Make NightVision findings read well in GitHub Code Scanning - #8
Merged
Merged
Conversation
The export's rule help is boilerplate, result messages are Markdown that GitHub shows as raw text, every finding is warning or note, and untraced findings point at a file named "/". Add a stdlib-only enrichment step that fixes all four, adds CWE tags and a run summary, and drops informational and duplicate results. Workflow: add PR scans, a readiness check instead of sleep 10, a manual scan-duration input, scan-ID capture from stdout only, export of findings from failed scans, and exclusion of findings triaged in NightVision. Bump actions to Node 24 majors. The job id stays "test" so the stale alerts from the old per-scan rule IDs close on the next run. Repair the Slack, Teams and email workflows (retired upload-sarif v2, docker-compose v1, removed -a flag, --lang spring, invalid Slack YAML), make Slack manual-only, and point all four at one Code Scanning category. Remove the never-run "improved workflow" file and write a real README. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The CI target is https://localhost:9000, but the July demo-baseline commit turned SSL off and renamed the keystore password to one the keystore does not use, so every scan since then fails the connectivity check. Add docker-compose.ci.yml, which turns SSL on with the keystore's real password for CI only; local demos keep plain HTTP. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
A scan that dies partway (a relay timeout did this on the last PR run) exports a subset of findings, and uploading it marks everything it missed as fixed. Keep partial findings in the artifacts instead. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Code Scanning made the demo look worse than the scan. On the June run every rule ID embedded a per-scan UUID, so each run closed all alerts and opened new ones (alert numbers are at 756 for 26 findings). The current CLI fixes the IDs, but GitHub still renders the export poorly:
**and emojiwarning/note, so SQL injection looks like a missing header/What changed
scripts/nightvision-sarif-enrich.py(stdlib Python): plain-text messages (SQL Injection - PostgreSQL on POST /search.+ proof link), rule help and remediation, CWE tags,errorfor critical/high, rule-levelsecurity-severityand precision, a real file for app-wide findings, and dropping of informational and duplicate results. It also writes a severity table to the job summary. Schema-validated against SARIF 2.1.0; on the June scan it takes 35 raw results to 19 alerts (4 critical, 2 high, 13 low).nightvision.yml: scans PRs too, waits for the app to respond instead ofsleep 10, adds a manual scan-duration input, reads the scan ID from stdout only, still exports findings when a scan ends non-zero, excludes findings triaged as false positive/won't fix in NightVision, uploads artifacts, and bumps actions to Node 24 majors. The job id staystest, so the 26 stale UUID-rule alerts close on the first run.upload-sarif@v2,docker-composev1, removed-aflag,--lang spring, and invalid Slack YAML that meant it never ran). Fixed, Slack made manual-only so pushes don't start a second scan, and all four share one Code Scanning category.improved workflowfile (no.ymlextension), and wrote a real README.Testing
actionlintis clean onnightvision.yml; all workflow YAML parses🤖 Generated with Claude Code