afterhours-shift-manager/.github
Adam Moussa f996f9600b
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
fix: resolve code-scanning alerts 11-15 (workflow permissions + log taint) (#184)
* ci(dependency-review): set explicit read-only GITHUB_TOKEN permissions

Resolves code-scanning alert 11 (actions/missing-workflow-permissions).
The callable workflow only needs contents: read.

* fix(logging): remove taint-flagged values from 3CX and roster-sync logs

Resolves code-scanning alerts 12-15 (py/clear-text-logging-sensitive-data).
CodeQL taints the 3CX response dicts via the Secrets Manager-sourced
domain in the request URL, so entity IDs subscripted from those
responses (ivr_id, resource_id, queue_id) and the roster result dict
trip the query. None of the flagged values are secrets, but the log
lines are rewritten so the pattern cannot trip: entity IDs are dropped
in favor of the untainted destination DNs, and the roster summary logs
counts instead of the member-derived dict (which also keeps employee
names out of the logs).

* fix: update ci workflow SHA to latest version

* fix(logging): drop employee-derived DNs from forwarding log

Resolves new code-scanning alerts 16/17. The closed/holiday DNs added
in the previous commit derive from roster employee lookups in the
Slack bot, so CodeQL classifies them as private data. Log only the
resource type; ring_scheduler already logs the queue number.
2026-07-27 13:48:14 -04:00
..
workflows fix: resolve code-scanning alerts 11-15 (workflow permissions + log taint) (#184) 2026-07-27 13:48:14 -04:00
dependabot.yml ci: expand dependabot coverage (INFRA-130) (#160) 2026-07-08 16:53:42 -04:00