mirror of
https://github.com/Sea-Haven-Industries/afterhours-shift-manager.git
synced 2026-09-30 23:03:11 +00:00
* ci(dependency-review): set explicit read-only GITHUB_TOKEN permissions Resolves code-scanning alert 11 (actions/missing-workflow-permissions). The callable workflow only needs contents: read. * fix(logging): remove taint-flagged values from 3CX and roster-sync logs Resolves code-scanning alerts 12-15 (py/clear-text-logging-sensitive-data). CodeQL taints the 3CX response dicts via the Secrets Manager-sourced domain in the request URL, so entity IDs subscripted from those responses (ivr_id, resource_id, queue_id) and the roster result dict trip the query. None of the flagged values are secrets, but the log lines are rewritten so the pattern cannot trip: entity IDs are dropped in favor of the untainted destination DNs, and the roster summary logs counts instead of the member-derived dict (which also keeps employee names out of the logs). * fix: update ci workflow SHA to latest version * fix(logging): drop employee-derived DNs from forwarding log Resolves new code-scanning alerts 16/17. The closed/holiday DNs added in the previous commit derive from roster employee lookups in the Slack bot, so CodeQL classifies them as private data. Log only the resource type; ring_scheduler already logs the queue number.
14 lines
353 B
YAML
14 lines
353 B
YAML
name: CI
|
|
on:
|
|
pull_request:
|
|
branches: [main]
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
ci:
|
|
uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@f71002a9ed2938730b683249b28059c92a081af6
|
|
with:
|
|
source-dirs: "src/slack-bot src/weekly-post src/roster-sync src/ring-scheduler src/shared/shared tests"
|
|
run-tests: true
|