Exclude 3rd party license compliance content from GHAS scanning#11127
Merged
andyfeller merged 1 commit intotrunkfrom Jun 16, 2025
Merged
Exclude 3rd party license compliance content from GHAS scanning#11127andyfeller merged 1 commit intotrunkfrom
andyfeller merged 1 commit intotrunkfrom
Conversation
These changes will cause GitHub Advanced Security to ignore the auto-generated content around 3rd party dependencies used by `cli/cli` from static code analysis and secret scanning. For more information: - https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/customizing-your-advanced-setup-for-code-scanning - https://docs.github.com/en/code-security/secret-scanning/using-advanced-secret-scanning-and-push-protection-features/excluding-folders-and-files-from-secret-scanning
Contributor
There was a problem hiding this comment.
Pull Request Overview
This PR configures GitHub Advanced Security to skip auto-generated third-party dependency content and associated license files during code scanning and secret scanning.
- Adds
paths-ignorepatterns to the CodeQL workflow to excludethird-party/**and license Markdown files. - Introduces a secret scanning config file that excludes the same paths from secret scanning.
Reviewed Changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| .github/workflows/codeql.yml | Added a config block under the CodeQL analysis step to ignore third-party/** and Markdown license files |
| .github/secret_scanning.yml | New file defining paths-ignore for secret scanning to exclude the third-party directory and license files |
Comments suppressed due to low confidence (1)
.github/secret_scanning.yml:1
- According to GitHub’s secret scanning schema, the config file should include a
versionfield and wrappaths-ignoreunder the proper top-level key (e.g.,push_protectionorsecret_scanning). Please update the file to match the expected structure.
paths-ignore:
tmeijn
pushed a commit
to tmeijn/dotfiles
that referenced
this pull request
Jun 19, 2025
This MR contains the following updates: | Package | Update | Change | |---|---|---| | [cli/cli](https://github.com/cli/cli) | patch | `v2.74.1` -> `v2.74.2` | MR created with the help of [el-capitano/tools/renovate-bot](https://gitlab.com/el-capitano/tools/renovate-bot). **Proposed changes to behavior should be submitted there as MRs.** --- ### Release Notes <details> <summary>cli/cli (cli/cli)</summary> ### [`v2.74.2`](https://github.com/cli/cli/releases/tag/v2.74.2): GitHub CLI 2.74.2 [Compare Source](cli/cli@v2.74.1...v2.74.2) #### What's Changed ##### 🐛 Fixes - Fix assignees being dropped from `gh pr edit` by [@​BagToad](https://github.com/BagToad) in cli/cli#11065 - Add accurate context when run rerun fails by [@​leudz](https://github.com/leudz) in cli/cli#10774 - Avoid requesting MR reviewer twice by [@​williammartin](https://github.com/williammartin) in cli/cli#11099 - Quote filenames suggested at the end of worklow run by [@​williammartin](https://github.com/williammartin) in cli/cli#11134 - Fix expected error output of TestRepo/repo-rename-transfer-ownership by [@​aconsuegra](https://github.com/aconsuegra) in cli/cli#10888 ##### 📚 Docs & Chores - Add instructions for MidnightBSD installation by [@​laffer1](https://github.com/laffer1) in cli/cli#10699 - docs: update install command for Debian by [@​MagneticNeedle](https://github.com/MagneticNeedle) in cli/cli#10935 - Fix step order for CodeQL workflow by [@​BagToad](https://github.com/BagToad) in cli/cli#11145 - Add workflow to check `help wanted` labelling by [@​williammartin](https://github.com/williammartin) in cli/cli#11105 - Quote workflow conditional by [@​williammartin](https://github.com/williammartin) in cli/cli#11122 - Fix script path for help-wanted check by [@​BagToad](https://github.com/BagToad) in cli/cli#11125 - Exclude 3rd party license compliance content from