mirror of
https://github.com/Sea-Haven-Industries/apm-wo-analysis.git
synced 2026-09-30 04:13:13 +00:00
chore: resolve open code scanning alerts (URL host matching + workflow permissions) (#36)
Some checks are pending
Deploy / deploy (push) Waiting to run
Some checks are pending
Deploy / deploy (push) Waiting to run
* fix: Refactor `comment_intent` to use `_contains_url_with_host` for URL host matching. * ci: add least-privilege permissions blocks to workflow callers Resolves code scanning alerts #4 and #5 (actions/missing-workflow-permissions). Both callable workflows only need contents: read; the dependency-review callable already declares it internally, this caps the caller token to match.
This commit is contained in:
parent
3748a29744
commit
299ead89b3
3 changed files with 22 additions and 1 deletions
3
.github/workflows/ci.yaml
vendored
3
.github/workflows/ci.yaml
vendored
|
|
@ -3,6 +3,9 @@ on:
|
||||||
pull_request:
|
pull_request:
|
||||||
branches: [main]
|
branches: [main]
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
ci:
|
ci:
|
||||||
uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main
|
uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main
|
||||||
|
|
|
||||||
4
.github/workflows/dependency-review.yml
vendored
4
.github/workflows/dependency-review.yml
vendored
|
|
@ -1,6 +1,10 @@
|
||||||
name: Dependency Review
|
name: Dependency Review
|
||||||
on:
|
on:
|
||||||
pull_request:
|
pull_request:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
review:
|
review:
|
||||||
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main
|
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main
|
||||||
|
|
|
||||||
|
|
@ -25,6 +25,7 @@ from __future__ import annotations
|
||||||
import html
|
import html
|
||||||
import os
|
import os
|
||||||
import re
|
import re
|
||||||
|
from urllib.parse import unquote, urlparse
|
||||||
|
|
||||||
# Axis 2 — Hold Reason → category.
|
# Axis 2 — Hold Reason → category.
|
||||||
HOLD_TO_CATEGORY = {
|
HOLD_TO_CATEGORY = {
|
||||||
|
|
@ -118,6 +119,19 @@ def strip_html(comment: str | None) -> str:
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
|
|
||||||
|
|
||||||
|
def _contains_url_with_host(text: str, expected_host: str) -> bool:
|
||||||
|
"""Return True when ''text'' contains an absolute URL with hostname ''expected_host''."""
|
||||||
|
for raw_url in re.findall(r"https?://[^\s<>'\"()]+", text, flags=re.IGNORECASE):
|
||||||
|
candidate = unquote(raw_url).rstrip(".,;:!?)]}\"'")
|
||||||
|
try:
|
||||||
|
host = urlparse(candidate).hostname
|
||||||
|
except ValueError:
|
||||||
|
continue
|
||||||
|
if host and host.lower() == expected_host:
|
||||||
|
return True
|
||||||
|
return False
|
||||||
|
|
||||||
|
|
||||||
def comment_intent(comment: str) -> str | None:
|
def comment_intent(comment: str) -> str | None:
|
||||||
"""Ordered, most-specific-first rule ladder over the *stripped* text.
|
"""Ordered, most-specific-first rule ladder over the *stripped* text.
|
||||||
|
|
||||||
|
|
@ -147,7 +161,7 @@ def comment_intent(comment: str) -> str | None:
|
||||||
# -- SIM Ticket: Amazon SIM tooling references.
|
# -- SIM Ticket: Amazon SIM tooling references.
|
||||||
if (
|
if (
|
||||||
re.search(r"\bsim\b.*\b(ticket|tt|v\d{6,})\b", low)
|
re.search(r"\bsim\b.*\b(ticket|tt|v\d{6,})\b", low)
|
||||||
or "t.corp.amazon.com" in low
|
or _contains_url_with_host(t, "t.corp.amazon.com")
|
||||||
or re.search(r"\bsim\s*tt\b", low)
|
or re.search(r"\bsim\s*tt\b", low)
|
||||||
):
|
):
|
||||||
return "SIM Ticket"
|
return "SIM Ticket"
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue