Skip to content

Refactor and enhance Azure Opex Dashboard functionality#290

Draft
gunzip wants to merge 66 commits into
mainfrom
chores/opex-refactor-hex
Draft

Refactor and enhance Azure Opex Dashboard functionality#290
gunzip wants to merge 66 commits into
mainfrom
chores/opex-refactor-hex

fix: remove duplicate checkout step in infra_plan_opex workflow

34061c5
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL failed Sep 14, 2025 in 3s

7 new alerts including 3 high severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 3 high
  • 4 medium

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 62 in .github/workflows/infra_plan_opex.yaml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'infra_plan_opex.yaml' step
Uses Step: get-version
uses 'pagopa/dx/.github/actions/get-terraform-version' with ref 'main', not a pinned commit hash

Check warning on line 140 in .github/workflows/infra_plan_opex.yaml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'infra_plan_opex.yaml' step
Uses Step
uses 'pagopa/dx/.github/actions/azure-login' with ref 'main', not a pinned commit hash

Check warning on line 144 in .github/workflows/infra_plan_opex.yaml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'infra_plan_opex.yaml' step
Uses Step: set-terraform-version
uses 'pagopa/dx/.github/actions/terraform-setup' with ref 'main', not a pinned commit hash

Check warning on line 262 in .github/workflows/infra_plan_opex.yaml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'infra_plan_opex.yaml' step
Uses Step: comment
uses 'pagopa/dx/actions/pr-comment' with ref 'main', not a pinned commit hash

Check failure on line 127 in packages/opex-dashboard-ts/src/domain/services/kusto-query-service.ts

See this annotation in the file changed.

Code scanning / CodeQL

Polynomial regular expression used on uncontrolled data High

This
regular expression
that depends on
library input
may run slow on strings starting with '{' and with many repetitions of '{'.
This
regular expression
that depends on
library input
may run slow on strings starting with '{' and with many repetitions of '{'.
This
regular expression
that depends on
library input
may run slow on strings starting with '{' and with many repetitions of '{'.
This
regular expression
that depends on
library input
may run slow on strings starting with '{' and with many repetitions of '{'.
This
regular expression
that depends on
library input
may run slow on strings starting with '{' and with many repetitions of '{'.
This
regular expression
that depends on
library input
may run slow on strings starting with '{' and with many repetitions of '{'.

Check failure on line 5 in packages/opex-dashboard-ts/src/domain/services/path-utils.ts

See this annotation in the file changed.

Code scanning / CodeQL

Polynomial regular expression used on uncontrolled data High

This
regular expression
that depends on
library input
may run slow on strings starting with '{' and with many repetitions of '{|'.
This
regular expression
that depends on
library input
may run slow on strings starting with '{' and with many repetitions of '{|'.
This
regular expression
that depends on
library input
may run slow on strings starting with '{' and with many repetitions of '{|'.

Check failure on line 185 in packages/opex-dashboard-ts/src/infrastructure/terraform/azure-alerts.ts

See this annotation in the file changed.

Code scanning / CodeQL

Polynomial regular expression used on uncontrolled data High

This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '/'.
This
regular expression
that depends on
library input
may run slow on strings with many repetitions of '/'.