GHAS scanning by [@​andyfeller](https://github.com/andyfeller) in cli/cli#11127 - Second fix for file not found in help-wanted check by [@​BagToad](https://github.com/BagToad) in cli/cli#11128 - Ensure gh executes in workflow check script by [@​williammartin](https://github.com/williammartin) in cli/cli#11133 - Improve help wanted check skipping logic by [@​BagToad](https://github.com/BagToad) in cli/cli#11135 #####Dependencies - Bump go to 1.24 by [@​williammartin](https://github.com/williammartin) in cli/cli#11142 - chore(deps): bump mislav/bump-homebrew-formula-action from 3.2 to 3.4 by [@​dependabot](https://github.com/dependabot) in cli/cli#11066 - chore(deps): bump github.com/sigstore/protobuf-specs from 0.4.2 to 0.4.3 by [@​dependabot](https://github.com/dependabot) in cli/cli#11092 - chore(deps): bump google.golang.org/grpc from 1.72.0 to 1.72.2 by [@​dependabot](https://github.com/dependabot) in cli/cli#11033 - chore(deps): bump actions/attest-build-provenance from 2.3.0 to 2.4.0 by [@​dependabot](https://github.com/dependabot) in cli/cli#11107 - chore(deps): bump github.com/in-toto/attestation from 1.1.1 to 1.1.2 by [@​dependabot](https://github.com/dependabot) in cli/cli#11123 - chore(deps): bump github.com/google/go-containerregistry from 0.20.3 to 0.20.6 by [@​dependabot](https://github.com/dependabot) in cli/cli#11120 - Bump golangci-lint to v2 by [@​williammartin](https://github.com/williammartin) in cli/cli#11121 #### New Contributors - [@​MagneticNeedle](https://github.com/MagneticNeedle) made their first contribution in cli/cli#10935 - [@​laffer1](https://github.com/laffer1) made their first contribution in cli/cli#10699 **Full Changelog**: cli/cli@v2.74.1...v2.74.2 </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever MR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this MR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this MR, check this box --- This MR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MC42MC4xIiwidXBkYXRlZEluVmVyIjoiNDAuNjAuMSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiUmVub3ZhdGUgQm90Il19-->
SamMorrowDrums
added a commit
to github/github-mcp-server
that referenced
this pull request
Dec 12, 2025
- license-check.yml: Auto-regenerate licenses, push fix to PR, and comment - script/licenses: Pin go-licenses version in CI for reproducibility - script/licenses-check: Pin go-licenses version in CI - code-scanning.yml: Exclude third-party folder from CodeQL Inspired by cli/cli improvements: - cli/cli#11161 (pinned version) - cli/cli#11127 (GHAS exclusion) - cli/cli#11370 (auto-regenerate)
SamMorrowDrums
added a commit
to github/github-mcp-server
that referenced
this pull request
Dec 12, 2025
- license-check.yml: Auto-regenerate licenses, push fix to PR, and comment - script/licenses: Pin go-licenses version in CI for reproducibility - script/licenses-check: Pin go-licenses version in CI - code-scanning.yml: Exclude third-party folder from CodeQL Inspired by cli/cli improvements: - cli/cli#11161 (pinned version) - cli/cli#11127 (GHAS exclusion) - cli/cli#11370 (auto-regenerate)
SamMorrowDrums
added a commit
to github/github-mcp-server
that referenced
this pull request
Dec 12, 2025
- license-check.yml: Auto-regenerate licenses, push fix to PR, and comment - script/licenses: Pin go-licenses version in CI for reproducibility - script/licenses-check: Pin go-licenses version in CI - code-scanning.yml: Exclude third-party folder from CodeQL Inspired by cli/cli improvements: - cli/cli#11161 (pinned version) - cli/cli#11127 (GHAS exclusion) - cli/cli#11370 (auto-regenerate)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #11126
Relates #11047
These changes will cause GitHub Advanced Security to ignore the auto-generated content around 3rd party dependencies used by
cli/clifrom static code analysis and secret scanning.For more information: