Skip to content

Suppress false positive CodeQL warning on LocalOrchestrationService#1348

Open
AnatoliB wants to merge 2 commits intomainfrom
anatolib/codeql-fix-37181655-2
Open

Suppress false positive CodeQL warning on LocalOrchestrationService#1348
AnatoliB wants to merge 2 commits intomainfrom
anatolib/codeql-fix-37181655-2

Conversation

@AnatoliB
Copy link
Copy Markdown
Collaborator

@AnatoliB AnatoliB commented May 1, 2026

…alization security in in-proc testing context

Co-authored-by: Copilot <copilot@github.com>
Copilot AI review requested due to automatic review settings May 1, 2026 06:24
@AnatoliB AnatoliB marked this pull request as ready for review May 1, 2026 06:24
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the DurableTask emulator’s in-proc orchestration state JSON serialization settings to suppress security analyzer warnings related to Json.NET TypeNameHandling.

Changes:

  • Adds System.Diagnostics.CodeAnalysis and [SuppressMessage] attributes for CA2326/CA2327 on the StateJsonSettings field.
  • Adds an inline comment explaining why the unsafe-deserialization warnings are considered a false positive for this emulator scenario.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread src/DurableTask.Emulator/LocalOrchestrationService.cs Outdated
Comment thread src/DurableTask.Emulator/LocalOrchestrationService.cs Outdated
Co-authored-by: Copilot <copilot@github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants