Compare commits

...

47 Commits

Author SHA1 Message Date
Andrew Eisenberg 8aff97f12c Merge pull request #1346 from github/mergeback/v2.1.31-to-main-c3b6fce4
Mergeback v2.1.31 refs/heads/releases/v2 into main
2022-11-07 02:18:21 -08:00
github-actions[bot] 31a2afec21 Update checked-in dependencies 2022-11-04 23:01:51 +00:00
github-actions[bot] 6a5e69e74f Update changelog and version after v2.1.31 2022-11-04 20:36:31 +00:00
Andrew Eisenberg c3b6fce4ee Merge pull request #1345 from github/update-v2.1.31-a8cabafa
Merge main into releases/v2
2022-11-04 13:33:47 -07:00
Andrew Eisenberg 8aa42f1f11 Update CHANGELOG.md
Add link to codeql PR.
2022-11-04 10:19:29 -07:00
Andrew Eisenberg 29a5553722 Update CHANGELOG.md
Add message about `rb/weak-cryptographic-algorithm`.
2022-11-04 10:14:36 -07:00
github-actions[bot] e260194d76 Update changelog for v2.1.31 2022-11-04 17:05:58 +00:00
Edoardo Pirovano a8cabafa56 Merge pull request #1344 from github/edoardo/prune-ruby
Prune results of Ruby query from SARIF
2022-11-04 17:01:42 +00:00
Edoardo Pirovano 862a512899 Prune results of Ruby query from SARIF 2022-11-04 14:57:13 +00:00
Henry Mercer 71510779c2 Merge pull request #1342 from github/mergeback/v2.1.30-to-main-18fe527f
Mergeback v2.1.30 refs/heads/releases/v2 into main
2022-11-02 13:38:45 +00:00
github-actions[bot] 81a1ec0fb3 Update checked-in dependencies 2022-11-02 12:31:48 +00:00
github-actions[bot] 60c8cda203 Update changelog and version after v2.1.30 2022-11-02 12:13:36 +00:00
Henry Mercer 18fe527fa8 Merge pull request #1341 from github/update-v2.1.30-cd983e71
Merge main into releases/v2
2022-11-02 12:09:34 +00:00
github-actions[bot] f04ca7c11c Update changelog for v2.1.30 2022-11-02 11:23:49 +00:00
Henry Mercer cd983e71c6 Merge pull request #1334 from github/henrymercer/better-error-for-glibc
Add a better error message for users of CodeQL CLI 2.7.2 and earlier running on `ubuntu-22.04`
2022-11-01 16:51:05 +00:00
Angela P Wen 2ec046b5ac Merge pull request #1328 from github/angelapwen/add-go-autobuild-comment
Add Go to list of supported languages
2022-11-01 09:50:32 -07:00
Cornelius Riemenschneider 72bd9cbe62 Merge pull request #1321 from github/criemen/datadog-tag
Actions status report: Send testing_environment.
2022-11-01 16:51:25 +01:00
Angela P Wen ac0112f7f1 Add Go to list of supported languages 2022-11-01 08:28:56 -07:00
Cornelius Riemenschneider 77b1f7e44c Merge remote-tracking branch 'origin/main' into criemen/datadog-tag 2022-11-01 16:15:42 +01:00
Henry Mercer aa07b3894b Merge pull request #1340 from github/henrymercer/fix-proxy-check
Fix missing Docker image in proxy test
2022-11-01 15:07:13 +00:00
Henry Mercer c44e6c6096 Fix missing Docker image in proxy test 2022-11-01 14:32:18 +00:00
Cornelius Riemenschneider ae0a2603c1 Update src/actions-util.ts
Co-authored-by: Henry Mercer <henry.mercer@me.com>
2022-11-01 14:46:41 +01:00
Cornelius Riemenschneider bfcbb093ac Re-export codeql testing environment variable to subsequent steps, if set. 2022-11-01 13:18:57 +01:00
Cornelius Riemenschneider 4b73c4f99e Actions status report: Send testing_environment.
The testing environment is taken from the environment variable
CODEQL_ACTION_TESTING_ENVIRONMENT.
2022-11-01 13:18:57 +01:00
Henry Mercer 6c6b550a41 Add changelog note 2022-10-31 14:22:26 +00:00
Henry Mercer a3141c7a07 Improve error message 2022-10-31 14:19:04 +00:00
Henry Mercer 13cb2ca824 Merge branch 'main' into henrymercer/better-error-for-glibc 2022-10-31 13:44:00 +00:00
Henry Mercer 7e2585030f Merge pull request #1330 from github/henrymercer/ubuntu-image-upgrade
Make PR checks compatible with the latest version of the `ubuntu-latest` runner image
2022-10-31 10:07:19 +00:00
Henry Mercer 4b37e17ec1 Check stdout rather than stderr 2022-10-28 18:59:02 +01:00
Henry Mercer a12a861b82 Add a better error message for users of CodeQL CLI 2.7.2 and earlier
Improves the error message for users running (a) CLI 2.7.2 and earlier
and (b) `ubuntu-22.04`, to which `ubuntu-latest` is now being migrated.
Previously this was "undefined symbol: __libc_dlopen_mode, version
GLIBC_PRIVATE".
Now we give some guidance around glibc versions and using the
`ubuntu-20.04` runner image.
2022-10-28 18:38:00 +01:00
Henry Mercer 993ca05cd7 Fix artifact lookup for ubuntu-20.04 2022-10-27 17:56:45 +01:00
Henry Mercer a31200481f Be more specific about where the 2.7.3 constraint comes from 2022-10-27 16:28:36 +01:00
Henry Mercer 4ed5abeff3 Remove redundant Rubocop checks 2022-10-27 16:23:29 +01:00
Henry Mercer 734292689d Update non-generated checks for ubuntu-latest image update 2022-10-27 16:23:29 +01:00
Henry Mercer 5767f918ef Remove redundant fail-fast configurations 2022-10-27 15:19:07 +01:00
Henry Mercer f248a57d3b Run PR checks for CLIs < 2.7.3 on ubuntu-20.04
Build tracing using CLIs before 2.7.3 no longer works with the most
recent update to the `ubuntu-22.04` runner image.

With this new logic, we can remove the workarounds around testing
`windows-2019` and `windows-2022`.
2022-10-27 15:19:07 +01:00
Edoardo Pirovano 40542d38bc Merge pull request #1326 from github/henrymercer/fix-mergeback-pr-description
Fix mergeback PR description
2022-10-26 14:14:58 +01:00
Henry Mercer 55ffe2dcbb Fix mergeback PR description
Previously the quoted values weren't visible in the PR description.
2022-10-26 12:22:05 +01:00
Edoardo Pirovano 3c7f7914e6 Merge pull request #1324 from github/mergeback/v2.1.29-to-main-ec3cf9c6
Mergeback v2.1.29 refs/heads/releases/v2 into main
2022-10-26 11:08:36 +01:00
github-actions[bot] e76b89fe31 Update checked-in dependencies 2022-10-26 08:59:39 +00:00
github-actions[bot] 98f6408f34 Update changelog and version after v2.1.29 2022-10-26 08:45:16 +00:00
Edoardo Pirovano ec3cf9c605 Merge pull request #1323 from github/update-v2.1.29-4b53723d
Merge main into releases/v2
2022-10-26 09:42:45 +01:00
github-actions[bot] f246f20ec4 Update changelog for v2.1.29 2022-10-26 08:19:54 +00:00
Edoardo Pirovano 4b53723d6b Merge pull request #1320 from github/edoardo/2.11.2-bump
Bump default CodeQL version to 2.11.2
2022-10-25 09:41:40 +01:00
Andrew Eisenberg de9f112cd1 Merge pull request #1318 from github/aeisenberg/bump-min-version
Bumps the min version for code scanning config in the cli
2022-10-24 09:47:34 -07:00
Andrew Eisenberg f1a4ff53b4 Bumps the min version for code scanning config in the cli
2.11.1 has a fix in it for parsing query filters.
2022-10-24 09:20:10 -07:00
Edoardo Pirovano 624418cb40 Bump default CodeQL version to 2.11.2 2022-10-24 13:08:52 +01:00
67 changed files with 608 additions and 237 deletions
+6 -10
View File
@@ -25,19 +25,19 @@ jobs:
strategy: strategy:
matrix: matrix:
include: include:
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210308 version: stable-20210308
- os: macos-latest - os: macos-latest
version: stable-20210308 version: stable-20210308
- os: windows-2019 - os: windows-2019
version: stable-20210308 version: stable-20210308
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210319 version: stable-20210319
- os: macos-latest - os: macos-latest
version: stable-20210319 version: stable-20210319
- os: windows-2019 - os: windows-2019
version: stable-20210319 version: stable-20210319
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210809 version: stable-20210809
- os: macos-latest - os: macos-latest
version: stable-20210809 version: stable-20210809
@@ -47,23 +47,19 @@ jobs:
version: cached version: cached
- os: macos-latest - os: macos-latest
version: cached version: cached
- os: windows-2019 - os: windows-latest
version: cached version: cached
- os: ubuntu-latest - os: ubuntu-latest
version: latest version: latest
- os: macos-latest - os: macos-latest
version: latest version: latest
- os: windows-2019 - os: windows-latest
version: latest
- os: windows-2022
version: latest version: latest
- os: ubuntu-latest - os: ubuntu-latest
version: nightly-latest version: nightly-latest
- os: macos-latest - os: macos-latest
version: nightly-latest version: nightly-latest
- os: windows-2019 - os: windows-latest
version: nightly-latest
- os: windows-2022
version: nightly-latest version: nightly-latest
name: "Analyze: 'ref' and 'sha' from inputs" name: "Analyze: 'ref' and 'sha' from inputs"
timeout-minutes: 45 timeout-minutes: 45
+1 -3
View File
@@ -29,9 +29,7 @@ jobs:
version: latest version: latest
- os: macos-latest - os: macos-latest
version: latest version: latest
- os: windows-2019 - os: windows-latest
version: latest
- os: windows-2022
version: latest version: latest
name: autobuild-action name: autobuild-action
timeout-minutes: 45 timeout-minutes: 45
+6 -10
View File
@@ -25,19 +25,19 @@ jobs:
strategy: strategy:
matrix: matrix:
include: include:
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210308 version: stable-20210308
- os: macos-latest - os: macos-latest
version: stable-20210308 version: stable-20210308
- os: windows-2019 - os: windows-2019
version: stable-20210308 version: stable-20210308
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210319 version: stable-20210319
- os: macos-latest - os: macos-latest
version: stable-20210319 version: stable-20210319
- os: windows-2019 - os: windows-2019
version: stable-20210319 version: stable-20210319
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210809 version: stable-20210809
- os: macos-latest - os: macos-latest
version: stable-20210809 version: stable-20210809
@@ -47,23 +47,19 @@ jobs:
version: cached version: cached
- os: macos-latest - os: macos-latest
version: cached version: cached
- os: windows-2019 - os: windows-latest
version: cached version: cached
- os: ubuntu-latest - os: ubuntu-latest
version: latest version: latest
- os: macos-latest - os: macos-latest
version: latest version: latest
- os: windows-2019 - os: windows-latest
version: latest
- os: windows-2022
version: latest version: latest
- os: ubuntu-latest - os: ubuntu-latest
version: nightly-latest version: nightly-latest
- os: macos-latest - os: macos-latest
version: nightly-latest version: nightly-latest
- os: windows-2019 - os: windows-latest
version: nightly-latest
- os: windows-2022
version: nightly-latest version: nightly-latest
name: 'Go: Custom queries' name: 'Go: Custom queries'
timeout-minutes: 45 timeout-minutes: 45
+3 -3
View File
@@ -25,15 +25,15 @@ jobs:
strategy: strategy:
matrix: matrix:
include: include:
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210308 version: stable-20210308
- os: macos-latest - os: macos-latest
version: stable-20210308 version: stable-20210308
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210319 version: stable-20210319
- os: macos-latest - os: macos-latest
version: stable-20210319 version: stable-20210319
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210809 version: stable-20210809
- os: macos-latest - os: macos-latest
version: stable-20210809 version: stable-20210809
+6 -10
View File
@@ -25,19 +25,19 @@ jobs:
strategy: strategy:
matrix: matrix:
include: include:
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210308 version: stable-20210308
- os: macos-latest - os: macos-latest
version: stable-20210308 version: stable-20210308
- os: windows-2019 - os: windows-2019
version: stable-20210308 version: stable-20210308
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210319 version: stable-20210319
- os: macos-latest - os: macos-latest
version: stable-20210319 version: stable-20210319
- os: windows-2019 - os: windows-2019
version: stable-20210319 version: stable-20210319
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210809 version: stable-20210809
- os: macos-latest - os: macos-latest
version: stable-20210809 version: stable-20210809
@@ -47,23 +47,19 @@ jobs:
version: cached version: cached
- os: macos-latest - os: macos-latest
version: cached version: cached
- os: windows-2019 - os: windows-latest
version: cached version: cached
- os: ubuntu-latest - os: ubuntu-latest
version: latest version: latest
- os: macos-latest - os: macos-latest
version: latest version: latest
- os: windows-2019 - os: windows-latest
version: latest
- os: windows-2022
version: latest version: latest
- os: ubuntu-latest - os: ubuntu-latest
version: nightly-latest version: nightly-latest
- os: macos-latest - os: macos-latest
version: nightly-latest version: nightly-latest
- os: windows-2019 - os: windows-latest
version: nightly-latest
- os: windows-2022
version: nightly-latest version: nightly-latest
name: 'Go: Custom tracing' name: 'Go: Custom tracing'
timeout-minutes: 45 timeout-minutes: 45
+3 -3
View File
@@ -25,15 +25,15 @@ jobs:
strategy: strategy:
matrix: matrix:
include: include:
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210308 version: stable-20210308
- os: macos-latest - os: macos-latest
version: stable-20210308 version: stable-20210308
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210319 version: stable-20210319
- os: macos-latest - os: macos-latest
version: stable-20210319 version: stable-20210319
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210809 version: stable-20210809
- os: macos-latest - os: macos-latest
version: stable-20210809 version: stable-20210809
@@ -25,19 +25,19 @@ jobs:
strategy: strategy:
matrix: matrix:
include: include:
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210308 version: stable-20210308
- os: macos-latest - os: macos-latest
version: stable-20210308 version: stable-20210308
- os: windows-2019 - os: windows-2019
version: stable-20210308 version: stable-20210308
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210319 version: stable-20210319
- os: macos-latest - os: macos-latest
version: stable-20210319 version: stable-20210319
- os: windows-2019 - os: windows-2019
version: stable-20210319 version: stable-20210319
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210809 version: stable-20210809
- os: macos-latest - os: macos-latest
version: stable-20210809 version: stable-20210809
@@ -47,23 +47,19 @@ jobs:
version: cached version: cached
- os: macos-latest - os: macos-latest
version: cached version: cached
- os: windows-2019 - os: windows-latest
version: cached version: cached
- os: ubuntu-latest - os: ubuntu-latest
version: latest version: latest
- os: macos-latest - os: macos-latest
version: latest version: latest
- os: windows-2019 - os: windows-latest
version: latest
- os: windows-2022
version: latest version: latest
- os: ubuntu-latest - os: ubuntu-latest
version: nightly-latest version: nightly-latest
- os: macos-latest - os: macos-latest
version: nightly-latest version: nightly-latest
- os: windows-2019 - os: windows-latest
version: nightly-latest
- os: windows-2022
version: nightly-latest version: nightly-latest
name: 'Go: Reconciled tracing with custom build steps' name: 'Go: Reconciled tracing with custom build steps'
timeout-minutes: 45 timeout-minutes: 45
@@ -25,15 +25,15 @@ jobs:
strategy: strategy:
matrix: matrix:
include: include:
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210308 version: stable-20210308
- os: macos-latest - os: macos-latest
version: stable-20210308 version: stable-20210308
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210319 version: stable-20210319
- os: macos-latest - os: macos-latest
version: stable-20210319 version: stable-20210319
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210809 version: stable-20210809
- os: macos-latest - os: macos-latest
version: stable-20210809 version: stable-20210809
+1 -3
View File
@@ -29,9 +29,7 @@ jobs:
version: nightly-latest version: nightly-latest
- os: macos-latest - os: macos-latest
version: nightly-latest version: nightly-latest
- os: windows-2019 - os: windows-latest
version: nightly-latest
- os: windows-2022
version: nightly-latest version: nightly-latest
name: 'Packaging: Download using registries' name: 'Packaging: Download using registries'
timeout-minutes: 45 timeout-minutes: 45
+3 -3
View File
@@ -25,15 +25,15 @@ jobs:
strategy: strategy:
matrix: matrix:
include: include:
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210308 version: stable-20210308
- os: macos-latest - os: macos-latest
version: stable-20210308 version: stable-20210308
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210319 version: stable-20210319
- os: macos-latest - os: macos-latest
version: stable-20210319 version: stable-20210319
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210809 version: stable-20210809
- os: macos-latest - os: macos-latest
version: stable-20210809 version: stable-20210809
@@ -29,23 +29,19 @@ jobs:
version: latest version: latest
- os: macos-latest - os: macos-latest
version: latest version: latest
- os: windows-2019 - os: windows-latest
version: latest
- os: windows-2022
version: latest version: latest
- os: ubuntu-latest - os: ubuntu-latest
version: cached version: cached
- os: macos-latest - os: macos-latest
version: cached version: cached
- os: windows-2019 - os: windows-latest
version: cached version: cached
- os: ubuntu-latest - os: ubuntu-latest
version: nightly-latest version: nightly-latest
- os: macos-latest - os: macos-latest
version: nightly-latest version: nightly-latest
- os: windows-2019 - os: windows-latest
version: nightly-latest
- os: windows-2022
version: nightly-latest version: nightly-latest
name: 'Packaging: Config and input passed to the CLI' name: 'Packaging: Config and input passed to the CLI'
timeout-minutes: 45 timeout-minutes: 45
+3 -7
View File
@@ -29,23 +29,19 @@ jobs:
version: latest version: latest
- os: macos-latest - os: macos-latest
version: latest version: latest
- os: windows-2019 - os: windows-latest
version: latest
- os: windows-2022
version: latest version: latest
- os: ubuntu-latest - os: ubuntu-latest
version: cached version: cached
- os: macos-latest - os: macos-latest
