mirror of
https://github.com/moltbot/moltbot.git
synced 2026-05-06 23:55:12 +00:00
Renames the default auth/secrets CodeQL security category from the generic javascript-typescript label to core-auth-secrets.
Proof:
- Branch CodeQL security run https://github.com/openclaw/openclaw/actions/runs/25134871512 passed on 1d9f727bfd.
- Core auth/secrets analysis 1200412263 returned 0 results.
- Branch open CodeQL alerts: none.
- Workflow Sanity, Blacksmith Testbox, Blacksmith Build Artifacts Testbox, and OpenGrep PR Diff passed.
Scope is label/config only: same paths, query pack, filters, timeout, and runner.
58 lines
1.3 KiB
YAML
58 lines
1.3 KiB
YAML
name: openclaw-codeql-core-auth-secrets-critical-security
|
|
|
|
disable-default-queries: true
|
|
|
|
queries:
|
|
- uses: security-extended
|
|
|
|
query-filters:
|
|
- include:
|
|
precision:
|
|
- high
|
|
- very-high
|
|
- exclude:
|
|
problem.severity:
|
|
- recommendation
|
|
- warning
|
|
|
|
paths:
|
|
- src/agents/*auth*.ts
|
|
- src/agents/**/*auth*.ts
|
|
- src/agents/auth-health*.ts
|
|
- src/agents/auth-profiles
|
|
- src/agents/bash-tools.exec-host-shared.ts
|
|
- src/agents/sandbox
|
|
- src/agents/sandbox.ts
|
|
- src/agents/sandbox-*.ts
|
|
- src/config/*secret*.ts
|
|
- src/config/**/*secret*.ts
|
|
- src/cron/service/jobs.ts
|
|
- src/cron/stagger.ts
|
|
- src/gateway/*auth*.ts
|
|
- src/gateway/**/*auth*.ts
|
|
- src/gateway/*secret*.ts
|
|
- src/gateway/**/*secret*.ts
|
|
- src/gateway/protocol/**/*secret*.ts
|
|
- src/gateway/resolve-configured-secret-input-string*.ts
|
|
- src/gateway/security-path*.ts
|
|
- src/gateway/server-methods/secrets*.ts
|
|
- src/infra/secret-file*.ts
|
|
- src/secrets
|
|
- src/security
|
|
|
|
paths-ignore:
|
|
- "**/node_modules"
|
|
- "**/coverage"
|
|
- "**/*.generated.ts"
|
|
- "**/*.bundle.js"
|
|
- "**/*-runtime.js"
|
|
- "**/*.test.ts"
|
|
- "**/*.test.tsx"
|
|
- "**/*.e2e.test.ts"
|
|
- "**/*.e2e.test.tsx"
|
|
- "**/*test-support*"
|
|
- "**/*test-helper*"
|
|
- "**/*mock*"
|
|
- "**/*fixture*"
|
|
- "**/*bench*"
|