Repository navigation
upload-sarif always warns when setting partialFingerprints #4052
Description
Activity
Hi @tylerbrazier,
The part of the documentation you quoted is about the general requirement for fingerprints in SARIF files when uploading them to Code Scanning to ensure stable alerts.
If you are using the CodeQL Action, then the CodeQL Action already generates the fingerprints for you before uploading a SARIF file to Code Scanning. You shouldn't need to calculate them yourself in that case. Indeed, the sentence after the one you quoted suggests looking at the CodeQL Action implementation as a reference. You would only need to generate them yourself if you are uploading files directly to the API.
Can you clarify whether you are using the
analyzeorupload-sarifaction and whether you have encountered any issues with the fingerprints that are automatically generated by the CodeQL Action?Hi @mgb, We're using the
upload-sarifaction. I did notice with the default implementation it closes and reopens each security finding with every commit, so that's when we decided to add our own fingerprint generation logic, which doesn't have that problem. We run our action on PR's created by other teams and block the PR until the issues are resolved, so those PR authors go to the action's output to see what caused the issue; the problem is that they also see warnings about fingerprint generation which can totally be ignored, but are misleading for them because they seem to indicate some other problem that they didn't even cause.I did notice with the default implementation it closes and reopens each security finding with every commit, so that's when we decided to add our own fingerprint generation logic, which doesn't have that problem.
If you could share any information about the SARIF files this is happening with (e.g. what tool they were generated with or ideally a sample file), then we could investigate the issue. It would also be good if you could share relevant workflow logs. To be clear, the issue here is the alert wobble you experienced when using
upload-sarif, not the warnings about fingerprint generation.If you could share any information about the SARIF files this is happening with (e.g. what tool they were generated with or ideally a sample file), then we could investigate the issue.
This is happening in a private repo for our company so I can't share that specifically; I'll try to reproduce the issue in a test repo and post an update here
The documentation recommends calculating
partialFingerprintsbefore uploading:However, this always results in a warning in the output with no way to suppress it. If calculating the fingerprint is the recommendation then we should not be seeing a warning for it.