Repository navigation
Merge pull request #46 from namecheap/fix/restore-permission-check-su… #23
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # The Jenkins project's own static analysis for plugins: CodeQL run with the | |
| # jenkins-infra query pack rather than the generic Java one, so it looks for the | |
| # mistakes plugins actually make -- unsafe Stapler bindings, do* methods missing | |
| # a permission check or CSRF protection, XSS through Jelly. | |
| # | |
| # This plugin has exactly that surface: BuildAddUrl.BuildUrlAction issues a | |
| # redirect built from a user-supplied URL, DescriptorImpl exposes doCheck* | |
| # methods, and the dashboard interpolates job and environment names into its | |
| # views. | |
| # | |
| # Findings appear under Security > Code scanning; they do not fail the build. | |
| name: Jenkins Security Scan | |
| on: | |
| push: | |
| branches: [master] | |
| pull_request: | |
| types: [opened, synchronize, reopened] | |
| workflow_dispatch: | |
| permissions: | |
| security-events: write | |
| contents: read | |
| actions: read | |
| jobs: | |
| security-scan: | |
| uses: jenkins-infra/jenkins-security-scan/.github/workflows/jenkins-security-scan.yaml@da7438f10fecc21e40174d420ef34daae0874122 # v2.4.0 | |
| with: | |
| java-cache: maven | |
| java-version: 21 |