

- MONGODB COMPASS CREATE DATABASE INVALID NAMESPACE SPECIFIED UPDATE
- MONGODB COMPASS CREATE DATABASE INVALID NAMESPACE SPECIFIED FULL
Run yum update python to update your system. The security adivsory here indicates that the AL2 Python package has been patched and an update is available (in python-2.7.18-1.amzn2.0.5.aarch64). Thanks for any help and information that you can provide! lg. Could the documentation be appended to add additional information about when this particular workflow should be executed?

I found some lines in a YouTube explanation video, showing when the GitHub workflow is triggered, but there is no additional documentation in the GitHub Actions for CodeGuru Reviewer. Lastly, there does not seem to be any documentation for when this GitHub workflow is to be triggered. Why is the SARIF upload skipped if the GitHub event is pushed? I don't see any explanation for why this logic is in place to skip the SARIF upload to GitHub if the GitHub event is a push. According to the GitHub Actions for CodeGuru Reviewer, the Upload Review Result step for uploading the SARIF file to GitHub is skipped if the GitHub event is equal to push. I also do not understand why the SARIF file is not pushed during a GitHub push event. I would expect the recommendation to only be resolved if an actual fix is committed in the corresponding pull request.

MONGODB COMPASS CREATE DATABASE INVALID NAMESPACE SPECIFIED FULL
The behavior seems to report that because the recommendation was not found in the incremental scan, then the recommendation must have been fixed from the full repository scan. However, this is not the case, and no fixes were actually provided in the pull request. When the incremental scan results file is compared to the full repository scan results file, the outcome is that GitHub reports that all recommendations from the full repository scan have been fixed. However, according to CodeGuru, the amount of lines that are scanned during an incremental scan are equivalent to the amount of lines that are scanned during a full repository scan.Īdditionally, when the incremental scan is performed, not all recommendations from the full repository scan are found. In theory, this incremental scan should only scan the code that was changed in our GitHub pull request. When triggering the GitHub actions CodeGuru workflow through a GitHub pull request, this generates an incremental scan on CodeGuru for our GitHub repository. This full repository scan shows all of the findings in the GitHub repository. When dispatching the GitHub actions CodeGuru workflow manually, this generates a full repository scan on CodeGuru for our GitHub repository. We are currently attempting to integrate CodeGuru Reviewer with GitHub actions to scan our code in a GitHub repository.
