Repository navigation
Move public search scope into the Documents picker #616
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: XSS Sink Check | |
| on: | |
| pull_request: | |
| branches: | |
| - Development | |
| - paullizer-react-v2-ui # Temporary: remove when paullizer-react-v2-ui merges into Development (#1571) | |
| paths: | |
| - 'application/**/*.js' | |
| - 'application/**/*.html' | |
| - 'application/**/*.py' | |
| - 'application/**/*.ts' | |
| - 'application/**/*.tsx' | |
| - 'application/**/*.jsx' | |
| - 'application/**/*.mjs' | |
| - 'scripts/check_xss_sinks.py' | |
| - 'functional_tests/test_xss_guardrails_checker.py' | |
| - '.github/workflows/xss-sink-check.yml' | |
| - '.github/workflows/xss-full-scan.yml' | |
| - '.github/instructions/xss-prevention.instructions.md' | |
| - '.github/prompts/xss-full-audit-and-remediation.prompt.md' | |
| jobs: | |
| xss-sink-check: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 0 | |
| - name: Set up Python | |
| uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 | |
| with: | |
| python-version: '3.12' | |
| - name: Get changed XSS-related files | |
| id: changed-files | |
| uses: tj-actions/changed-files@9426d40962ed5378910ee2e21d5f8c6fcbf2dd96 # v47.0.6 | |
| with: | |
| files_yaml: | | |
| xss_surface: | |
| - 'application/**/*.js' | |
| - 'application/**/*.html' | |
| - 'application/**/*.py' | |
| - 'application/**/*.ts' | |
| - 'application/**/*.tsx' | |
| - 'application/**/*.jsx' | |
| - 'application/**/*.mjs' | |
| xss_guardrails: | |
| - 'scripts/check_xss_sinks.py' | |
| - 'functional_tests/test_xss_guardrails_checker.py' | |
| - '.github/workflows/xss-sink-check.yml' | |
| - '.github/workflows/xss-full-scan.yml' | |
| - '.github/instructions/xss-prevention.instructions.md' | |
| - '.github/prompts/xss-full-audit-and-remediation.prompt.md' | |
| - 'docs/explanation/features/v0.241.022/XSS_PR_GUARDRAILS.md' | |
| - name: Run XSS sink validation | |
| env: | |
| CHANGED_XSS_FILES: ${{ steps.changed-files.outputs.xss_surface_all_changed_files }} | |
| GITHUB_BASE_SHA: ${{ github.event.pull_request.base.sha }} | |
| GITHUB_HEAD_SHA: ${{ github.sha }} | |
| run: | | |
| if [[ -z "$CHANGED_XSS_FILES" ]]; then | |
| echo "No changed application files detected for XSS sink validation." | |
| exit 0 | |
| fi | |
| echo "Changed application files:" | |
| printf '%s\n' "$CHANGED_XSS_FILES" | tr ' ' '\n' | |
| python scripts/check_xss_sinks.py \ | |
| --base-sha "$GITHUB_BASE_SHA" \ | |
| --head-sha "$GITHUB_HEAD_SHA" \ | |
| $CHANGED_XSS_FILES | |
| - name: Run XSS guardrail self-test (advisory) | |
| if: steps.changed-files.outputs.xss_guardrails_any_changed == 'true' | |
| continue-on-error: true | |
| run: | | |
| python functional_tests/test_xss_guardrails_checker.py |