 0 on success,
// otherwise the exit code of whichever step (activation or build) - or,
Generated Vendored
+1 -1
View File
File diff suppressed because one or more lines are too long
+11 -9
View File
@@ -40,15 +40,17 @@ export async function run() {
getInput: (name) => (name === 'projectPath' ? projectPath : core.getInput(name)),
});
// codeql[js/command-line-injection] - args is an array of discrete argv
// entries, not a concatenated shell string, and @actions/exec's
// toolrunner.js passes it straight to child_process.spawn(fileName, args,
// options) (verified by reading node_modules/@actions/exec/lib/toolrunner.js)
// - no shell is ever invoked to (mis)parse it, so classic shell/command
// injection via metacharacters isn't reachable here. CodeQL's static
// analysis can't see through @actions/exec's internals to confirm that,
// which is why it still flags this generic "user input reaches an
// exec-family call" pattern.
// CodeQL flags this line (js/command-line-injection) since args
// ultimately derives from Action inputs. Verified false positive: args
// is an array of discrete argv entries, not a concatenated shell
// string, and @actions/exec's toolrunner.js passes it straight to
// child_process.spawn(fileName, args, options) - verified by reading
// node_modules/@actions/exec/lib/toolrunner.js - never a shell string,
// never shell-parsed. CodeQL's static analysis can't see through
// @actions/exec's internals to confirm that. This comment does not
// suppress the alert (GitHub Code Scanning's default setup has no
// inline-suppression-comment mechanism - that was legacy LGTM.com
// behavior); the alert needs dismissing via the Security tab/API.
const exitCode = await exec.exec(cliPath, args, { ignoreReturnCode: true });
// Matches the original action's engineExitCode output: 0 on success,