version: cached version: cached
- os: windows-2019 - os: windows-latest
version: cached version: cached
- os: ubuntu-latest - os: ubuntu-latest
version: nightly-latest version: nightly-latest
- os: macos-latest - os: macos-latest
version: nightly-latest version: nightly-latest
- os: windows-2019 - os: windows-latest
version: nightly-latest
- os: windows-2022
version: nightly-latest version: nightly-latest
name: 'Packaging: Config and input' name: 'Packaging: Config and input'
timeout-minutes: 45 timeout-minutes: 45
+3 -7
View File
@@ -29,23 +29,19 @@ jobs:
version: latest version: latest
- os: macos-latest - os: macos-latest
version: latest version: latest
- os: windows-2019 - os: windows-latest
version: latest
- os: windows-2022
version: latest version: latest
- os: ubuntu-latest - os: ubuntu-latest
version: cached version: cached
- os: macos-latest - os: macos-latest
version: cached version: cached
- os: windows-2019 - os: windows-latest
version: cached version: cached
- os: ubuntu-latest - os: ubuntu-latest
version: nightly-latest version: nightly-latest
- os: macos-latest - os: macos-latest
version: nightly-latest version: nightly-latest
- os: windows-2019 - os: windows-latest
version: nightly-latest
- os: windows-2022
version: nightly-latest version: nightly-latest
name: 'Packaging: Config file' name: 'Packaging: Config file'
timeout-minutes: 45 timeout-minutes: 45
+3 -7
View File
@@ -29,23 +29,19 @@ jobs:
version: latest version: latest
- os: macos-latest - os: macos-latest
version: latest version: latest
- os: windows-2019 - os: windows-latest
version: latest
- os: windows-2022
version: latest version: latest
- os: ubuntu-latest - os: ubuntu-latest
version: cached version: cached
- os: macos-latest - os: macos-latest
version: cached version: cached
- os: windows-2019 - os: windows-latest
version: cached version: cached
- os: ubuntu-latest - os: ubuntu-latest
version: nightly-latest version: nightly-latest
- os: macos-latest - os: macos-latest
version: nightly-latest version: nightly-latest
- os: windows-2019 - os: windows-latest
version: nightly-latest
- os: windows-2022
version: nightly-latest version: nightly-latest
name: 'Packaging: Action input' name: 'Packaging: Action input'
timeout-minutes: 45 timeout-minutes: 45
+6 -10
View File
@@ -25,19 +25,19 @@ jobs:
strategy: strategy:
matrix: matrix:
include: include:
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210308 version: stable-20210308
- os: macos-latest - os: macos-latest
version: stable-20210308 version: stable-20210308
- os: windows-2019 - os: windows-2019
version: stable-20210308 version: stable-20210308
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210319 version: stable-20210319
- os: macos-latest - os: macos-latest
version: stable-20210319 version: stable-20210319
- os: windows-2019 - os: windows-2019
version: stable-20210319 version: stable-20210319
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210809 version: stable-20210809
- os: macos-latest - os: macos-latest
version: stable-20210809 version: stable-20210809
@@ -47,23 +47,19 @@ jobs:
version: cached version: cached
- os: macos-latest - os: macos-latest
version: cached version: cached
- os: windows-2019 - os: windows-latest
version: cached version: cached
- os: ubuntu-latest - os: ubuntu-latest
version: latest version: latest
- os: macos-latest - os: macos-latest
version: latest version: latest
- os: windows-2019 - os: windows-latest
version: latest
- os: windows-2022
version: latest version: latest
- os: ubuntu-latest - os: ubuntu-latest
version: nightly-latest version: nightly-latest
- os: macos-latest - os: macos-latest
version: nightly-latest version: nightly-latest
- os: windows-2019 - os: windows-latest
version: nightly-latest
- os: windows-2022
version: nightly-latest version: nightly-latest
name: Remote config file name: Remote config file
timeout-minutes: 45 timeout-minutes: 45
-10
View File
@@ -25,18 +25,8 @@ jobs:
strategy: strategy:
matrix: matrix:
include: include:
- os: ubuntu-latest
version: stable-20210308
- os: ubuntu-latest
version: stable-20210319
- os: ubuntu-latest
version: stable-20210809
- os: ubuntu-latest - os: ubuntu-latest
version: cached version: cached
- os: ubuntu-latest
version: latest
- os: ubuntu-latest
version: nightly-latest
name: RuboCop multi-language name: RuboCop multi-language
timeout-minutes: 45 timeout-minutes: 45
runs-on: ${{ matrix.os }} runs-on: ${{ matrix.os }}
+2 -2
View File
@@ -51,10 +51,10 @@ jobs:
https_proxy: http://squid-proxy:3128 https_proxy: http://squid-proxy:3128
INTERNAL_CODEQL_ACTION_DEBUG_LOC: true INTERNAL_CODEQL_ACTION_DEBUG_LOC: true
container: container:
image: ubuntu:18.04 image: ubuntu:22.04
options: --dns 127.0.0.1 options: --dns 127.0.0.1
services: services:
squid-proxy: squid-proxy:
image: datadog/squid:latest image: ubuntu/squid:latest
ports: ports:
- 3128:3128 - 3128:3128
+6 -10
View File
@@ -25,19 +25,19 @@ jobs:
strategy: strategy:
matrix: matrix:
include: include:
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210308 version: stable-20210308
- os: macos-latest - os: macos-latest
version: stable-20210308 version: stable-20210308
- os: windows-2019 - os: windows-2019
version: stable-20210308 version: stable-20210308
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210319 version: stable-20210319
- os: macos-latest - os: macos-latest
version: stable-20210319 version: stable-20210319
- os: windows-2019 - os: windows-2019
version: stable-20210319 version: stable-20210319
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210809 version: stable-20210809
- os: macos-latest - os: macos-latest
version: stable-20210809 version: stable-20210809
@@ -47,23 +47,19 @@ jobs:
version: cached version: cached
- os: macos-latest - os: macos-latest
version: cached version: cached
- os: windows-2019 - os: windows-latest
version: cached version: cached
- os: ubuntu-latest - os: ubuntu-latest
version: latest version: latest
- os: macos-latest - os: macos-latest
version: latest version: latest
- os: windows-2019 - os: windows-latest
version: latest
- os: windows-2022
version: latest version: latest
- os: ubuntu-latest - os: ubuntu-latest
version: nightly-latest version: nightly-latest
- os: macos-latest - os: macos-latest
version: nightly-latest version: nightly-latest
- os: windows-2019 - os: windows-latest
version: nightly-latest
- os: windows-2022
version: nightly-latest version: nightly-latest
name: "Upload-sarif: 'ref' and 'sha' from inputs" name: "Upload-sarif: 'ref' and 'sha' from inputs"
timeout-minutes: 45 timeout-minutes: 45
+6 -10
View File
@@ -25,19 +25,19 @@ jobs:
strategy: strategy:
matrix: matrix:
include: include:
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210308 version: stable-20210308
- os: macos-latest - os: macos-latest
version: stable-20210308 version: stable-20210308
- os: windows-2019 - os: windows-2019
version: stable-20210308 version: stable-20210308
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210319 version: stable-20210319
- os: macos-latest - os: macos-latest
version: stable-20210319 version: stable-20210319
- os: windows-2019 - os: windows-2019
version: stable-20210319 version: stable-20210319
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210809 version: stable-20210809
- os: macos-latest - os: macos-latest
version: stable-20210809 version: stable-20210809
@@ -47,23 +47,19 @@ jobs:
version: cached version: cached
- os: macos-latest - os: macos-latest
version: cached version: cached
- os: windows-2019 - os: windows-latest
version: cached version: cached
- os: ubuntu-latest - os: ubuntu-latest
version: latest version: latest
- os: macos-latest - os: macos-latest
version: latest version: latest
- os: windows-2019 - os: windows-latest
version: latest
- os: windows-2022
version: latest version: latest
- os: ubuntu-latest - os: ubuntu-latest
version: nightly-latest version: nightly-latest
- os: macos-latest - os: macos-latest
version: nightly-latest version: nightly-latest
- os: windows-2019 - os: windows-latest
version: nightly-latest
- os: windows-2022
version: nightly-latest version: nightly-latest
name: Use a custom `checkout_path` name: Use a custom `checkout_path`
timeout-minutes: 45 timeout-minutes: 45
@@ -24,7 +24,6 @@ jobs:
continue-on-error: true continue-on-error: true
strategy: strategy:
fail-fast: true
matrix: matrix:
include: include:
- os: ubuntu-latest - os: ubuntu-latest
+34 -5
View File
@@ -19,8 +19,31 @@ jobs:
upload-artifacts: upload-artifacts:
strategy: strategy:
matrix: matrix:
os: [ubuntu-latest, macos-latest] include:
version: [stable-20210308, stable-20210319, stable-20210809, cached, latest, nightly-latest] - os: ubuntu-20.04
version: stable-20210308
- os: macos-latest
version: stable-20210308
- os: ubuntu-20.04
version: stable-20210319
- os: macos-latest
version: stable-20210319
- os: ubuntu-20.04
version: stable-20210809
- os: macos-latest
version: stable-20210809
- os: ubuntu-latest
version: cached
- os: macos-latest
version: cached
- os: ubuntu-latest
version: latest
- os: macos-latest
version: latest
- os: ubuntu-latest
version: nightly-latest
- os: macos-latest
version: nightly-latest
name: Upload debug artifacts name: Upload debug artifacts
timeout-minutes: 45 timeout-minutes: 45
runs-on: ${{ matrix.os }} runs-on: ${{ matrix.os }}
@@ -58,11 +81,17 @@ jobs:
- name: Check expected artifacts exist - name: Check expected artifacts exist
shell: bash shell: bash
run: | run: |
OPERATING_SYSTEMS="ubuntu-latest macos-latest"
VERSIONS="stable-20210308 stable-20210319 stable-20210809 cached latest nightly-latest" VERSIONS="stable-20210308 stable-20210319 stable-20210809 cached latest nightly-latest"
LANGUAGES="cpp csharp go java javascript python" LANGUAGES="cpp csharp go java javascript python"
for os in $OPERATING_SYSTEMS; do for version in $VERSIONS; do
for version in $VERSIONS; do if [[ "$version" =~ stable-(20210308|20210319|20210809) ]]; then
# Note the absence of the period in "ubuntu-2004": this is present in the image name
# but not the artifact name
OPERATING_SYSTEMS="ubuntu-2004 macos-latest"
else
OPERATING_SYSTEMS="ubuntu-latest macos-latest"
fi
for os in $OPERATING_SYSTEMS; do
pushd "./my-debug-artifacts-$os-$version" pushd "./my-debug-artifacts-$os-$version"
echo "Artifacts from version $version on $os:" echo "Artifacts from version $version on $os:"
for language in $LANGUAGES; do for language in $LANGUAGES; do
+2 -1
View File
@@ -121,7 +121,8 @@ jobs:
- [ ] Remove and re-add the "Update dependencies" label to the PR to trigger just this workflow. - [ ] Remove and re-add the "Update dependencies" label to the PR to trigger just this workflow.
- [ ] Wait for the "Update dependencies" workflow to push a commit updating the dependencies. - [ ] Wait for the "Update dependencies" workflow to push a commit updating the dependencies.
- [ ] Mark the PR as ready for review to trigger the full set of PR checks. - [ ] Mark the PR as ready for review to trigger the full set of PR checks.
- [ ] Approve and merge the PR. Make sure `Create a merge commit` is selected rather than `Squash and merge` or `Rebase and merge`. - [ ] Approve and merge the PR. When merging the PR, make sure "Create a merge commit" is
selected rather than "Squash and merge" or "Rebase and merge".
EOF EOF
) )
-1
View File
@@ -16,7 +16,6 @@ jobs:
timeout-minutes: 45 timeout-minutes: 45
strategy: strategy:
fail-fast: true
matrix: matrix:
node-types-version: [12.12, current] node-types-version: [12.12, current]
+4 -4
View File
@@ -26,7 +26,7 @@ jobs:
strategy: strategy:
fail-fast: false fail-fast: false
matrix: matrix:
os: [ubuntu-latest, ubuntu-22.04, macos-latest] os: [ubuntu-20.04, ubuntu-22.04, macos-latest]
python_deps_type: [pipenv, poetry, requirements, setup_py] python_deps_type: [pipenv, poetry, requirements, setup_py]
python_version: [2, 3] python_version: [2, 3]
exclude: exclude:
@@ -65,7 +65,7 @@ jobs:
cd $GITHUB_WORKSPACE/python-setup/tests/${PYTHON_DEPS_TYPE}/requests-${PYTHON_VERSION} cd $GITHUB_WORKSPACE/python-setup/tests/${PYTHON_DEPS_TYPE}/requests-${PYTHON_VERSION}
case ${{ matrix.os }} in case ${{ matrix.os }} in
ubuntu-latest*) basePath="/opt";; ubuntu-20.04*) basePath="/opt";;
ubuntu-22.04*) basePath="/opt";; ubuntu-22.04*) basePath="/opt";;
macos-latest*) basePath="/Users/runner";; macos-latest*) basePath="/Users/runner";;
esac esac
@@ -90,7 +90,7 @@ jobs:
strategy: strategy:
fail-fast: false fail-fast: false
matrix: matrix:
os: [ubuntu-latest, ubuntu-22.04, macos-latest] os: [ubuntu-20.04, ubuntu-22.04, macos-latest]
steps: steps:
# Checks-out your repository under $GITHUB_WORKSPACE, so your job can access it # Checks-out your repository under $GITHUB_WORKSPACE, so your job can access it
@@ -112,7 +112,7 @@ jobs:
cd $GITHUB_WORKSPACE/python-setup/tests/requirements/non-standard-location cd $GITHUB_WORKSPACE/python-setup/tests/requirements/non-standard-location
case ${{ matrix.os }} in case ${{ matrix.os }} in
ubuntu-latest*) basePath="/opt";; ubuntu-20.04*) basePath="/opt";;
ubuntu-22.04*) basePath="/opt";; ubuntu-22.04*) basePath="/opt";;
macos-latest*) basePath="/Users/runner";; macos-latest*) basePath="/Users/runner";;
esac esac
@@ -21,7 +21,7 @@ jobs:
strategy: strategy:
matrix: matrix:
include: include:
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210809 version: stable-20210809
- os: ubuntu-latest - os: ubuntu-latest
version: cached version: cached
@@ -24,9 +24,9 @@ jobs:
strategy: strategy:
matrix: matrix:
include: include:
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210308 version: stable-20210308
- os: ubuntu-latest - os: ubuntu-20.04
version: stable-20210319 version: stable-20210319
name: Test unsetting environment variables name: Test unsetting environment variables
timeout-minutes: 45 timeout-minutes: 45
+12
View File
@@ -4,6 +4,18 @@
No user facing changes. No user facing changes.
## 2.1.31 - 04 Nov 2022
- The `rb/weak-cryptographic-algorithm` Ruby query has been updated to no longer report uses of hash functions such as `MD5` and `SHA1` even if they are known to be weak. These hash algorithms are used very often in non-sensitive contexts, making the query too imprecise in practice. For more information, see the corresponding change in the [github/codeql repository](https://github.com/github/codeql/pull/11129). [#1344](https://github.com/github/codeql-action/pull/1344)
## 2.1.30 - 02 Nov 2022
- Improve the error message when using CodeQL bundle version 2.7.2 and earlier in a workflow that runs on a runner image such as `ubuntu-22.04` that uses glibc version 2.34 and later. [#1334](https://github.com/github/codeql-action/pull/1334)
## 2.1.29 - 26 Oct 2022
- Update default CodeQL bundle version to 2.11.2. [#1320](https://github.com/github/codeql-action/pull/1320)
## 2.1.28 - 18 Oct 2022 ## 2.1.28 - 18 Oct 2022
- Update default CodeQL bundle version to 2.11.1. [#1294](https://github.com/github/codeql-action/pull/1294) - Update default CodeQL bundle version to 2.11.1. [#1294](https://github.com/github/codeql-action/pull/1294)
+1 -1
View File
@@ -61,7 +61,7 @@ jobs:
# with: # with:
# languages: go, javascript, csharp, python, cpp, java # languages: go, javascript, csharp, python, cpp, java
# Autobuild attempts to build any compiled languages (C/C++, C#, or Java). # Autobuild attempts to build any compiled languages (C/C++, C#, Go, or Java).
# If this step fails, then you should remove it and run the build manually (see below). # If this step fails, then you should remove it and run the build manually (see below).
- name: Autobuild - name: Autobuild
uses: github/codeql-action/autobuild@v2 uses: github/codeql-action/autobuild@v2
+7
View File
@@ -502,6 +502,12 @@ async function createStatusReportBase(actionName, status, actionStartedAt, cause
const runnerOs = (0, util_1.getRequiredEnvParam)("RUNNER_OS"); const runnerOs = (0, util_1.getRequiredEnvParam)("RUNNER_OS");
const codeQlCliVersion = (0, util_1.getCachedCodeQlVersion)(); const codeQlCliVersion = (0, util_1.getCachedCodeQlVersion)();
const actionRef = process.env["GITHUB_ACTION_REF"]; const actionRef = process.env["GITHUB_ACTION_REF"];
const testingEnvironment = process.env[sharedEnv.CODEQL_ACTION_TESTING_ENVIRONMENT] || "";
// re-export the testing environment variable so that it is available to subsequent steps,
// even if it was only set for this step
if (testingEnvironment !== "") {
core.exportVariable(sharedEnv.CODEQL_ACTION_TESTING_ENVIRONMENT, testingEnvironment);
}
const statusReport = { const statusReport = {
workflow_run_id: workflowRunID, workflow_run_id: workflowRunID,
workflow_name: workflowName, workflow_name: workflowName,
@@ -515,6 +521,7 @@ async function createStatusReportBase(actionName, status, actionStartedAt, cause
started_at: workflowStartedAt, started_at: workflowStartedAt,
action_started_at: actionStartedAt.toISOString(), action_started_at: actionStartedAt.toISOString(),
status, status,
testing_environment: testingEnvironment,
runner_os: runnerOs, runner_os: runnerOs,
action_version: pkg.version, action_version: pkg.version,
}; };
File diff suppressed because one or more lines are too long
Generated
+35 -12
View File
@@ -22,7 +22,7 @@ var __importDefault = (this && this.__importDefault) || function (mod) {
return (mod && mod.__esModule) ? mod : { "default": mod }; return (mod && mod.__esModule) ? mod : { "default": mod };
}; };
Object.defineProperty(exports, "__esModule", { value: true }); Object.defineProperty(exports, "__esModule", { value: true });
exports.getExtraOptions = exports.getCodeQLForTesting = exports.getCachedCodeQL = exports.setCodeQL = exports.getCodeQL = exports.convertToSemVer = exports.getCodeQLURLVersion = exports.setupCodeQL = exports.getCodeQLActionRepository = exports.CODEQL_VERSION_BETTER_RESOLVE_LANGUAGES = exports.CODEQL_VERSION_ML_POWERED_QUERIES_WINDOWS = exports.CODEQL_VERSION_NEW_TRACING = exports.CODEQL_VERSION_GHES_PACK_DOWNLOAD = exports.CODEQL_VERSION_CONFIG_FILES = exports.CODEQL_VERSION_COUNTS_LINES = exports.CODEQL_DEFAULT_ACTION_REPOSITORY = exports.CommandInvocationError = void 0; exports.getExtraOptions = exports.getCodeQLForTesting = exports.getCachedCodeQL = exports.setCodeQL = exports.getCodeQL = exports.convertToSemVer = exports.getCodeQLURLVersion = exports.setupCodeQL = exports.getCodeQLActionRepository = exports.CODEQL_VERSION_BETTER_RESOLVE_LANGUAGES = exports.CODEQL_VERSION_ML_POWERED_QUERIES_WINDOWS = exports.CODEQL_VERSION_TRACING_GLIBC_2_34 = exports.CODEQL_VERSION_NEW_TRACING = exports.CODEQL_VERSION_GHES_PACK_DOWNLOAD = exports.CODEQL_VERSION_CONFIG_FILES = exports.CODEQL_VERSION_COUNTS_LINES = exports.CODEQL_DEFAULT_ACTION_REPOSITORY = exports.CommandInvocationError = void 0;
const fs = __importStar(require("fs")); const fs = __importStar(require("fs"));
const path = __importStar(require("path")); const path = __importStar(require("path"));
const toolrunner = __importStar(require("@actions/exec/lib/toolrunner")); const toolrunner = __importStar(require("@actions/exec/lib/toolrunner"));
@@ -43,10 +43,11 @@ const trap_caching_1 = require("./trap-caching");
const util = __importStar(require("./util")); const util = __importStar(require("./util"));
const util_1 = require("./util"); const util_1 = require("./util");
class CommandInvocationError extends Error { class CommandInvocationError extends Error {
constructor(cmd, args, exitCode, error) { constructor(cmd, args, exitCode, error, output) {
super(`Failure invoking ${cmd} with arguments ${args}.\n super(`Failure invoking ${cmd} with arguments ${args}.\n
Exit code ${exitCode} and error was:\n Exit code ${exitCode} and error was:\n
${error}`); ${error}`);
this.output = output;
} }
} }
exports.CommandInvocationError = CommandInvocationError; exports.CommandInvocationError = CommandInvocationError;
@@ -93,6 +94,11 @@ exports.CODEQL_VERSION_GHES_PACK_DOWNLOAD = "2.10.4";
* versions above that. * versions above that.
*/ */
exports.CODEQL_VERSION_NEW_TRACING = "2.7.0"; exports.CODEQL_VERSION_NEW_TRACING = "2.7.0";
/**
* Versions 2.7.3+ of the CodeQL CLI support build tracing with glibc 2.34 on Linux. Versions before
* this cannot perform build tracing when running on the Actions `ubuntu-22.04` runner image.
*/
exports.CODEQL_VERSION_TRACING_GLIBC_2_34 = "2.7.3";
/** /**
* Versions 2.9.0+ of the CodeQL CLI run machine learning models from a temporary directory, which * Versions 2.9.0+ of the CodeQL CLI run machine learning models from a temporary directory, which
* resolves an issue on Windows where TensorFlow models are not correctly loaded due to the path of * resolves an issue on Windows where TensorFlow models are not correctly loaded due to the path of
@@ -467,15 +473,32 @@ async function getCodeQLForCmd(cmd, checkVersion) {
// action/runner has been implemented in `codeql database trace-command` // action/runner has been implemented in `codeql database trace-command`
// _and_ is present in the latest supported CLI release.) // _and_ is present in the latest supported CLI release.)
const envFile = path.resolve(databasePath, "working", "env.tmp"); const envFile = path.resolve(databasePath, "working", "env.tmp");
await runTool(cmd, [ try {
"database", await runTool(cmd, [
"trace-command", "database",
databasePath, "trace-command",
...getExtraOptionsFromEnv(["database", "trace-command"]), databasePath,
process.execPath, ...getExtraOptionsFromEnv(["database", "trace-command"]),
tracerEnvJs, process.execPath,
envFile, tracerEnvJs,
]); envFile,
]);
}
catch (e) {
if (e instanceof CommandInvocationError &&
e.output.includes("undefined symbol: __libc_dlopen_mode, version GLIBC_PRIVATE") &&
process.platform === "linux" &&
!(await util.codeQlVersionAbove(this, exports.CODEQL_VERSION_TRACING_GLIBC_2_34))) {
throw new util.UserError("The CodeQL CLI is incompatible with the version of glibc on your system. " +
`Please upgrade to CodeQL CLI version ${exports.CODEQL_VERSION_TRACING_GLIBC_2_34} or ` +
"later. If you cannot upgrade to a newer version of the CodeQL CLI, you can " +
`alternatively run your workflow on another runner image such as "ubuntu-20.04" ` +
"that has glibc 2.33 or earlier installed.");
}
else {
throw e;
}
}
return JSON.parse(fs.readFileSync(envFile, "utf-8")); return JSON.parse(fs.readFileSync(envFile, "utf-8"));
}, },
async databaseInit(databasePath, language, sourceRoot) { async databaseInit(databasePath, language, sourceRoot) {
@@ -864,7 +887,7 @@ async function runTool(cmd, args = []) {
ignoreReturnCode: true, ignoreReturnCode: true,
}).exec(); }).exec();
if (exitCode !== 0) if (exitCode !== 0)
throw new CommandInvocationError(cmd, args, exitCode, error); throw new CommandInvocationError(cmd, args, exitCode, error, output);
return output; return output;
} }
/** /**
+1 -1
View File
File diff suppressed because one or more lines are too long
+1 -1
View File
@@ -1,3 +1,3 @@
{ {
"bundleVersion": "codeql-bundle-20221010" "bundleVersion": "codeql-bundle-20221024"
} }
+1 -1
View File
@@ -37,7 +37,7 @@ exports.featureConfig = {
}, },
[Feature.CliConfigFileEnabled]: { [Feature.CliConfigFileEnabled]: {
envVar: "CODEQL_PASS_CONFIG_TO_CLI", envVar: "CODEQL_PASS_CONFIG_TO_CLI",
minimumVersion: "2.10.1", minimumVersion: "2.11.1",
}, },
[Feature.GolangExtractionReconciliationEnabled]: { [Feature.GolangExtractionReconciliationEnabled]: {
envVar: "CODEQL_GOLANG_EXTRACTION_RECONCILIATION", envVar: "CODEQL_GOLANG_EXTRACTION_RECONCILIATION",
+2 -1
View File
@@ -1,6 +1,6 @@
"use strict"; "use strict";
Object.defineProperty(exports, "__esModule", { value: true }); Object.defineProperty(exports, "__esModule", { value: true });
exports.CODEQL_WORKFLOW_STARTED_AT = exports.ODASA_TRACER_CONFIGURATION = void 0; exports.CODEQL_ACTION_TESTING_ENVIRONMENT = exports.CODEQL_WORKFLOW_STARTED_AT = exports.ODASA_TRACER_CONFIGURATION = void 0;
exports.ODASA_TRACER_CONFIGURATION = "ODASA_TRACER_CONFIGURATION"; exports.ODASA_TRACER_CONFIGURATION = "ODASA_TRACER_CONFIGURATION";
// The time at which the first action (normally init) started executing. // The time at which the first action (normally init) started executing.
// If a workflow invokes a different action without first invoking the init // If a workflow invokes a different action without first invoking the init
@@ -8,4 +8,5 @@ exports.ODASA_TRACER_CONFIGURATION = "ODASA_TRACER_CONFIGURATION";
// then this variable will be assigned the start time of the action invoked // then this variable will be assigned the start time of the action invoked
// rather that the init action. // rather that the init action.
exports.CODEQL_WORKFLOW_STARTED_AT = "CODEQL_WORKFLOW_STARTED_AT"; exports.CODEQL_WORKFLOW_STARTED_AT = "CODEQL_WORKFLOW_STARTED_AT";
exports.CODEQL_ACTION_TESTING_ENVIRONMENT = "CODEQL_ACTION_TESTING_ENVIRONMENT";
//# sourceMappingURL=shared-environment.js.map //# sourceMappingURL=shared-environment.js.map
+1 -1
View File
@@ -1 +1 @@
{"version":3,"file":"shared-environment.js","sourceRoot":"","sources":["../src/shared-environment.ts"],"names":[],"mappings":";;;AAAa,QAAA,0BAA0B,GAAG,4BAA4B,CAAC;AACvE,wEAAwE;AACxE,2EAA2E;AAC3E,4EAA4E;AAC5E,2EAA2E;AAC3E,+BAA+B;AAClB,QAAA,0BAA0B,GAAG,4BAA4B,CAAC"} {"version":3,"file":"shared-environment.js","sourceRoot":"","sources":["../src/shared-environment.ts"],"names":[],"mappings":";;;AAAa,QAAA,0BAA0B,GAAG,4BAA4B,CAAC;AACvE,wEAAwE;AACxE,2EAA2E;AAC3E,4EAA4E;AAC5E,2EAA2E;AAC3E,+BAA+B;AAClB,QAAA,0BAA0B,GAAG,4BAA4B,CAAC;AAE1D,QAAA,iCAAiC,GAC5C,mCAAmC,CAAC"}
+36 -1
View File
@@ -22,9 +22,10 @@ var __importDefault = (this && this.__importDefault) || function (mod) {
return (mod && mod.__esModule) ? mod : { "default": mod }; return (mod && mod.__esModule) ? mod : { "default": mod };
}; };
Object.defineProperty(exports, "__esModule", { value: true }); Object.defineProperty(exports, "__esModule", { value: true });
exports.validateUniqueCategory = exports.waitForProcessing = exports.buildPayload = exports.validateSarifFileSchema = exports.countResultsInSarif = exports.uploadFromRunner = exports.uploadFromActions = exports.findSarifFilesInDir = exports.populateRunAutomationDetails = exports.combineSarifFiles = void 0; exports.pruneInvalidResults = exports.validateUniqueCategory = exports.waitForProcessing = exports.buildPayload = exports.validateSarifFileSchema = exports.countResultsInSarif = exports.uploadFromRunner = exports.uploadFromActions = exports.findSarifFilesInDir = exports.populateRunAutomationDetails = exports.combineSarifFiles = void 0;
const fs = __importStar(require("fs")); const fs = __importStar(require("fs"));
const path = __importStar(require("path")); const path = __importStar(require("path"));
const process_1 = require("process");
const zlib_1 = __importDefault(require("zlib")); const zlib_1 = __importDefault(require("zlib"));
const core = __importStar(require("@actions/core")); const core = __importStar(require("@actions/core"));
const file_url_1 = __importDefault(require("file-url")); const file_url_1 = __importDefault(require("file-url"));
@@ -269,6 +270,8 @@ async function uploadFiles(sarifFiles, repositoryNwo, commitOid, ref, analysisKe
let sarif = combineSarifFiles(sarifFiles); let sarif = combineSarifFiles(sarifFiles);
sarif = await fingerprints.addFingerprints(sarif, sourceRoot, logger); sarif = await fingerprints.addFingerprints(sarif, sourceRoot, logger);
sarif = populateRunAutomationDetails(sarif, category, analysisKey, environment); sarif = populateRunAutomationDetails(sarif, category, analysisKey, environment);
if (process_1.env["CODEQL_DISABLE_SARIF_PRUNING"] !== "true")
sarif = pruneInvalidResults(sarif, logger);
const toolNames = util.getToolNames(sarif); const toolNames = util.getToolNames(sarif);
validateUniqueCategory(sarif); validateUniqueCategory(sarif);
const sarifPayload = JSON.stringify(sarif); const sarifPayload = JSON.stringify(sarif);
@@ -376,4 +379,36 @@ exports.validateUniqueCategory = validateUniqueCategory;
function sanitize(str) { function sanitize(str) {
return (str !== null && str !== void 0 ? str : "_").replace(/[^a-zA-Z0-9_]/g, "_").toLocaleUpperCase(); return (str !== null && str !== void 0 ? str : "_").replace(/[^a-zA-Z0-9_]/g, "_").toLocaleUpperCase();
} }
function pruneInvalidResults(sarif, logger) {
var _a, _b, _c, _d, _e, _f, _g, _h;
let pruned = 0;
const newRuns = [];
for (const run of sarif.runs || []) {
if (((_b = (_a = run.tool) === null || _a === void 0 ? void 0 : _a.driver) === null || _b === void 0 ? void 0 : _b.name) === "CodeQL" &&
((_d = (_c = run.tool) === null || _c === void 0 ? void 0 : _c.driver) === null || _d === void 0 ? void 0 : _d.semanticVersion) === "2.11.2") {
// Version 2.11.2 of the CodeQL CLI had many false positives in the
// rb/weak-cryptographic-algorithm query which we prune here. The
// issue is tracked in https://github.com/github/codeql/issues/11107.
