mirror of
https://github.com/github/codeql-action.git
synced 2026-08-06 13:13:45 -05:00
Compare commits
441 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 25599b3fc8 | |||
| 639dddc728 | |||
| 0b27c71731 | |||
| 6679b049d5 | |||
| 13e47f85a5 | |||
| 5f152be4c2 | |||
| f4b6bd982f | |||
| d1a65275e8 | |||
| 0ccdcb8c0a | |||
| 05a48207b3 | |||
| 0d579ffd05 | |||
| d4c6be7cf1 | |||
| 72d2d850d1 | |||
| 23f983ce00 | |||
| 832e97ccad | |||
| 5ef38c0b13 | |||
| 80c9cda739 | |||
| f2669dd916 | |||
| bd03c44cf4 | |||
| 102d7627b6 | |||
| 0c0c5dc2f1 | |||
| e96635d9ff | |||
| 77f9a86c60 | |||
| e681b9fb11 | |||
| bc4b00aadc | |||
| 05b6a6cfaa | |||
| b1b5550715 | |||
| 31d26f2397 | |||
| 4d433615e7 | |||
| 545356f200 | |||
| 6d1c37ed8f | |||
| 759b5db350 | |||
| 60a0e2bf96 | |||
| 7449e3294d | |||
| 4cd47adfe1 | |||
| 5fa8dad095 | |||
| 6a77217a46 | |||
| b6dfacb528 | |||
| 6123416ead | |||
| a6594f96a3 | |||
| be20394012 | |||
| d1c255c293 | |||
| b371ccd8ea | |||
| 71d7981285 | |||
| e9e9733cb5 | |||
| 8e17ec94b4 | |||
| aae94187c1 | |||
| 36148cccb9 | |||
| a5b959e10d | |||
| d1ac77f26d | |||
| 675af55c60 | |||
| 281b265245 | |||
| 335f08ccc6 | |||
| 4593dc2f8f | |||
| d4f1b14259 | |||
| 8a884bdb36 | |||
| 129d771399 | |||
| 776fd85f8c | |||
| f654d61146 | |||
| eddf33655d | |||
| 9f77ff18bb | |||
| 0158d05946 | |||
| a05f541a6e | |||
| 40f0fa95c4 | |||
| 9bf973324f | |||
| 1175fd9b5d | |||
| 1faad73c9a | |||
| 6b246e4709 | |||
| 0a5b95cdcc | |||
| 77fc89c78d | |||
| bf9bf1c027 | |||
| 24fa947692 | |||
| aaed7b75f9 | |||
| 2a2f4c30a1 | |||
| 6d060bbaa1 | |||
| 28b449d8c7 | |||
| 1721ce7afd | |||
| ff2daa0aba | |||
| b43d146e37 | |||
| 66e08d2b3f | |||
| 9a31859f78 | |||
| ae9cb02459 | |||
| c0b22b827b | |||
| d09af9d5b8 | |||
| e7ec96cee0 | |||
| 41d5a06bfd | |||
| 4ca06280ba | |||
| b895512248 | |||
| 6059d3ceb5 | |||
| bab3951531 | |||
| 93ec0f487d | |||
| c793b717bc | |||
| 06cd615ad8 | |||
| f5516c6630 | |||
| 97519e197e | |||
| a6892dcba5 | |||
| 8eb0202e9d | |||
| dd779fa7d3 | |||
| f05cfae018 | |||
| e1b83ccb74 | |||
| 6a6bd778b6 | |||
| f0f92a1dc8 | |||
| e931a2475a | |||
| 8bfaf96434 | |||
| 8a1cd7656d | |||
| 3b16d31abc | |||
| 40aec383a1 | |||
| 2fce45b8e6 | |||
| d7cfd19fb8 | |||
| 68d73442fa | |||
| f91cab1409 | |||
| 5876a93a5f | |||
| 0ea8490473 | |||
| a85af80f34 | |||
| 47671ab7aa | |||
| 96e6b655c1 | |||
| 57c7bc6885 | |||
| d52917b510 | |||
| b948e562f4 | |||
| c889588a2c | |||
| b77ebbe4d8 | |||
| 9a0fe9e006 | |||
| dd78add36d | |||
| e62a268a73 | |||
| 63b4776d64 | |||
| 6932b1cda2 | |||
| 40aefb0faf | |||
| efe64e03d9 | |||
| 898d46e783 | |||
| 04c1e601ab | |||
| 2f77cd04d4 | |||
| c7e378f003 | |||
| 0ec47d036c | |||
| 59245fd159 | |||
| 05259a1d08 | |||
| 389c8322d5 | |||
| 01ee2f785a | |||
| c72d9a4933 | |||
| ca42bf226a | |||
| 6704d80ac6 | |||
| 76348c0f12 | |||
| 3a42a998ef | |||
| 8ab0431fc3 | |||
| 2c92579346 | |||
