mirror of
https://github.com/Sea-Haven-Industries/afterhours-shift-manager.git
synced 2026-09-30 06:43:12 +00:00
* ci(dependency-review): set explicit read-only GITHUB_TOKEN permissions Resolves code-scanning alert 11 (actions/missing-workflow-permissions). The callable workflow only needs contents: read. * fix(logging): remove taint-flagged values from 3CX and roster-sync logs Resolves code-scanning alerts 12-15 (py/clear-text-logging-sensitive-data). CodeQL taints the 3CX response dicts via the Secrets Manager-sourced domain in the request URL, so entity IDs subscripted from those responses (ivr_id, resource_id, queue_id) and the roster result dict trip the query. None of the flagged values are secrets, but the log lines are rewritten so the pattern cannot trip: entity IDs are dropped in favor of the untainted destination DNs, and the roster summary logs counts instead of the member-derived dict (which also keeps employee names out of the logs). * fix: update ci workflow SHA to latest version * fix(logging): drop employee-derived DNs from forwarding log Resolves new code-scanning alerts 16/17. The closed/holiday DNs added in the previous commit derive from roster employee lookups in the Slack bot, so CodeQL classifies them as private data. Log only the resource type; ring_scheduler already logs the queue number. |
||
|---|---|---|
| .. | ||
| changelog-guard.yml | ||
| ci.yaml | ||
| dependency-review.yml | ||
| deploy.yaml | ||
| labeler.yml | ||