Skip to content

upload-sarif always warns when setting partialFingerprints #4052

Description

@tylerbrazier

The documentation recommends calculating partialFingerprints before uploading:

To avoid seeing duplicate alerts, you should calculate fingerprint data and populate the partialFingerprints property before you upload the SARIF file.

However, this always results in a warning in the output with no way to suppress it. If calculating the fingerprint is the recommendation then we should not be seeing a warning for it.

Activity

  1. mbg commented on Jul 29, 2026

    @mbg
    Member

    Hi @tylerbrazier,

    The part of the documentation you quoted is about the general requirement for fingerprints in SARIF files when uploading them to Code Scanning to ensure stable alerts.

    If you are using the CodeQL Action, then the CodeQL Action already generates the fingerprints for you before uploading a SARIF file to Code Scanning. You shouldn't need to calculate them yourself in that case. Indeed, the sentence after the one you quoted suggests looking at the CodeQL Action implementation as a reference. You would only need to generate them yourself if you are uploading files directly to the API.

    Can you clarify whether you are using the analyze or upload-sarif action and whether you have encountered any issues with the fingerprints that are automatically generated by the CodeQL Action?

  2. tylerbrazier commented on Jul 30, 2026

    @tylerbrazier
    Author

    Hi @mgb, We're using the upload-sarif action. I did notice with the default implementation it closes and reopens each security finding with every commit, so that's when we decided to add our own fingerprint generation logic, which doesn't have that problem. We run our action on PR's created by other teams and block the PR until the issues are resolved, so those PR authors go to the action's output to see what caused the issue; the problem is that they also see warnings about fingerprint generation which can totally be ignored, but are misleading for them because they seem to indicate some other problem that they didn't even cause.

  3. mbg commented on Jul 30, 2026

    @mbg
    Member

    I did notice with the default implementation it closes and reopens each security finding with every commit, so that's when we decided to add our own fingerprint generation logic, which doesn't have that problem.

    If you could share any information about the SARIF files this is happening with (e.g. what tool they were generated with or ideally a sample file), then we could investigate the issue. It would also be good if you could share relevant workflow logs. To be clear, the issue here is the alert wobble you experienced when using upload-sarif, not the warnings about fingerprint generation.

  4. tylerbrazier commented on Aug 4, 2026

    @tylerbrazier
    Author

    If you could share any information about the SARIF files this is happening with (e.g. what tool they were generated with or ideally a sample file), then we could investigate the issue.

    This is happening in a private repo for our company so I can't share that specifically; I'll try to reproduce the issue in a test repo and post an update here

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions