Skip to content

Keep vendored and generated code out of CodeQL - #1152

Merged
vharseko merged 3 commits into
OpenIdentityPlatform:masterfrom
vharseko:codeql-exclude-vendored-js
Oct 1, 2026
Merged

vharseko merged 3 commits into
OpenIdentityPlatform:masterfrom
vharseko:codeql-exclude-vendored-js

Conversation

@vharseko

@vharseko vharseko commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Summary

Two changes to .github/workflows/codeql.yml:

  1. The JavaScript analysis carries 780 open alerts (of 1099 in Code scanning) that no change to OpenAM code can address. This PR scopes them out; they close with the first scan on master after the merge.
  2. The Java analysis has not uploaded since Run the CodeQL security-and-quality suite #1140. Leaving the generated JAXB sources out brings it back under the SARIF limit.

Vendored libraries → paths-ignore (482 alerts)

Path Library Alerts
openam-server-only/src/main/webapp/assets/lib/yui/** YUI 2.3.0 (2007) 383
openam-server-only/src/main/webapp/com_sun_web_ui/js/** Sun Web UI (Lockhart) scripts 87
openam-server-only/src/main/webapp/js/Bluff-0.3.6.2/** Bluff 0.3.6.2 12

None of these directories has been changed since the initial import. The JSPs under com_sun_web_ui/jsp carry ForgeRock/3A changes, so they stay analysed.

js/syntax-error → query-filters (298 alerts)

The JavaScript extractor parses as plain JavaScript:

  • the script blocks of JSPs (<%= %>, 293 alerts)
  • Velocity templates config/options.htm and config/wizard/step5.htm (#if, $context)
  • openam-scripting/src/main/js/authentication-server-side.js, which openam-scripting/pom.xml injects verbatim into scripting.xml; its &lt; is the intended XML escaping.

The extractor skips any block it cannot parse, so the note carries no finding. It is not a bug in the code.

Generated JAXB sources → paths-ignore (Java upload limit)

Since #1140 switched to security-and-quality, the Java SARIF has 58863 results, more than the 25000 that Code scanning accepts. Every Java upload on master has been rejected since then (run 36687081889). As a result, the Java alerts fixed by #1133–#1139 are still shown as open, and new ones are not recorded.

A local run of the same bundle (CodeQL 2.27.1, build-mode none, security-and-quality) completed 151 of 244 queries before the machine ran out of memory. In those queries, about 50,600 of about 66,900 result rows fall in openam-schema/openam-{liberty,saml2,wsfederation}-schema/src/main/java. Of the 2443 files there, 2439 were generated by JAXB 1.0.6 in 2012 ("Any modifications to this file will be lost upon recompilation"); the other 4 are a copy of its com.sun.xml.bind runtime.

Rule total in these modules
java/missing-override-annotation 32022 23280
java/reference-equality-on-strings 17279 17272
java/unused-label 4138 4137
java/local-variable-is-never-read 3776 3335

A full run of this branch (the whole security-and-quality suite, CodeQL 2.27.1, vharseko/OpenAM run 36855689676, SARIF kept as an artifact instead of uploaded) gives 14370 Java results, so the upload is accepted again; the excluded trees accounted for about 44,500 of the 58863.

Code scanning keeps only the top 5,000 results of an accepted run, ranked by severity (SARIF limits). Of the 14370, 1486 are error or warning (365 of them carry a security-severity), and all of them are kept. The other 12884 are recommendation; about 9,400 of those are dropped on every run (java/missing-override-annotation 8365, java/unused-parameter 1499, java/deprecated-call 938, ...). That is accepted here: recording every maintainability note is not the goal of this PR, and the comment in codeql.yml says so.

Trade-off: with build-mode none, CodeQL does not extract the excluded files, so the JAXB types are unresolved where openam-federation-library uses them. For generated beans this is acceptable.

Test plan

  • The workflow YAML and its embedded config parse. The paths-ignore/query-filters keys are checked against the current open-alert list: 780 alerts match.
  • JavaScript: a full run of this branch (run 36855689676) gives 181 results (973 on master), none in the excluded paths and no js/syntax-error. The PR run cannot show this: CodeQL analyses a pull request diff-informed (only the changed lines, here codeql.yml), so every analysis on refs/pull/1152/merge has 0 results.
  • Java: the same run gives 14370 results, under the 25000 upload limit.
  • After the merge, the first push run on master:
    gh api 'repos/OpenIdentityPlatform/OpenAM/code-scanning/analyses?ref=refs/heads/master&per_page=20' \
      --jq '.[] | select(.category | test("java|javascript")) | "\(.category) \(.results_count) \(.commit_sha[0:10])"'
    # expect java-kotlin < 25000 on the merge commit
    gh api --paginate 'repos/OpenIdentityPlatform/OpenAM/code-scanning/alerts?state=open&tool_name=CodeQL&per_page=100' \
      --jq '.[] | select(.rule.id == "js/syntax-error"
          or (.most_recent_instance.location.path | test("assets/lib/yui/|com_sun_web_ui/js/|Bluff-0\\.3\\.6\\.2/")))
          | .number' | wc -l
    # expect 0

@vharseko vharseko added ci CI, GitHub Actions, or build pipeline security Security fix or hardening (CVE, GHSA, XSS/CSRF/SSRF) java Pull requests that update java code labels Sep 30, 2026
@vharseko vharseko changed the title Keep vendored JavaScript and template syntax errors out of CodeQL Keep vendored and generated code out of CodeQL Sep 30, 2026
@vharseko vharseko removed the java Pull requests that update java code label Sep 30, 2026

@maximthomas maximthomas left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

praise: The exclusions sit exactly where the noise is.

  • com_sun_web_ui/js/** is ignored while com_sun_web_ui/jsp stays analysed, so the JSPs with OpenAM changes keep full coverage.
  • The Java rejection is real (rejecting SARIF, as there are more results per run than allowed (58863 > 25000), run 36687081889). The three JAXB trees hold 17,272 of the 17,279 java/reference-equality-on-strings results, and that count reproduces at the head.
  • js/syntax-error carries no security tag. A parse failure in a hand-written script still shows up through js/diagnostics/extraction-errors: master job 109976439988 lists authentication-server-side.js#L28.

question (non-blocking): Is it acceptable to drop the Java results beyond the top 5,000, or should the upload stay under 5,000?

.github/workflows/codeql.yml:106-111, :115-121

Code scanning keeps only the top 5,000 results of an accepted run, ranked by severity (the SARIF limits table on docs.github.com). The PR's own table leaves 8,742 java/missing-override-annotation results outside the excluded trees, and master's 244/244-query total puts the remainder at about 10,800 at most. After the merge the upload is accepted, but about half of the Java results, the recommendation-level ones, are still dropped on every run. Security results rank higher and are kept. If every Java result is meant to be recorded, one more filter fixes it, and this stays a Minor. If only the rejection matters, a line in the comment is enough.

            query-filters:
              - exclude:
                  id: js/syntax-error
              # Code scanning keeps only the top 5,000 results of a run, by severity;
              # this rule alone leaves about 8,700 outside the JAXB trees.
              - exclude:
                  id: java/missing-override-annotation

suggestion (non-blocking): The JavaScript test-plan item would pass on this PR's run whether or not the exclusions work.

.github/workflows/codeql.yml:103-105, :115-121

The PR's Analyze jobs are diff-informed (Computing PR diff ranges... Persisted 2 diff range(s) across 1 file(s) in run 36740189432). Every analysis on refs/pull/1152/merge therefore has results_count 0, and the check was already green at the base. The description says this for the Java item. The JavaScript item ("reports none of the excluded paths or js/syntax-error") would be ticked from a run that cannot report any result. The Summary already expects the alerts to close with the first scan on master, so the test plan can say that too.

# After the first push run of codeql.yml on master:
gh api 'repos/OpenIdentityPlatform/OpenAM/code-scanning/analyses?ref=refs/heads/master&per_page=20' \
  --jq '.[] | select(.category | test("java|javascript")) | "\(.category) \(.results_count) \(.commit_sha[0:10])"'
# expect java-kotlin < 25000 on the merge commit
gh api --paginate 'repos/OpenIdentityPlatform/OpenAM/code-scanning/alerts?state=open&tool_name=CodeQL&per_page=100' \
  --jq '.[] | select(.rule.id == "js/syntax-error"
      or (.most_recent_instance.location.path | test("assets/lib/yui/|com_sun_web_ui/js/|Bluff-0\\.3\\.6\\.2/")))
      | .number' | wc -l
# expect 0

Pin: use these two checks instead of the second test-plan item. Reverting lines 103-121 makes them fail, while the PR run stays green either way.

The JavaScript analysis reports 780 alerts that no change to OpenAM can
address:

- 482 in unmodified third-party libraries served by openam-server-only:
  YUI 2.3.0 (assets/lib/yui), the Sun Web UI scripts (com_sun_web_ui/js)
  and Bluff 0.3.6.2. They are now listed in paths-ignore next to the
  other vendored JavaScript. The com_sun_web_ui JSPs carry OpenAM
  changes and stay analysed.
- 298 js/syntax-error notes. The extractor parses script blocks of JSPs
  (<%= %>), Velocity templates (#if, $context) and the default
  authentication script, which is injected into scripting.xml and
  therefore XML-escaped, as plain JavaScript. It skips a block it cannot
  parse either way, so the note carries no finding; the query is
  excluded through query-filters.
Since the switch to security-and-quality (OpenIdentityPlatform#1140) the Java SARIF holds
58863 results, above the 25000 Code scanning accepts, so every Java
upload on master is rejected and the alerts fixed by OpenIdentityPlatform#1133-OpenIdentityPlatform#1139 still
show as open.

About 50,000 of those results come from openam-schema's liberty, saml2
and wsfederation modules: 2439 of their 2443 sources were generated by
JAXB 1.0.6 in 2012, the other 4 are a copy of its com.sun.xml.bind
runtime. Most are missing-override-annotation (23280),
reference-equality-on-strings (17272), unused-label (4137) and
local-variable-is-never-read (3335). Listing their src/main/java in
paths-ignore leaves the rest of the Java code on the full suite.
@vharseko
vharseko force-pushed the codeql-exclude-vendored-js branch from 12f287e to bd97099 Compare October 1, 2026 11:56
@vharseko

vharseko commented Oct 1, 2026

Copy link
Copy Markdown
Member Author

Both points checked against a full run of this branch: vharseko/OpenAM run 36855689676, the whole security-and-quality suite with the PR's config, SARIF kept as an artifact instead of uploaded.

question (5,000 kept results): Dropping them is acceptable; bd97099 records it in the comment next to the JAXB exclusion, no extra filter.

The real count is higher than the estimate: 14370 Java results, under 25000, so the upload is accepted. Of those, 1486 are error/warning (365 with a security-severity) and are all kept. The remaining 12884 are recommendation, and about 9,400 of them fall outside the top 5,000. Filtering java/missing-override-annotation (8365) alone would not get the run under 5,000 either: 6005 would remain, mostly java/unused-parameter (1499) and java/deprecated-call (938). The goal here is the upload and the security results, not every maintainability note, so the cap stays as it is.

suggestion (test plan): Taken. The JavaScript item is now backed by the full run, not the diff-informed PR run: 181 results (973 on master), none under yui/, com_sun_web_ui/js/ or Bluff-0.3.6.2/, no js/syntax-error. The Java item has the 14370 from the same run. Your two gh api checks are the post-merge item of the test plan.

@vharseko
vharseko requested a review from maximthomas October 1, 2026 11:57

@maximthomas maximthomas left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

praise: The JAXB comment now carries the measured figures and the cap the upload runs into.

  • .github/workflows/codeql.yml:107-108 matches the measured run: 58,863 Java results, about 44,500 of them in the three JAXB trees.
  • .github/workflows/codeql.yml:109-111 holds: the java.sarif of vharseko/OpenAM run 36855689676 recounts to 371 error + 1,115 warning + 12,884 note = 14,370, and all 365 results with a security-severity are error or warning, so the 1,486 error/warning results all fit under 5,000.

@vharseko
vharseko merged commit 5812b46 into OpenIdentityPlatform:master Oct 1, 2026
14 checks passed
@vharseko
vharseko deleted the codeql-exclude-vendored-js branch October 1, 2026 12:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci CI, GitHub Actions, or build pipeline security Security fix or hardening (CVE, GHSA, XSS/CSRF/SSRF)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants