mirror of
https://github.com/Sea-Haven-Industries/afterhours-shift-manager.git
synced 2026-09-30 07:53:11 +00:00
* ci(dependency-review): set explicit read-only GITHUB_TOKEN permissions Resolves code-scanning alert 11 (actions/missing-workflow-permissions). The callable workflow only needs contents: read. * fix(logging): remove taint-flagged values from 3CX and roster-sync logs Resolves code-scanning alerts 12-15 (py/clear-text-logging-sensitive-data). CodeQL taints the 3CX response dicts via the Secrets Manager-sourced domain in the request URL, so entity IDs subscripted from those responses (ivr_id, resource_id, queue_id) and the roster result dict trip the query. None of the flagged values are secrets, but the log lines are rewritten so the pattern cannot trip: entity IDs are dropped in favor of the untainted destination DNs, and the roster summary logs counts instead of the member-derived dict (which also keeps employee names out of the logs). * fix: update ci workflow SHA to latest version * fix(logging): drop employee-derived DNs from forwarding log Resolves new code-scanning alerts 16/17. The closed/holiday DNs added in the previous commit derive from roster employee lookups in the Slack bot, so CodeQL classifies them as private data. Log only the resource type; ring_scheduler already logs the queue number.
8 lines
227 B
YAML
8 lines
227 B
YAML
name: Dependency Review
|
|
on:
|
|
pull_request:
|
|
permissions:
|
|
contents: read
|
|
jobs:
|
|
review:
|
|
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main
|