Skip to content

Clarify expression hash input for CodeQL review - #67057

Merged
pelikhan merged 2 commits into
mainfrom
copilot/deep-report-investigate-alert
Oct 9, 2026
Merged

pelikhan merged 2 commits into
mainfrom
copilot/deep-report-investigate-alert

Conversation

Copilot AI commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

A CodeQL alert flagged hashing in expression extraction. The hash is derived from workflow expression source, not evaluated runtime data.

  • Clarification: Document that the digest is used only to generate an environment variable name.
  • Example:
    // content is unevaluated workflow expression source, not its runtime value; the digest is only an environment variable name.
    hash := sha256.Sum256([]byte(content))

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Investigate go/weak-sensitive-data-hashing CodeQL alert Clarify expression hash input for CodeQL review Oct 9, 2026
Copilot AI requested a review from pelikhan October 9, 2026 00:55
@pelikhan
pelikhan marked this pull request as ready for review October 9, 2026 01:12
Copilot AI balanced review requested due to automatic review settings October 9, 2026 01:12

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The documentation accurately reflects the surrounding implementation.

0 open findings

What changed in this PR

Clarifies that expression hashing generates deterministic environment variable names and does not process evaluated runtime data.

Changes:

  • Documents the SHA-256 input and non-security purpose.
File Description
pkg/​workflow/​expression_extraction.go Clarifies expression hashing behavior.

🧠 Review effort: Balanced


💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

@pelikhan
pelikhan merged commit 8578f92 into main Oct 9, 2026
39 checks passed
@pelikhan
pelikhan deleted the copilot/deep-report-investigate-alert branch October 9, 2026 01:49
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.91.7

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[deep-report] Investigate/dismiss-or-fix go/weak-sensitive-data-hashing CodeQL alert in pkg/workflow/expression_extraction.go

3 participants