mirror of
https://github.com/sbroenne/mcp-server-excel.git
synced 2026-09-19 07:53:08 +08:00
352b1da895
Reverts the scratch verification commit; confirms PAT push authentication and ruleset bypass work end-to-end for the release-automation fix.
138 lines
4.6 KiB
YAML
138 lines
4.6 KiB
YAML
# CodeQL Configuration for ExcelMcp
|
|
# Defines security scanning rules and exclusions
|
|
# Version: 4.0 - Exclude test code from analysis (production code only)
|
|
#
|
|
# Summary of Intentional Exclusions:
|
|
# - tests/**: Test code doesn't ship to production
|
|
# - cs/catch-of-all-exceptions: MCP/CLI require broad exception handling
|
|
# - cs/call-to-gc: Required for COM resource management
|
|
# - cs/invalid-dynamic-call: COM interop uses dynamic extensively
|
|
#
|
|
# See CODEQL-FIXES-SUMMARY.md for detailed rationale
|
|
|
|
name: "ExcelMcp CodeQL Configuration v3.0"
|
|
|
|
# Disable default query suite and use custom security-focused queries
|
|
disable-default-queries: true
|
|
|
|
# Query packs to run
|
|
queries:
|
|
# Built-in security queries (do not include quality-only rules)
|
|
- uses: security-extended
|
|
|
|
# Paths to exclude from analysis
|
|
paths-ignore:
|
|
- '**/bin/**'
|
|
- '**/obj/**'
|
|
- '**/packages/**'
|
|
- '**/.nuget/**'
|
|
- '**/node_modules/**'
|
|
- '**/*.Designer.cs'
|
|
- '**/*.g.cs'
|
|
- '**/*.g.i.cs'
|
|
- '**/AssemblyInfo.cs'
|
|
- '**/TemporaryGeneratedFile_*.cs'
|
|
- 'tests/**' # Test code doesn't ship to production
|
|
|
|
# Paths to explicitly include (production code only)
|
|
paths:
|
|
- 'src/**'
|
|
|
|
# Query filters - Suppress intentional patterns
|
|
query-filters:
|
|
# ============================================================================
|
|
# INTENTIONAL PATTERN: Generic Exception Catches in MCP Tools
|
|
# MCP protocol requires tools to return JSON responses for ALL errors.
|
|
# Throwing exceptions would break the MCP protocol contract.
|
|
# ============================================================================
|
|
- exclude:
|
|
id: cs/catch-of-all-exceptions
|
|
paths:
|
|
- src/ExcelMcp.McpServer/Tools/**
|
|
|
|
# ============================================================================
|
|
# INTENTIONAL PATTERN: Generic Exception Catches in CLI Commands
|
|
# CLI commands catch exceptions to display user-friendly error messages.
|
|
# This is the standard pattern for command-line applications.
|
|
# ============================================================================
|
|
- exclude:
|
|
id: cs/catch-of-all-exceptions
|
|
paths:
|
|
- src/ExcelMcp.CLI/Commands/**
|
|
- src/ExcelMcp.CLI/Program.cs
|
|
|
|
# ============================================================================
|
|
# INTENTIONAL PATTERN: COM Interop Exception Handling
|
|
# Excel COM automation requires catching exceptions at session/batch boundaries
|
|
# to ensure proper COM cleanup and resource management.
|
|
# ============================================================================
|
|
- exclude:
|
|
id: cs/catch-of-all-exceptions
|
|
paths:
|
|
- src/ExcelMcp.ComInterop/Session/**
|
|
|
|
# ============================================================================
|
|
# INTENTIONAL PATTERN: Dynamic COM Calls
|
|
# Excel COM interop uses late binding (dynamic) extensively.
|
|
# These are not invalid calls - they're the standard COM interop pattern.
|
|
# ============================================================================
|
|
- exclude:
|
|
id: cs/invalid-dynamic-call
|
|
paths:
|
|
- src/ExcelMcp.Core/**
|
|
- src/ExcelMcp.ComInterop/**
|
|
|
|
# ============================================================================
|
|
# INTENTIONAL PATTERN: Explicit GC for COM Cleanup
|
|
# GC.Collect() is required after releasing COM objects to ensure
|
|
# Excel process cleanup. This follows Microsoft guidance for COM interop.
|
|
# ============================================================================
|
|
- exclude:
|
|
id: cs/call-to-gc
|
|
paths:
|
|
- src/ExcelMcp.ComInterop/**
|
|
|
|
# ============================================================================
|
|
# AUTO-GENERATED CODE: Regex Generator
|
|
# System.Text.RegularExpressions.Generator produces code with patterns
|
|
# that trigger CodeQL alerts. This code is compiler-generated and safe.
|
|
# ============================================================================
|
|
- exclude:
|
|
id: cs/useless-cast-to-self
|
|
paths:
|
|
- '**/obj/**'
|
|
- '**/*.g.cs'
|
|
- exclude:
|
|
id: cs/useless-assignment-to-local
|
|
paths:
|
|
- '**/obj/**'
|
|
- '**/*.g.cs'
|
|
- exclude:
|
|
id: cs/complex-block
|
|
paths:
|
|
- '**/obj/**'
|
|
- '**/*.g.cs'
|
|
|
|
# External data sources (for taint tracking)
|
|
# external-repository-token: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
# ML-powered alerts (experimental)
|
|
ml-powered-queries: true
|
|
|
|
# Trap caching for faster subsequent runs
|
|
trap-caching: true
|
|
|
|
# Build mode for compiled languages
|
|
# build-mode: 'manual' for custom build commands
|
|
|
|
# Security policy
|
|
security-policy:
|
|
# Severity levels to report
|
|
minimum-severity: medium
|
|
|
|
# Report on security findings
|
|
fail-on-severity: high
|
|
|
|
# License compliance
|
|
check-licenses: true
|