| 2475286230 | |||
| 236fbf7645 | |||
| 29181f28d5 | |||
| a0735d7c2a | |||
| b35e0349aa | |||
| 4406eba03e | |||
| 1b897f3911 | |||
| adf58cf166 | |||
| b7d3fb98df | |||
| 4e8e79431d | |||
| 52c2a032f3 | |||
| ba1288cb3c | |||
| 29765a3c71 | |||
| 068e80c14c | |||
| 154969e08b | |||
| b0ed4dedcb | |||
| 3c83f578ed | |||
| 20f148b36e | |||
| 4068616de4 | |||
| 0d5f70631a | |||
| ae14a1f513 | |||
| a577f702b9 | |||
| bce0deb953 | |||
| db33d20bf4 | |||
| 3c911485ed | |||
| 1ec5b701fc | |||
| 9bdf640d99 | |||
| b2beb85441 | |||
| f657c4e1eb | |||
| f379c46d49 | |||
| 8105503f1a | |||
| 056b0912cf | |||
| 445a2a9bb2 | |||
| 182427800c | |||
| c0fc915677 | |||
| 18898a6dd3 | |||
| 70db156dcb | |||
| 9c61a2ddf4 | |||
| 123b3011fa | |||
| 0aafb58a10 | |||
| 16adc4e672 | |||
| 2808ca726e | |||
| 2a607fea25 | |||
| ed39a1ea5c | |||
| 7ea93ee2e1 | |||
| e51b6a9a52 | |||
| 160d27baf0 | |||
| 28737ec792 | |||
| e5f9d3b55e | |||
| dc00a6f08f | |||
| ab56c02e0c | |||
| 83c236af2b | |||
| 25bde03dfb | |||
| c4dca28336 | |||
| 1aad2787ec | |||
| b6cf67a711 | |||
| f59338d600 | |||
| 2a07b6e3c7 | |||
| fba33f686a | |||
| 48094d2b6e | |||
| cb4e075f11 | |||
| 1847416575 | |||
| 11dd746d70 | |||
| a754a57c21 | |||
| 466da5ec2d | |||
| 0a9b98b511 | |||
| bce7dc4616 | |||
| b13ab62bc0 | |||
| 4ea06e96f5 | |||
| c9223eb0a0 | |||
| f0767c48a1 | |||
| 4e71011f44 | |||
| 710e294578 | |||
| b948539dd4 | |||
| c54531587d | |||
| 559d85d1fa | |||
| 8e010557a9 | |||
| 37d6d1ca27 | |||
| 68b53dc641 | |||
| 89a39a4e59 | |||
| e5d84c885c | |||
| 0c202097b5 | |||
| 314172e5a1 | |||
| cdda72d36b | |||
| cfda84cc55 | |||
| 39ba80c475 | |||
| 00150dad95 | |||
| d97dce6561 | |||
| 50fdbb9ec8 | |||
| f7905e8415 | |||
| 4191f52110 | |||
| 79a913656c | |||
| 167b47e60c | |||
| 5e7a52feb2 | |||
| 76cf404c99 | |||
| 7407d38386 | |||
| 015d8c7cbc | |||
| 09bd46dda5 | |||
| b927a69f96 | |||
| 61f7dd3d0d | |||
| 64300e453b | |||
| 906dd890a5 | |||
| 898ae16413 | |||
| fa56ea8dc0 | |||
| 657f337cd1 | |||
| 05d4e25296 | |||
| 5c583bbb19 | |||
| 554b93127b | |||
| 3dd1275368 | |||
| d24014a749 | |||
| cc0dce044b | |||
| ef58c00dfe | |||
| 7b7a951e08 | |||
| 0c47ae1c18 | |||
| 6c405c2562 | |||
| 827bba691f | |||
| 96961e0ee3 | |||
| ebad062f08 | |||
| e275d63e1d | |||
| 69c2819972 | |||
| d28d9967fe | |||
| d1bdc0ea05 | |||
| b1b1e44da9 | |||
| 46473e05b7 | |||
| 32ab108bfd | |||
| 971592501c | |||
| 2abec3f0c3 | |||
| 6d55dfff02 | |||
| 5c96b6e3db | |||
| 44a4bea367 | |||
| 11c6c18818 | |||
| 99fcc7b2a1 | |||
| c1d6ee5477 | |||
| ef9cfd91a8 | |||
| 4250b466b2 | |||
| a3d7d36aa6 | |||
| 33e2dff082 | |||
| bff89dcba4 | |||
| d6ea6709b9 | |||
| f315d82bd7 | |||
| ebce69a4b7 | |||
| ab2580041c | |||
| d1689c9307 | |||
| 147d1495e4 | |||
| 3e37216660 | |||
| ad5a6c0147 | |||
| aee29a19d7 | |||
| ac74c2835a | |||
| f8c75d3f32 | |||
| e315c6fd3b | |||
| e6a312a771 | |||
| 73f5a29960 | |||
