mirror of
https://github.com/Sea-Haven-Industries/apm-wo-analysis.git
synced 2026-09-30 01:53:13 +00:00
chore: resolve open code scanning alerts (URL host matching + workflow permissions) (#36)
Some checks are pending
Deploy / deploy (push) Waiting to run
Some checks are pending
Deploy / deploy (push) Waiting to run
* fix: Refactor `comment_intent` to use `_contains_url_with_host` for URL host matching. * ci: add least-privilege permissions blocks to workflow callers Resolves code scanning alerts #4 and #5 (actions/missing-workflow-permissions). Both callable workflows only need contents: read; the dependency-review callable already declares it internally, this caps the caller token to match.
This commit is contained in:
parent
3748a29744
commit
299ead89b3
3 changed files with 22 additions and 1 deletions
3
.github/workflows/ci.yaml
vendored
3
.github/workflows/ci.yaml
vendored
|
|
@ -3,6 +3,9 @@ on:
|
|||
pull_request:
|
||||
branches: [main]
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
ci:
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main
|
||||
|
|
|
|||
4
.github/workflows/dependency-review.yml
vendored
4
.github/workflows/dependency-review.yml
vendored
|
|
@ -1,6 +1,10 @@
|
|||
name: Dependency Review
|
||||
on:
|
||||
pull_request:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
review:
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main
|
||||
|
|
|
|||
|
|
@ -25,6 +25,7 @@ from __future__ import annotations
|
|||
import html
|
||||
import os
|
||||
import re
|
||||
from urllib.parse import unquote, urlparse
|
||||
|
||||
# Axis 2 — Hold Reason → category.
|
||||
HOLD_TO_CATEGORY = {
|
||||
|
|
@ -118,6 +119,19 @@ def strip_html(comment: str | None) -> str:
|
|||
# ---------------------------------------------------------------------------
|
||||
|
||||
|
||||
def _contains_url_with_host(text: str, expected_host: str) -> bool:
|
||||
"""Return True when ''text'' contains an absolute URL with hostname ''expected_host''."""
|
||||
for raw_url in re.findall(r"https?://[^\s<>'\"()]+", text, flags=re.IGNORECASE):
|
||||
candidate = unquote(raw_url).rstrip(".,;:!?)]}\"'")
|
||||
try:
|
||||
host = urlparse(candidate).hostname
|
||||
except ValueError:
|
||||
continue
|
||||
if host and host.lower() == expected_host:
|
||||
return True
|
||||
return False
|
||||
|
||||
|
||||
def comment_intent(comment: str) -> str | None:
|
||||
"""Ordered, most-specific-first rule ladder over the *stripped* text.
|
||||
|
||||
|
|
@ -147,7 +161,7 @@ def comment_intent(comment: str) -> str | None:
|
|||
# -- SIM Ticket: Amazon SIM tooling references.
|
||||
if (
|
||||
re.search(r"\bsim\b.*\b(ticket|tt|v\d{6,})\b", low)
|
||||
or "t.corp.amazon.com" in low
|
||||
or _contains_url_with_host(t, "t.corp.amazon.com")
|
||||
or re.search(r"\bsim\s*tt\b", low)
|
||||
):
|
||||
return "SIM Ticket"
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue