Fixes #20484: Configure CodeQL to exclude URL redirect false positives

This commit is contained in:
Jason Novinger
2025-10-02 16:27:31 -05:00
parent 5f77d684e1
commit 7907d34a33

View File

@@ -1,3 +1,11 @@
paths-ignore: paths-ignore:
# Ignore compiled JS # Ignore compiled JS
- netbox/project-static/dist - netbox/project-static/dist
query-filters:
# Exclude py/url-redirection: NetBox uses safe_for_redirect() wrapper function
# which validates all redirects via Django's url_has_allowed_host_and_scheme().
# CodeQL's taint tracking doesn't recognize wrapper functions without custom
# query configuration. See #20484.
- exclude:
id: py/url-redirection