| 8b734d3bc2 | |||
| e21e4ca93f | |||
| 595ce2dc3e | |||
| a61e3cb9f2 | |||
| d5f0374a1f | |||
| 466a4f00eb | |||
| 817d568ca0 | |||
| 34d43db4c6 | |||
| db834c9e1d | |||
| 7af50a43c1 | |||
| 60dee3dbd3 | |||
| 0874cf9f8b | |||
| bc76ceafaf | |||
| 377300bcda | |||
| ee8360df59 | |||
| 9dcfdf2c9c | |||
| 2c9bc45d46 | |||
| 368f322a09 | |||
| 5283c3ba5a | |||
| ea1a400e13 | |||
| 248d7971c2 | |||
| 64940fad4a | |||
| ef618feace | |||
| 6bddc7956d | |||
| 01fcdceb89 | |||
| 9e907b5e64 | |||
| 1814c9fbfd | |||
| 4bf6fa4e2d | |||
| 9658e23e5b | |||
| e1933c66bd | |||
| edf36092cf | |||
| 15a3d32df0 | |||
| 9835994414 | |||
| 0ce6420f8e | |||
| be75dd92ea | |||
| 05bca54402 | |||
| 2d6b98c7cf | |||
| 876cecb383 | |||
| 43b46a19be | |||
| 8ad4b6ec58 | |||
| 4edc7d2e82 | |||
| 2adcb6464e | |||
| da67096c6f | |||
| c48cd247df | |||
| 0cfcceb4b8 | |||
| cbb92e7ff6 | |||
| db9346285d | |||
| 2de76b6faa | |||
| 6a17f4e258 | |||
| 8cc4d2539b | |||
| 406bbfcef1 | |||
| 5132eb53f2 | |||
| 5b3261bcbf | |||
| 9267d8d51e | |||
| bc1164e014 | |||
| 7801eda177 | |||
| b1d963ed8f | |||
| d636fb3f63 | |||
| d155ebf27f | |||
| e8f0116911 | |||
| 713a293090 | |||
| ff33514494 | |||
| efb92e2714 | |||
| d73644591f | |||
| 41d2cc39b6 | |||
| be578c7735 | |||
| fa6e24cf12 | |||
| 2b5b614c85 | |||
| 555ee17b0b | |||
| e114998dda | |||
| bd36637537 | |||
| 4d0bec12bf | |||
| 0387f55b70 | |||
| 27b3b6586d | |||
| c4b0f60beb | |||
| 51357000d2 | |||
| 4d44b570d2 | |||
| 700fc11b44 | |||
| 9f2f6d0d2e | |||
| 01ee641f14 | |||
| c7eff3f0b1 | |||
| c4717c9c74 | |||
| b030333651 | |||
| 70eae154c6 | |||
| 93302bc63a | |||
| 310177a1fb | |||
| b13d724d35 | |||
| 4b8e16f54f | |||
| 481be99883 | |||
| 9b3a0d2c26 | |||
| d2901f5537 | |||
| 46c411a7f4 | |||
| 5a82333186 | |||
| 45cbd0c69e | |||
| cb528be87e | |||
| 7aee932974 | |||
| b5f028a984 | |||
| 9702c27ab9 | |||
| c36c94846f | |||
| 3d0331896c | |||
| 77591e2c4a | |||
| 7a44a9db3f | |||
| e2ac371513 | |||
| 7deb0a15d3 | |||
| 4f6ea84c21 | |||
| 73dbc8364d | |||
| f959778b39 | |||
| d38ad56358 | |||
| bc9796e2e0 | |||
| ab5b0e3aab | |||
| 57a47f44df | |||
| 076d055bee | |||
| 6d4cd5d744 | |||
| 42fb267c1c | |||
| 832a783bd4 | |||
| 160e695297 | |||
| 8aac4e47ac | |||
| e8d7df4f04 | |||
| c1bba77db0 | |||
| 6bc82e05fd | |||
| 42f00f2d33 | |||
| cedee6de9f | |||
| f52cbc8309 | |||
| c5aaca4bb9 | |||
| 3e58739c65 | |||
| a6ccefb47c | |||
| 0e64858573 | |||
| beb9f533db | |||
| a1c70789a3 | |||
| d94d88d717 | |||
| a6d296a341 | |||
| 28f6d316c0 | |||
| 1d0f911837 | |||
| 05bd050f34 | |||
| 325a3a2ae3 | |||
| 6394750070 | |||
| f1588cde0c | |||
| f985be5b50 | |||
| 4dcc8a9cdc | |||
| fbe3ae9de8 | |||
| 2a384c1c14 | |||
| 0c8e06dfb2 | |||
| b2ff80ddac | |||
| 48f3548141 | |||
| 800dfbe5e1 |
@@ -23,13 +23,13 @@ For internal use only. Please select the risk level of this change:
|
|||||||
Workflow types:
|
Workflow types:
|
||||||
|
|
||||||
- **Advanced setup** - Impacts users who have custom CodeQL workflows.
|
- **Advanced setup** - Impacts users who have custom CodeQL workflows.
|
||||||
- **Managed** - Impacts users with `dynamic` workflows (Default Setup, CCR, ...).
|
- **Managed** - Impacts users with `dynamic` workflows (Default Setup, Code Quality, ...).
|
||||||
|
|
||||||
Products:
|
Products:
|
||||||
|
|
||||||
- **Code Scanning** - The changes impact analyses when `analysis-kinds: code-scanning`.
|
- **Code Scanning** - The changes impact analyses when `analysis-kinds: code-scanning`.
|
||||||
- **Code Quality** - The changes impact analyses when `analysis-kinds: code-quality`.
|
- **Code Quality** - The changes impact analyses when `analysis-kinds: code-quality`.
|
||||||
- **CCR** - The changes impact analyses for Copilot Code Reviews.
|
- **Other first-party** - The changes impact other first-party analyses.
|
||||||
- **Third-party analyses** - The changes affect the `upload-sarif` action.
|
- **Third-party analyses** - The changes affect the `upload-sarif` action.
|
||||||
|
|
||||||
Environments:
|
Environments:
|
||||||
@@ -54,6 +54,7 @@ Environments:
|
|||||||
|
|
||||||
- **Feature flags** - All new or changed code paths can be fully disabled with corresponding feature flags.
|
- **Feature flags** - All new or changed code paths can be fully disabled with corresponding feature flags.
|
||||||
- **Rollback** - Change can only be disabled by rolling back the release or releasing a new version with a fix.
|
- **Rollback** - Change can only be disabled by rolling back the release or releasing a new version with a fix.
|
||||||
|
- **Development/testing only** - This change cannot cause any failures in production.
|
||||||
- **Other** - Please provide details.
|
- **Other** - Please provide details.
|
||||||
|
|
||||||
#### How will you know if something goes wrong after this change is released?
|
#### How will you know if something goes wrong after this change is released?
|
||||||
|
|||||||
@@ -71,8 +71,9 @@ def open_pr(
|
|||||||
body.append('')
|
body.append('')
|
||||||
body.append('Contains the following pull requests:')
|
body.append('Contains the following pull requests:')
|
||||||
for pr in pull_requests:
|
for pr in pull_requests:
|
||||||
merger = get_merger_of_pr(repo, pr)
|
# Use PR author if they are GitHub staff, otherwise use the merger
|
||||||
body.append(f'- #{pr.number} (@{merger})')
|
display_user = get_pr_author_if_staff(pr) or get_merger_of_pr(repo, pr)
|
||||||
|
body.append(f'- #{pr.number} (@{display_user})')
|
||||||
|
|
||||||
# List all commits not part of a PR
|
# List all commits not part of a PR
|
||||||
if len(commits_without_pull_requests) > 0:
|
if len(commits_without_pull_requests) > 0:
|
||||||
@@ -168,6 +169,14 @@ def get_pr_for_commit(commit):
|
|||||||
def get_merger_of_pr(repo, pr):
|
def get_merger_of_pr(repo, pr):
