diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 6a650cde62..ad952b2a4c 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -97,9 +97,31 @@ jobs: - '**/node_modules/**' - '**/test-output/**' - 'openam-ui/openam-ui-ria/src/main/js/libs/**' + # Unmodified third-party libraries served by openam-server-only: + # YUI 2.3.0, the Sun Web UI (Lockhart) scripts and Bluff 0.3.6.2. + # The com_sun_web_ui JSPs carry OpenAM changes and stay analysed. + - 'openam-server-only/src/main/webapp/assets/lib/yui/**' + - 'openam-server-only/src/main/webapp/com_sun_web_ui/js/**' + - 'openam-server-only/src/main/webapp/js/Bluff-0.3.6.2/**' + # JAXB 1.0.6 classes generated in 2012 and committed, with a copy + # of its com.sun.xml.bind runtime. They yield about 44,500 of the + # 58,900 Java results; a SARIF upload may carry at most 25,000. + # Of an accepted upload Code scanning keeps the top 5,000 results + # by severity: every error and warning of the remaining ~14,400 + # is kept, only recommendation-level results are dropped. + - 'openam-schema/openam-liberty-schema/src/main/java/**' + - 'openam-schema/openam-saml2-schema/src/main/java/**' + - 'openam-schema/openam-wsfederation-schema/src/main/java/**' # .NET build output (generated AssemblyInfo, compiled artifacts). - '**/obj/**' - '**/bin/**' + query-filters: + # The JavaScript extractor parses script blocks of JSPs and Velocity + # templates, and scripts injected into XML, as plain JavaScript, so + # every <%= %>, #if or < is reported as a syntax error. The + # extractor skips a block it cannot parse either way. + - exclude: + id: js/syntax-error # --- Manual build (only used when build-mode is 'manual') ------------- # - name: Set up JDK 11