const newResults = [];
for (const result of run.results || []) {
if (result.ruleId === "rb/weak-cryptographic-algorithm" &&
(((_f = (_e = result.message) === null || _e === void 0 ? void 0 : _e.text) === null || _f === void 0 ? void 0 : _f.includes(" MD5 ")) ||
((_h = (_g = result.message) === null || _g === void 0 ? void 0 : _g.text) === null || _h === void 0 ? void 0 : _h.includes(" SHA1 ")))) {
pruned += 1;
continue;
}
newResults.push(result);
}
newRuns.push({ ...run, results: newResults });
}
else {
newRuns.push(run);
}
}
if (pruned > 0) {
logger.info(`Pruned ${pruned} results believed to be invalid from SARIF file.`);
}
return { ...sarif, runs: newRuns };
}
exports.pruneInvalidResults = pruneInvalidResults;
//# sourceMappingURL=upload-lib.js.map //# sourceMappingURL=upload-lib.js.map
File diff suppressed because one or more lines are too long
+100
View File
@@ -28,6 +28,7 @@ const ava_1 = __importDefault(require("ava"));
const logging_1 = require("./logging"); const logging_1 = require("./logging");
const testing_utils_1 = require("./testing-utils"); const testing_utils_1 = require("./testing-utils");
const uploadLib = __importStar(require("./upload-lib")); const uploadLib = __importStar(require("./upload-lib"));
const upload_lib_1 = require("./upload-lib");
const util_1 = require("./util"); const util_1 = require("./util");
(0, testing_utils_1.setupTests)(ava_1.default); (0, testing_utils_1.setupTests)(ava_1.default);
ava_1.default.beforeEach(() => { ava_1.default.beforeEach(() => {
@@ -200,6 +201,105 @@ ava_1.default.beforeEach(() => {
t.throws(() => uploadLib.validateUniqueCategory(sarif1)); t.throws(() => uploadLib.validateUniqueCategory(sarif1));
t.throws(() => uploadLib.validateUniqueCategory(sarif2)); t.throws(() => uploadLib.validateUniqueCategory(sarif2));
}); });
(0, ava_1.default)("pruneInvalidResults", (t) => {
const loggedMessages = [];
const mockLogger = {
info: (message) => {
loggedMessages.push(message);
},
};
const sarif = {
runs: [
{
tool: otherTool,
results: [resultWithBadMessage1, resultWithGoodMessage],
},
{
tool: affectedCodeQLVersion,
results: [
resultWithOtherRuleId,
resultWithBadMessage1,
resultWithBadMessage2,
resultWithGoodMessage,
],
},
{
tool: unaffectedCodeQLVersion,
results: [resultWithBadMessage1, resultWithGoodMessage],
},
],
};
const result = (0, upload_lib_1.pruneInvalidResults)(sarif, mockLogger);
const expected = {
runs: [
{
tool: otherTool,
results: [resultWithBadMessage1, resultWithGoodMessage],
},
{
tool: affectedCodeQLVersion,
results: [resultWithOtherRuleId, resultWithGoodMessage],
},
{
tool: unaffectedCodeQLVersion,
results: [resultWithBadMessage1, resultWithGoodMessage],
},
],
};
t.deepEqual(result, expected);
t.deepEqual(loggedMessages.length, 1);
t.assert(loggedMessages[0].includes("Pruned 2 results"));
});
const affectedCodeQLVersion = {
driver: {
name: "CodeQL",
semanticVersion: "2.11.2",
},
};
const unaffectedCodeQLVersion = {
driver: {
name: "CodeQL",
semanticVersion: "2.11.3",
},
};
const otherTool = {
driver: {
name: "Some other tool",
semanticVersion: "2.11.2",
},
};
const resultWithOtherRuleId = {
ruleId: "doNotPrune",
message: {
text: "should not be pruned even though it says MD5 in it",
},
locations: [],
partialFingerprints: {},
};
const resultWithGoodMessage = {
ruleId: "rb/weak-cryptographic-algorithm",
message: {
text: "should not be pruned SHA128 is not a FP",
},
locations: [],
partialFingerprints: {},
};
const resultWithBadMessage1 = {
ruleId: "rb/weak-cryptographic-algorithm",
message: {
text: "should be pruned MD5 is a FP",
},
locations: [],
partialFingerprints: {},
};
const resultWithBadMessage2 = {
ruleId: "rb/weak-cryptographic-algorithm",
message: {
text: "should be pruned SHA1 is a FP",
},
locations: [],
partialFingerprints: {},
};
function createMockSarif(id, tool) { function createMockSarif(id, tool) {
return { return {
runs: [ runs: [
File diff suppressed because one or more lines are too long
+1 -1
View File
File diff suppressed because one or more lines are too long
+1 -1
View File
@@ -1,6 +1,6 @@
{ {
"name": "codeql", "name": "codeql",
"version": "2.1.29", "version": "2.1.32",
"lockfileVersion": 2, "lockfileVersion": 2,
"requires": true, "requires": true,
"packages": { "packages": {
+2 -2
View File
@@ -1,12 +1,12 @@
{ {
"name": "codeql", "name": "codeql",
"version": "2.1.29", "version": "2.1.32",
"lockfileVersion": 2, "lockfileVersion": 2,
"requires": true, "requires": true,
"packages": { "packages": {
"": { "": {
"name": "codeql", "name": "codeql",
"version": "2.1.29", "version": "2.1.32",
"license": "MIT", "license": "MIT",
"dependencies": { "dependencies": {
"@actions/artifact": "^1.1.0", "@actions/artifact": "^1.1.0",
+1 -1
View File
@@ -1,6 +1,6 @@
{ {
"name": "codeql", "name": "codeql",
"version": "2.1.29", "version": "2.1.32",
"private": true, "private": true,
"description": "CodeQL action", "description": "CodeQL action",
"scripts": { "scripts": {
+1 -1
View File
@@ -1,7 +1,7 @@
name: "Extractor ram and threads options test" name: "Extractor ram and threads options test"
description: "Tests passing RAM and threads limits to extractors" description: "Tests passing RAM and threads limits to extractors"
versions: ["latest"] versions: ["latest"]
os: ["ubuntu-latest"] operatingSystems: ["ubuntu"]
steps: steps:
- uses: ./../action/init - uses: ./../action/init
with: with:
@@ -1,6 +1,6 @@
name: "Go: Autobuild custom tracing" name: "Go: Autobuild custom tracing"
description: "Checks that Go tracing works in conjunction with the autobuilder" description: "Checks that Go tracing works in conjunction with the autobuilder"
os: ["ubuntu-latest", "macos-latest"] operatingSystems: ["ubuntu", "macos"]
env: env:
CODEQL_EXTRACTOR_GO_BUILD_TRACING: "on" CODEQL_EXTRACTOR_GO_BUILD_TRACING: "on"
DOTNET_GENERATE_ASPNET_CERTIFICATE: "false" DOTNET_GENERATE_ASPNET_CERTIFICATE: "false"
@@ -1,6 +1,6 @@
name: "Go: Reconciled tracing with autobuilder" name: "Go: Reconciled tracing with autobuilder"
description: "Checks that Go reconciled tracing works when using an autobuilder step" description: "Checks that Go reconciled tracing works when using an autobuilder step"
os: ["ubuntu-latest", "macos-latest"] operatingSystems: ["ubuntu", "macos"]
env: env:
CODEQL_ACTION_RECONCILE_GO_EXTRACTION: "true" CODEQL_ACTION_RECONCILE_GO_EXTRACTION: "true"
DOTNET_GENERATE_ASPNET_CERTIFICATE: "false" DOTNET_GENERATE_ASPNET_CERTIFICATE: "false"
@@ -1,6 +1,6 @@
name: "Go: Reconciled tracing with legacy workflow" name: "Go: Reconciled tracing with legacy workflow"
description: "Checks that we run the autobuilder in legacy workflows with neither an autobuild step nor manual build steps" description: "Checks that we run the autobuilder in legacy workflows with neither an autobuild step nor manual build steps"
os: ["ubuntu-latest", "macos-latest"] operatingSystems: ["ubuntu", "macos"]
env: env:
# Enable reconciled Go tracing beta functionality # Enable reconciled Go tracing beta functionality
CODEQL_ACTION_RECONCILE_GO_EXTRACTION: "true" CODEQL_ACTION_RECONCILE_GO_EXTRACTION: "true"
+1 -1
View File
@@ -1,7 +1,7 @@
name: "Custom source root" name: "Custom source root"
description: "Checks that the argument specifying a non-default source root works" description: "Checks that the argument specifying a non-default source root works"
versions: ["latest", "cached", "nightly-latest"] # This feature is not compatible with old CLIs versions: ["latest", "cached", "nightly-latest"] # This feature is not compatible with old CLIs
os: ["ubuntu-latest"] operatingSystems: ["ubuntu"]
steps: steps:
- name: Move codeql-action - name: Move codeql-action
shell: bash shell: bash
-2
View File
@@ -7,8 +7,6 @@ versions: [
"latest", "latest",
"nightly-latest", "nightly-latest",
] ]
# Test on all three platforms since ML-powered queries use native code
os: ["ubuntu-latest", "macos-latest", "windows-latest"]
steps: steps:
- uses: ./../action/init - uses: ./../action/init
with: with:
@@ -1,6 +1,6 @@
name: "Multi-language repository" name: "Multi-language repository"
description: "An end-to-end integration test of a multi-language repository using automatic language detection" description: "An end-to-end integration test of a multi-language repository using automatic language detection"
os: ["ubuntu-latest", "macos-latest"] operatingSystems: ["ubuntu", "macos"]
steps: steps:
- uses: ./../action/init - uses: ./../action/init
with: with:
+3 -1
View File
@@ -1,6 +1,8 @@
name: "RuboCop multi-language" name: "RuboCop multi-language"
description: "Tests using RuboCop to analyze a multi-language repository and then using the CodeQL Action to upload the resulting SARIF" description: "Tests using RuboCop to analyze a multi-language repository and then using the CodeQL Action to upload the resulting SARIF"
os: ["ubuntu-latest"] operatingSystems: ["ubuntu"]
