From 969b66d8791a98f0dbadf3567d593c916042f02e Mon Sep 17 00:00:00 2001 From: Valera V Harseko Date: Wed, 30 Sep 2026 16:58:55 +0300 Subject: [PATCH 1/3] Keep vendored JavaScript and template syntax errors out of CodeQL The JavaScript analysis reports 780 alerts that no change to OpenAM can address: - 482 in unmodified third-party libraries served by openam-server-only: YUI 2.3.0 (assets/lib/yui), the Sun Web UI scripts (com_sun_web_ui/js) and Bluff 0.3.6.2. They are now listed in paths-ignore next to the other vendored JavaScript. The com_sun_web_ui JSPs carry OpenAM changes and stay analysed. - 298 js/syntax-error notes. The extractor parses script blocks of JSPs (<%= %>), Velocity templates (#if, $context) and the default authentication script, which is injected into scripting.xml and therefore XML-escaped, as plain JavaScript. It skips a block it cannot parse either way, so the note carries no finding; the query is excluded through query-filters. --- .github/workflows/codeql.yml | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 6a650cde62..8ff49cd353 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -97,9 +97,22 @@ jobs: - '**/node_modules/**' - '**/test-output/**' - 'openam-ui/openam-ui-ria/src/main/js/libs/**' + # Unmodified third-party libraries served by openam-server-only: + # YUI 2.3.0, the Sun Web UI (Lockhart) scripts and Bluff 0.3.6.2. + # The com_sun_web_ui JSPs carry OpenAM changes and stay analysed. + - 'openam-server-only/src/main/webapp/assets/lib/yui/**' + - 'openam-server-only/src/main/webapp/com_sun_web_ui/js/**' + - 'openam-server-only/src/main/webapp/js/Bluff-0.3.6.2/**' # .NET build output (generated AssemblyInfo, compiled artifacts). - '**/obj/**' - '**/bin/**' + query-filters: + # The JavaScript extractor parses script blocks of JSPs and Velocity + # templates, and scripts injected into XML, as plain JavaScript, so + # every <%= %>, #if or < is reported as a syntax error. The + # extractor skips a block it cannot parse either way. + - exclude: + id: js/syntax-error # --- Manual build (only used when build-mode is 'manual') ------------- # - name: Set up JDK 11 From 2ebb7e7c057723d9ee2d73336d074179b20fdd78 Mon Sep 17 00:00:00 2001 From: Valera V Harseko Date: Wed, 30 Sep 2026 18:53:34 +0300 Subject: [PATCH 2/3] Keep the generated JAXB sources out of the Java CodeQL analysis Since the switch to security-and-quality (#1140) the Java SARIF holds 58863 results, above the 25000 Code scanning accepts, so every Java upload on master is rejected and the alerts fixed by #1133-#1139 still show as open. About 50,000 of those results come from openam-schema's liberty, saml2 and wsfederation modules: 2439 of their 2443 sources were generated by JAXB 1.0.6 in 2012, the other 4 are a copy of its com.sun.xml.bind runtime. Most are missing-override-annotation (23280), reference-equality-on-strings (17272), unused-label (4137) and local-variable-is-never-read (3335). Listing their src/main/java in paths-ignore leaves the rest of the Java code on the full suite. --- .github/workflows/codeql.yml | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 8ff49cd353..11c183bc30 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -103,6 +103,12 @@ jobs: - 'openam-server-only/src/main/webapp/assets/lib/yui/**' - 'openam-server-only/src/main/webapp/com_sun_web_ui/js/**' - 'openam-server-only/src/main/webapp/js/Bluff-0.3.6.2/**' + # JAXB 1.0.6 classes generated in 2012 and committed, with a copy + # of its com.sun.xml.bind runtime. They yield about 50,000 of the + # 59,000 Java results; a SARIF upload may carry at most 25,000. + - 'openam-schema/openam-liberty-schema/src/main/java/**' + - 'openam-schema/openam-saml2-schema/src/main/java/**' + - 'openam-schema/openam-wsfederation-schema/src/main/java/**' # .NET build output (generated AssemblyInfo, compiled artifacts). - '**/obj/**' - '**/bin/**' From bd970992678fc100527dd2861c20626c4600d696 Mon Sep 17 00:00:00 2001 From: Valera V Harseko Date: Thu, 1 Oct 2026 14:56:07 +0300 Subject: [PATCH 3/3] Note the 5,000-result cap of Code scanning next to the JAXB exclusion --- .github/workflows/codeql.yml | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 11c183bc30..ad952b2a4c 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -104,8 +104,11 @@ jobs: - 'openam-server-only/src/main/webapp/com_sun_web_ui/js/**' - 'openam-server-only/src/main/webapp/js/Bluff-0.3.6.2/**' # JAXB 1.0.6 classes generated in 2012 and committed, with a copy - # of its com.sun.xml.bind runtime. They yield about 50,000 of the - # 59,000 Java results; a SARIF upload may carry at most 25,000. + # of its com.sun.xml.bind runtime. They yield about 44,500 of the + # 58,900 Java results; a SARIF upload may carry at most 25,000. + # Of an accepted upload Code scanning keeps the top 5,000 results + # by severity: every error and warning of the remaining ~14,400 + # is kept, only recommendation-level results are dropped. - 'openam-schema/openam-liberty-schema/src/main/java/**' - 'openam-schema/openam-saml2-schema/src/main/java/**' - 'openam-schema/openam-wsfederation-schema/src/main/java/**'