ci(ci): exclude local sanity harnesses from JS scan - #262
Conversation
js/clear-text-logging taints process.env, so sanity scripts that log public contract addresses were reported as High. Keep scanning sdk/typescript. Co-authored-by: Cursor <cursoragent@cursor.com> Signed-off-by: JaCoderX <12550942+JaCoderX@users.noreply.github.com>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (2)
Included review availability: Your plan includes up to 1 review per rolling hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe pull request adds a CodeQL configuration file and updates the CodeQL workflow to use it. The configuration excludes sanity harnesses and the LOC-counting script from scans. ChangesCodeQL configuration
Estimated code review effort: 1 (Trivial) | ~5 minutes Merge Risk: ⚪ Minimal · up to This localized CI configuration change has no actionable merge-blocking risk remaining; the owner should ensure the documented CodeQL scope matches the intended policy. Suggested reviewers: Poem
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Summary by CodeRabbit