# This check doesn't use CodeQL, so the `version` matrix variable is unused.
versions: ["cached"]
steps: steps:
- name: Set up Ruby - name: Set up Ruby
uses: ruby/setup-ruby@v1 uses: ruby/setup-ruby@v1
+1 -1
View File
@@ -1,6 +1,6 @@
name: "Split workflow" name: "Split workflow"
description: "Tests a split-up workflow in which we first build a database and later analyze it" description: "Tests a split-up workflow in which we first build a database and later analyze it"
os: ["ubuntu-latest", "macos-latest"] operatingSystems: ["ubuntu", "macos"]
versions: ["latest", "cached", "nightly-latest"] # This feature is not compatible with old CLIs versions: ["latest", "cached", "nightly-latest"] # This feature is not compatible with old CLIs
steps: steps:
- uses: ./../action/init - uses: ./../action/init
@@ -1,7 +1,7 @@
name: "Autobuild working directory" name: "Autobuild working directory"
description: "Tests working-directory input of autobuild action" description: "Tests working-directory input of autobuild action"
versions: ["latest"] versions: ["latest"]
os: ["ubuntu-latest"] operatingSystems: ["ubuntu"]
steps: steps:
- name: Test setup - name: Test setup
shell: bash shell: bash
+1 -1
View File
@@ -1,7 +1,7 @@
name: "Local CodeQL bundle" name: "Local CodeQL bundle"
description: "Tests using a CodeQL bundle from a local file rather than a URL" description: "Tests using a CodeQL bundle from a local file rather than a URL"
versions: ["nightly-latest"] versions: ["nightly-latest"]
os: ["ubuntu-latest"] operatingSystems: ["ubuntu"]
steps: steps:
- name: Fetch a CodeQL bundle - name: Fetch a CodeQL bundle
shell: bash shell: bash
+3 -3
View File
@@ -1,13 +1,13 @@
name: "Proxy test" name: "Proxy test"
description: "Tests using a proxy specified by the https_proxy environment variable" description: "Tests using a proxy specified by the https_proxy environment variable"
versions: ["latest"] versions: ["latest"]
os: ["ubuntu-latest"] operatingSystems: ["ubuntu"]
container: container:
image: ubuntu:18.04 image: ubuntu:22.04
options: --dns 127.0.0.1 options: --dns 127.0.0.1
services: services:
squid-proxy: squid-proxy:
image: datadog/squid:latest image: ubuntu/squid:latest
ports: ports:
- 3128:3128 - 3128:3128
env: env:
+1 -1
View File
@@ -1,7 +1,7 @@
name: "Ruby analysis" name: "Ruby analysis"
description: "Tests creation of a Ruby database" description: "Tests creation of a Ruby database"
versions: ["latest", "cached", "nightly-latest"] versions: ["latest", "cached", "nightly-latest"]
os: ["ubuntu-latest", "macos-latest"] operatingSystems: ["ubuntu", "macos"]
env: env:
CODEQL_ENABLE_EXPERIMENTAL_FEATURES: "true" CODEQL_ENABLE_EXPERIMENTAL_FEATURES: "true"
steps: steps:
-4
View File
@@ -1,9 +1,5 @@
name: "Use a custom `checkout_path`" name: "Use a custom `checkout_path`"
description: "Checks that a custom `checkout_path` will find the proper commit_oid" description: "Checks that a custom `checkout_path` will find the proper commit_oid"
# Build tracing currently does not support Windows 2022, so use `windows-2019` instead of
# `windows-latest`.
# Must test on all three platforms since this test does path manipulation
os: [ubuntu-latest, macos-latest, windows-2019]
steps: steps:
# Check out the actions repo again, but at a different location. # Check out the actions repo again, but at a different location.
# choose an arbitrary SHA so that we can later test that the commit_oid is not from main # choose an arbitrary SHA so that we can later test that the commit_oid is not from main
+28 -19
View File
@@ -1,6 +1,7 @@
import ruamel.yaml import ruamel.yaml
import os import os
# The default set of CodeQL Bundle versions to use for the PR checks.
defaultTestVersions = [ defaultTestVersions = [
# The oldest supported CodeQL version: 2.4.5. If bumping, update `CODEQL_MINIMUM_VERSION` in `codeql.ts` # The oldest supported CodeQL version: 2.4.5. If bumping, update `CODEQL_MINIMUM_VERSION` in `codeql.ts`
"stable-20210308", "stable-20210308",
@@ -15,7 +16,24 @@ defaultTestVersions = [
# A nightly build directly from the our private repo, built in the last 24 hours. # A nightly build directly from the our private repo, built in the last 24 hours.
"nightly-latest" "nightly-latest"
] ]
defaultOperatingSystems = ["ubuntu-latest", "macos-latest", "windows-2019"]
def isCompatibleWithLatestImages(version):
if version in ["cached", "latest", "nightly-latest"]:
return True
date = version.split("-")[1]
# The first version of the CodeQL CLI compatible with `ubuntu-22.04` and `windows-2022` is
# 2.7.3. This appears in CodeQL Bundle version codeql-bundle-20211208.
return date >= "20211208"
def operatingSystemsForVersion(version):
if isCompatibleWithLatestImages(version):
return ["ubuntu-latest", "macos-latest", "windows-latest"]
else:
return ["ubuntu-20.04", "macos-latest", "windows-2019"]
header = """# Warning: This file is generated automatically, and should not be modified. header = """# Warning: This file is generated automatically, and should not be modified.
# Instead, please modify the template in the pr-checks directory and run: # Instead, please modify the template in the pr-checks directory and run:
# pip install ruamel.yaml && python3 sync.py # pip install ruamel.yaml && python3 sync.py
@@ -23,6 +41,7 @@ header = """# Warning: This file is generated automatically, and should not be m
""" """
class NonAliasingRTRepresenter(ruamel.yaml.representer.RoundTripRepresenter): class NonAliasingRTRepresenter(ruamel.yaml.representer.RoundTripRepresenter):
def ignore_aliases(self, data): def ignore_aliases(self, data):
return True return True
@@ -39,13 +58,6 @@ for file in os.listdir('checks'):
with open(f"checks/{file}", 'r') as checkStream: with open(f"checks/{file}", 'r') as checkStream:
checkSpecification = yaml.load(checkStream) checkSpecification = yaml.load(checkStream)
versions = defaultTestVersions
if 'versions' in checkSpecification:
versions = checkSpecification['versions']
operatingSystems = defaultOperatingSystems
if 'os' in checkSpecification:
operatingSystems = checkSpecification['os']
steps = [ steps = [
{ {
'name': 'Check out repository', 'name': 'Check out repository',
@@ -63,20 +75,17 @@ for file in os.listdir('checks'):
steps.extend(checkSpecification['steps']) steps.extend(checkSpecification['steps'])
matrix = [] matrix = []
for version in versions: for version in checkSpecification.get('versions', defaultTestVersions):
for os in operatingSystems: runnerImages = operatingSystemsForVersion(version)
if checkSpecification.get('operatingSystems', None):
runnerImages = [image for image in runnerImages for operatingSystem in checkSpecification['operatingSystems']
if image.startswith(operatingSystem)]
for runnerImage in runnerImages:
matrix.append({ matrix.append({
'os': os, 'os': runnerImage,
'version': version 'version': version
}) })
if (version == 'latest' or version == 'nightly-latest') and os == 'windows-2019':
# New versions of the CLI should also work with Windows Server 2022.
# Once all versions of the CLI that we test against work with Windows Server 2022,
# we should remove this logic and instead just add windows-2022 to the test matrix.
matrix.append({
'os': 'windows-2022',
'version': version
})
checkJob = { checkJob = {
'strategy': { 'strategy': {
+17
View File
@@ -600,6 +600,12 @@ export interface StatusReportBase {
completed_at?: string; completed_at?: string;
/** State this action is currently in. */ /** State this action is currently in. */
status: ActionStatus; status: ActionStatus;
/**
* Testing environment: Set if non-production environment.
* The server accepts one of the following values:
* `["", "qa-rc", "qa-rc-1", "qa-rc-2", "qa-experiment-1", "qa-experiment-2", "qa-experiment-3"]`.
*/
testing_environment: string;
/** /**
* Information about the enablement of the ML-powered JS query pack. * Information about the enablement of the ML-powered JS query pack.
* *
@@ -675,6 +681,16 @@ export async function createStatusReportBase(
const runnerOs = getRequiredEnvParam("RUNNER_OS"); const runnerOs = getRequiredEnvParam("RUNNER_OS");
const codeQlCliVersion = getCachedCodeQlVersion(); const codeQlCliVersion = getCachedCodeQlVersion();
const actionRef = process.env["GITHUB_ACTION_REF"]; const actionRef = process.env["GITHUB_ACTION_REF"];
const testingEnvironment =
process.env[sharedEnv.CODEQL_ACTION_TESTING_ENVIRONMENT] || "";
// re-export the testing environment variable so that it is available to subsequent steps,
// even if it was only set for this step
if (testingEnvironment !== "") {
core.exportVariable(
sharedEnv.CODEQL_ACTION_TESTING_ENVIRONMENT,
testingEnvironment
);
}
const statusReport: StatusReportBase = { const statusReport: StatusReportBase = {
workflow_run_id: workflowRunID, workflow_run_id: workflowRunID,
@@ -689,6 +705,7 @@ export async function createStatusReportBase(
started_at: workflowStartedAt, started_at: workflowStartedAt,
action_started_at: actionStartedAt.toISOString(), action_started_at: actionStartedAt.toISOString(),
status, status,
testing_environment: testingEnvironment,
runner_os: runnerOs, runner_os: runnerOs,
action_version: pkg.version, action_version: pkg.version,
}; };
+47 -11
View File
@@ -48,7 +48,13 @@ interface ExtraOptions {
} }
export class CommandInvocationError extends Error { export class CommandInvocationError extends Error {
constructor(cmd: string, args: string[], exitCode: number, error: string) { constructor(
cmd: string,
args: string[],
exitCode: number,
error: string,
public output: string
) {
super( super(
`Failure invoking ${cmd} with arguments ${args}.\n `Failure invoking ${cmd} with arguments ${args}.\n
Exit code ${exitCode} and error was:\n Exit code ${exitCode} and error was:\n
@@ -263,6 +269,12 @@ export const CODEQL_VERSION_GHES_PACK_DOWNLOAD = "2.10.4";
*/ */
export const CODEQL_VERSION_NEW_TRACING = "2.7.0"; export const CODEQL_VERSION_NEW_TRACING = "2.7.0";
/**
* Versions 2.7.3+ of the CodeQL CLI support build tracing with glibc 2.34 on Linux. Versions before
* this cannot perform build tracing when running on the Actions `ubuntu-22.04` runner image.
