Skip to content

Please clarify if github/codeql-action/upload-sarif is meant to be used on PRs #3578

Description

@LecrisUT

Given that the commits in a PR are ephemeral, it is unclear what the action would do with those or if the Github internal does some magic to only flag the commits in active branches. My guess is that we should not be uploading these on PRs at all, but I don't know if there is some other workflow that uses them when they are run on PRs?

Activity

  1. mbg commented on Mar 16, 2026

    @mbg
    Member

    Hi @LecrisUT 👋

    I'm not sure I really understand your concerns about uploading SARIF files for PRs, but it is supported. The results will be visible for a PR and (if they remain unresolved) can then be traced back to it.

  2. LecrisUT commented on Mar 16, 2026

    @LecrisUT
    Author

    My concern is if they would show up in the security tab. For example a developer is using a branch new-feature on the main repository and one commit is flagged as a security vulnerability during the PR, but everything is resolved at the end. How is the whole upload to github working in those cases:

    • does it create a security issue in the tab and does any notification propagate because of it?
    • are the issues cleaned up after the branch/PR is closed?
  3. mbg commented on Mar 16, 2026

    @mbg
    Member

    does it create a security issue in the tab and does any notification propagate because of it?

    When your workflow which uses upload-sarif runs for the commit that introduces the vulnerability, the corresponding alert is uploaded as part of the SARIF and stored in the backend. You can then view it on e.g. https://github.com/teemtee/tmt/security/code-scanning by filtering for that branch (the view only shows the default branch by default).

    are the issues cleaned up after the branch/PR is closed?

    If you then push another commit which resolves the security issue, and your workflow which uses upload-sarif runs again, then the alert will not be part of the SARIF that's uploaded and the backend will conclude that the alert has been resolved. It will then automatically be marked as "fixed".

  4. LecrisUT commented on Mar 16, 2026

    @LecrisUT
    Author

    Thank you. It does sound that my concern about ephemeral commits on PR branches may indeed be there. It would be good to document this nuance in either the github doc or here. It at the very least does not make meaningful sense to be doing those uploads if the original source that did the scanning already flags it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions