Repository navigation
fix(github insights): Improved Analyzer, new properties, severity fixes for codeScanning findings - #2053
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (2)
🚧 Files skipped from review as they are similar to previous changes (2)
WalkthroughReplaces manual map construction for OpenSSF analysis with a call to Changes
Possibly related PRs
Suggested reviewers
🚥 Pre-merge checks | ✅ 2 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (2 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
✨ Simplify code
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
BenchstatBase: ✅ No significant performance changes detectedFull benchstat output |
There was a problem hiding this comment.
Actionable comments posted: 2
🧹 Nitpick comments (1)
scrapers/github/openssf.go (1)
222-222: Consider logging the error fromToJSONMapinstead of discarding it.While
CheckResultcontains only basic JSON-serializable types, silently discarding errors can mask unexpected issues. The same pattern is used consistently inscraper.go, so this is a minor consistency point.🔧 Optional: Log serialization errors
- a.Analysis, _ = collections.ToJSONMap(check) + if analysisMap, err := collections.ToJSONMap(check); err != nil { + ctx.Warnf("failed to serialize OpenSSF check %q to JSON: %v", check.Name, err) + } else { + a.Analysis = analysisMap + }🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In `@scrapers/github/openssf.go` at line 222, Replace the discarded error from collections.ToJSONMap(check) by capturing it and logging it with the file's existing logger; e.g., call result, err := collections.ToJSONMap(check), assign a.Analysis = result only if err == nil (or assign anyway) and if err != nil emit a clear log entry including context (mention a, check or check.ID) using the logger available in this file (e.g., log/processLogger) so serialization problems are not silently ignored; keep behavior otherwise unchanged.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@scrapers/github/scraper.go`:
- Around line 236-246: The loop over alert.SecurityAdvisory.CWEs currently
slices cweID with cweID[4:] which can panic on malformed IDs; update the code in
the loop (where cweID is obtained and cweURL is built) to first validate the
format (e.g., check strings.HasPrefix(cweID, "CWE-") and len(cweID) > 4 or use
strings.Split/TrimPrefix) before slicing or constructing cweURL, and if the
format is unexpected simply skip adding the URL/Link (but still add the Property
text if desired) to avoid runtime panics.
- Line 186: The assignment a.Analyzer =
alert.GetDependency().GetPackage().GetEcosystem() can panic due to nil returns
from alert.GetDependency() or dependency.GetPackage(); update the code in
scraper.go (around the assignment) to perform defensive nil checks: fetch dep :=
alert.GetDependency(), return or skip if dep==nil, then pkg := dep.GetPackage(),
return or skip if pkg==nil, and only then set a.Analyzer = pkg.GetEcosystem()
(or set a.Analyzer to an empty string/default when nil); ensure you reference
alert.GetDependency(), dependency.GetPackage(), and GetEcosystem() in your
changes so the chain is safely guarded.
---
Nitpick comments:
In `@scrapers/github/openssf.go`:
- Line 222: Replace the discarded error from collections.ToJSONMap(check) by
capturing it and logging it with the file's existing logger; e.g., call result,
err := collections.ToJSONMap(check), assign a.Analysis = result only if err ==
nil (or assign anyway) and if err != nil emit a clear log entry including
context (mention a, check or check.ID) using the logger available in this file
(e.g., log/processLogger) so serialization problems are not silently ignored;
keep behavior otherwise unchanged.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: 1f843efe-c10c-4397-86cb-e57f1e964cb4
📒 Files selected for processing (3)
.gitignorescrapers/github/openssf.goscrapers/github/scraper.go
…blicly leaked, and push protection bypassed badges
d42c549 to
4d9311c
Compare
4d9311c to
8763a4c
Compare
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@scrapers/github/scraper.go`:
- Around line 321-322: The build breaks because the undefined variable configID
is used to derive repoFullName and build codeScanningURL; replace configID with
the function parameter externalConfigID (i.e., use
strings.TrimPrefix(externalConfigID, "github/") when computing repoFullName) so
repoFullName and the fmt.Sprintf call that uses alert.GetNumber() reference the
correct variable.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: 94b56cde-98de-45db-aac2-a5c6183a3bfa
📒 Files selected for processing (2)
scrapers/github/openssf.goscrapers/github/scraper.go
🚧 Files skipped from review as they are similar to previous changes (1)
- scrapers/github/openssf.go
8763a4c to
0ad0ba2
Compare
Summary by CodeRabbit