*/
export const CODEQL_VERSION_TRACING_GLIBC_2_34 = "2.7.3";
/** /**
* Versions 2.9.0+ of the CodeQL CLI run machine learning models from a temporary directory, which * Versions 2.9.0+ of the CodeQL CLI run machine learning models from a temporary directory, which
* resolves an issue on Windows where TensorFlow models are not correctly loaded due to the path of * resolves an issue on Windows where TensorFlow models are not correctly loaded due to the path of
@@ -742,15 +754,39 @@ async function getCodeQLForCmd(
// _and_ is present in the latest supported CLI release.) // _and_ is present in the latest supported CLI release.)
const envFile = path.resolve(databasePath, "working", "env.tmp"); const envFile = path.resolve(databasePath, "working", "env.tmp");
await runTool(cmd, [ try {
"database", await runTool(cmd, [
"trace-command", "database",
databasePath, "trace-command",
...getExtraOptionsFromEnv(["database", "trace-command"]), databasePath,
process.execPath, ...getExtraOptionsFromEnv(["database", "trace-command"]),
tracerEnvJs, process.execPath,
envFile, tracerEnvJs,
]); envFile,
]);
} catch (e) {
if (
e instanceof CommandInvocationError &&
e.output.includes(
"undefined symbol: __libc_dlopen_mode, version GLIBC_PRIVATE"
) &&
process.platform === "linux" &&
!(await util.codeQlVersionAbove(
this,
CODEQL_VERSION_TRACING_GLIBC_2_34
))
) {
throw new util.UserError(
"The CodeQL CLI is incompatible with the version of glibc on your system. " +
`Please upgrade to CodeQL CLI version ${CODEQL_VERSION_TRACING_GLIBC_2_34} or ` +
"later. If you cannot upgrade to a newer version of the CodeQL CLI, you can " +
`alternatively run your workflow on another runner image such as "ubuntu-20.04" ` +
"that has glibc 2.33 or earlier installed."
);
} else {
throw e;
}
}
return JSON.parse(fs.readFileSync(envFile, "utf-8")); return JSON.parse(fs.readFileSync(envFile, "utf-8"));
}, },
async databaseInit( async databaseInit(
@@ -1259,7 +1295,7 @@ async function runTool(cmd: string, args: string[] = []) {
ignoreReturnCode: true, ignoreReturnCode: true,
}).exec(); }).exec();
if (exitCode !== 0) if (exitCode !== 0)
throw new CommandInvocationError(cmd, args, exitCode, error); throw new CommandInvocationError(cmd, args, exitCode, error, output);
return output; return output;
} }
+1 -1
View File
@@ -1,3 +1,3 @@
{ {
"bundleVersion": "codeql-bundle-20221010" "bundleVersion": "codeql-bundle-20221024"
} }
+1 -1
View File
@@ -26,7 +26,7 @@ export const featureConfig: Record<
}, },
[Feature.CliConfigFileEnabled]: { [Feature.CliConfigFileEnabled]: {
envVar: "CODEQL_PASS_CONFIG_TO_CLI", envVar: "CODEQL_PASS_CONFIG_TO_CLI",
minimumVersion: "2.10.1", minimumVersion: "2.11.1",
}, },
[Feature.GolangExtractionReconciliationEnabled]: { [Feature.GolangExtractionReconciliationEnabled]: {
envVar: "CODEQL_GOLANG_EXTRACTION_RECONCILIATION", envVar: "CODEQL_GOLANG_EXTRACTION_RECONCILIATION",
+3
View File
@@ -5,3 +5,6 @@ export const ODASA_TRACER_CONFIGURATION = "ODASA_TRACER_CONFIGURATION";
// then this variable will be assigned the start time of the action invoked // then this variable will be assigned the start time of the action invoked
// rather that the init action. // rather that the init action.
export const CODEQL_WORKFLOW_STARTED_AT = "CODEQL_WORKFLOW_STARTED_AT"; export const CODEQL_WORKFLOW_STARTED_AT = "CODEQL_WORKFLOW_STARTED_AT";
export const CODEQL_ACTION_TESTING_ENVIRONMENT =
"CODEQL_ACTION_TESTING_ENVIRONMENT";
+115 -3
View File
@@ -3,14 +3,16 @@ import * as path from "path";
import test from "ava"; import test from "ava";
import { getRunnerLogger } from "./logging"; import { getRunnerLogger, Logger } from "./logging";
import { setupTests } from "./testing-utils"; import { setupTests } from "./testing-utils";
import * as uploadLib from "./upload-lib"; import * as uploadLib from "./upload-lib";
import { pruneInvalidResults } from "./upload-lib";
import { import {
GitHubVariant,
GitHubVersion,
initializeEnvironment, initializeEnvironment,
Mode, Mode,
GitHubVersion, SarifFile,
GitHubVariant,
withTmpDir, withTmpDir,
} from "./util"; } from "./util";
@@ -344,6 +346,116 @@ test("validateUniqueCategory for multiple runs", (t) => {
t.throws(() => uploadLib.validateUniqueCategory(sarif2)); t.throws(() => uploadLib.validateUniqueCategory(sarif2));
}); });
test("pruneInvalidResults", (t) => {
const loggedMessages: string[] = [];
const mockLogger = {
info: (message: string) => {
loggedMessages.push(message);
},
} as Logger;
const sarif: SarifFile = {
runs: [
{
tool: otherTool,
results: [resultWithBadMessage1, resultWithGoodMessage],
},
{
tool: affectedCodeQLVersion,
results: [
resultWithOtherRuleId,
resultWithBadMessage1,
resultWithBadMessage2,
resultWithGoodMessage,
],
},
{
tool: unaffectedCodeQLVersion,
results: [resultWithBadMessage1, resultWithGoodMessage],
},
],
};
const result = pruneInvalidResults(sarif, mockLogger);
const expected: SarifFile = {
runs: [
{
tool: otherTool,
results: [resultWithBadMessage1, resultWithGoodMessage],
},
{
tool: affectedCodeQLVersion,
results: [resultWithOtherRuleId, resultWithGoodMessage],
},
{
tool: unaffectedCodeQLVersion,
results: [resultWithBadMessage1, resultWithGoodMessage],
},
],
};
t.deepEqual(result, expected);
t.deepEqual(loggedMessages.length, 1);
t.assert(loggedMessages[0].includes("Pruned 2 results"));
});
const affectedCodeQLVersion = {
driver: {
name: "CodeQL",
semanticVersion: "2.11.2",
},
};
const unaffectedCodeQLVersion = {
driver: {
name: "CodeQL",
semanticVersion: "2.11.3",
},
};
const otherTool = {
driver: {
name: "Some other tool",
semanticVersion: "2.11.2",
},
};
const resultWithOtherRuleId = {
ruleId: "doNotPrune",
message: {
text: "should not be pruned even though it says MD5 in it",
},
locations: [],
partialFingerprints: {},
};
const resultWithGoodMessage = {
ruleId: "rb/weak-cryptographic-algorithm",
message: {
text: "should not be pruned SHA128 is not a FP",
},
locations: [],
partialFingerprints: {},
};
const resultWithBadMessage1 = {
ruleId: "rb/weak-cryptographic-algorithm",
message: {
text: "should be pruned MD5 is a FP",
},
locations: [],
partialFingerprints: {},
};
const resultWithBadMessage2 = {
ruleId: "rb/weak-cryptographic-algorithm",
message: {
text: "should be pruned SHA1 is a FP",
},
locations: [],
partialFingerprints: {},
};
function createMockSarif(id?: string, tool?: string) { function createMockSarif(id?: string, tool?: string) {
return { return {
runs: [ runs: [
+44 -1
View File
@@ -1,5 +1,6 @@
import * as fs from "fs"; import * as fs from "fs";
import * as path from "path"; import * as path from "path";
import { env } from "process";
import zlib from "zlib"; import zlib from "zlib";
import * as core from "@actions/core"; import * as core from "@actions/core";
@@ -15,7 +16,7 @@ import { Logger } from "./logging";
import { parseRepositoryNwo, RepositoryNwo } from "./repository"; import { parseRepositoryNwo, RepositoryNwo } from "./repository";
import * as sharedEnv from "./shared-environment"; import * as sharedEnv from "./shared-environment";
import * as util from "./util"; import * as util from "./util";
import { SarifFile } from "./util"; import { SarifFile, SarifResult, SarifRun } from "./util";
// Takes a list of paths to sarif files and combines them together, // Takes a list of paths to sarif files and combines them together,
// returning the contents of the combined sarif file. // returning the contents of the combined sarif file.
@@ -396,6 +397,9 @@ async function uploadFiles(
environment environment
); );
if (env["CODEQL_DISABLE_SARIF_PRUNING"] !== "true")
sarif = pruneInvalidResults(sarif, logger);
const toolNames = util.getToolNames(sarif); const toolNames = util.getToolNames(sarif);
validateUniqueCategory(sarif); validateUniqueCategory(sarif);
@@ -546,3 +550,42 @@ export function validateUniqueCategory(sarif: SarifFile): void {
function sanitize(str?: string) { function sanitize(str?: string) {
return (str ?? "_").replace(/[^a-zA-Z0-9_]/g, "_").toLocaleUpperCase(); return (str ?? "_").replace(/[^a-zA-Z0-9_]/g, "_").toLocaleUpperCase();
} }
export function pruneInvalidResults(
sarif: SarifFile,
logger: Logger
): SarifFile {
let pruned = 0;
const newRuns: SarifRun[] = [];
for (const run of sarif.runs || []) {
if (
run.tool?.driver?.name === "CodeQL" &&
run.tool?.driver?.semanticVersion === "2.11.2"
) {
// Version 2.11.2 of the CodeQL CLI had many false positives in the
// rb/weak-cryptographic-algorithm query which we prune here. The
// issue is tracked in https://github.com/github/codeql/issues/11107.
const newResults: SarifResult[] = [];
for (const result of run.results || []) {
if (
result.ruleId === "rb/weak-cryptographic-algorithm" &&
(result.message?.text?.includes(" MD5 ") ||
result.message?.text?.includes(" SHA1 "))
) {
pruned += 1;
continue;
}
newResults.push(result);
}
newRuns.push({ ...run, results: newResults });
} else {
newRuns.push(run);
}
}
if (pruned > 0) {
logger.info(
`Pruned ${pruned} results believed to be invalid from SARIF file.`
);
}
return { ...sarif, runs: newRuns };
}
+18 -11
View File
@@ -52,21 +52,28 @@ export const DID_AUTOBUILD_GO_ENV_VAR_NAME =
export interface SarifFile { export interface SarifFile {
version?: string | null; version?: string | null;
runs: Array<{ runs: SarifRun[];
tool?: { }
driver?: {
name?: string; export interface SarifRun {
}; tool?: {
driver?: {
name?: string;
semanticVersion?: string;
}; };
automationDetails?: { };
id?: string; automationDetails?: {
}; id?: string;
artifacts?: string[]; };
results?: SarifResult[]; artifacts?: string[];
}>; results?: SarifResult[];
} }
export interface SarifResult { export interface SarifResult {
ruleId?: string;
message?: {
text?: string;
};
locations: Array<{ locations: Array<{
physicalLocation: { physicalLocation: {
artifactLocation: { artifactLocation: {