Coder Social home page Coder Social logo

Comments (13)

stweil avatar stweil commented on July 22, 2024 1

It's not a real problem for me personally, because my fork runs the same security checks and reports them (so the whole GitHub concept of hiding the security reports is strange and wasting energy for unnecessary computations).

from kitodo-presentation.

stweil avatar stweil commented on July 22, 2024 1

I don't see any notes

Then go to settings/security_analysis and look for "Code scanning" and "Protection rules". There you can set the alert severity levels. Set both levels to "any" to get all the notes, too. Not all kinds of notes are useful, but some of them are.

from kitodo-presentation.

stweil avatar stweil commented on July 22, 2024

Only "members" of the Kitodo organization or the repository can see the security related pages which are mentioned above. I was member in 2017, but obviously removed later.

from kitodo-presentation.

sebastian-meyer avatar sebastian-meyer commented on July 22, 2024

Access can only be granted to admins, members with push rights and specific user groups. I'd have to create a user group and add all current outside collaborators to that group... :o(

from kitodo-presentation.

sebastian-meyer avatar sebastian-meyer commented on July 22, 2024

Votes: 11

from kitodo-presentation.

frank-ulrich-weber avatar frank-ulrich-weber commented on July 22, 2024

Can you please give me access to the security tab to fix the issues and warnings? Thanks!

from kitodo-presentation.

stweil avatar stweil commented on July 22, 2024

It's usually sufficient to fork the repository and use the security tab in your own fork (see my comment above). Then you can either use the fixes which are generated by CodeQL or manual fixes to create a pull request.

from kitodo-presentation.

sebastian-meyer avatar sebastian-meyer commented on July 22, 2024

Can you please give me access to the security tab to fix the issues and warnings? Thanks!

I've granted you the security manager role. You should be able to access the security tab now.

from kitodo-presentation.

frank-ulrich-weber avatar frank-ulrich-weber commented on July 22, 2024

Thanks Stefan and Sebastian, that helps a lot!

from kitodo-presentation.

frank-ulrich-weber avatar frank-ulrich-weber commented on July 22, 2024

I think I'm blind, but now I see 40 security issues on my current fork of the kitodo-presentation master: What do I have to do/configure to see the same amount of issues? How can I apply the same checks on a branch? I think I yust need a hint... Thanks!

from kitodo-presentation.

sebastian-meyer avatar sebastian-meyer commented on July 22, 2024

from kitodo-presentation.

stweil avatar stweil commented on July 22, 2024

GitHub code scanning currently reports 7 warnings and more than 6000 notes for the master branch.

from kitodo-presentation.

sebastian-meyer avatar sebastian-meyer commented on July 22, 2024

I don't see any notes and of the warnings we decided to ignore all that are reported for the 3D viewer javascripts (because those are still in a prototypical state and under heavy development). I've forwarded them to the developers and they will take care of those.
So, for me this looks fine, now.

from kitodo-presentation.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.