|
||||||
return repo.get_commit(pr.merge_commit_sha).author.login
|
return repo.get_commit(pr.merge_commit_sha).author.login
|
||||||
|
|
||||||
|
# Get the PR author if they are GitHub staff, otherwise None.
|
||||||
|
def get_pr_author_if_staff(pr):
|
||||||
|
if pr.user is None:
|
||||||
|
return None
|
||||||
|
if getattr(pr.user, 'site_admin', False):
|
||||||
|
return pr.user.login
|
||||||
|
return None
|
||||||
|
|
||||||
def get_current_version():
|
def get_current_version():
|
||||||
with open('package.json', 'r') as f:
|
with open('package.json', 'r') as f:
|
||||||
return json.load(f)['version']
|
return json.load(f)['version']
|
||||||
@@ -181,9 +190,9 @@ def replace_version_package_json(prev_version, new_version):
|
|||||||
print(line.replace(prev_version, new_version), end='')
|
print(line.replace(prev_version, new_version), end='')
|
||||||
else:
|
else:
|
||||||
prev_line_is_codeql = False
|
prev_line_is_codeql = False
|
||||||
print(line, end='')
|
print(line, end='')
|
||||||
if '\"name\": \"codeql\",' in line:
|
if '\"name\": \"codeql\",' in line:
|
||||||
prev_line_is_codeql = True
|
prev_line_is_codeql = True
|
||||||
|
|
||||||
def get_today_string():
|
def get_today_string():
|
||||||
today = datetime.datetime.today()
|
today = datetime.datetime.today()
|
||||||
|
|||||||
+5
-3
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -49,8 +52,7 @@ defaults:
|
|||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: all-platform-bundle-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
||||||
all-platform-bundle-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
all-platform-bundle:
|
all-platform-bundle:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -92,7 +94,7 @@ jobs:
|
|||||||
- id: init
|
- id: init
|
||||||
uses: ./../action/init
|
uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
# Swift is not supported on Ubuntu so we manually exclude it from the list here
|
# Swift is not supported on Ubuntu so we manually exclude it from the list here
|
||||||
languages: cpp,csharp,go,java,javascript,python,ruby
|
languages: cpp,csharp,go,java,javascript,python,ruby
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
- name: Build code
|
- name: Build code
|
||||||
|
|||||||
+28
-24
@@ -3,7 +3,7 @@
|
|||||||
# pr-checks/sync.sh
|
# pr-checks/sync.sh
|
||||||
# to regenerate this file.
|
# to regenerate this file.
|
||||||
|
|
||||||
name: PR Check - Quality queries input
|
name: PR Check - Analysis kinds
|
||||||
env:
|
env:
|
||||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||||
GO111MODULE: auto
|
GO111MODULE: auto
|
||||||
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -29,9 +32,9 @@ defaults:
|
|||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: quality-queries-${{github.ref}}
|
group: analysis-kinds-${{github.ref}}
|
||||||
jobs:
|
jobs:
|
||||||
quality-queries:
|
analysis-kinds:
|
||||||
strategy:
|
strategy:
|
||||||
fail-fast: false
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
@@ -45,6 +48,9 @@ jobs:
|
|||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: linked
|
version: linked
|
||||||
analysis-kinds: code-scanning,code-quality
|
analysis-kinds: code-scanning,code-quality
|
||||||
|
- os: ubuntu-latest
|
||||||
|
version: linked
|
||||||
|
analysis-kinds: risk-assessment
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: nightly-latest
|
version: nightly-latest
|
||||||
analysis-kinds: code-scanning
|
analysis-kinds: code-scanning
|
||||||
@@ -54,7 +60,10 @@ jobs:
|
|||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: nightly-latest
|
version: nightly-latest
|
||||||
analysis-kinds: code-scanning,code-quality
|
analysis-kinds: code-scanning,code-quality
|
||||||
name: Quality queries input
|
- os: ubuntu-latest
|
||||||
|
version: nightly-latest
|
||||||
|
analysis-kinds: risk-assessment
|
||||||
|
name: Analysis kinds
|
||||||
if: github.triggering_actor != 'dependabot[bot]'
|
if: github.triggering_actor != 'dependabot[bot]'
|
||||||
permissions:
|
permissions:
|
||||||
contents: read
|
contents: read
|
||||||
@@ -78,38 +87,32 @@ jobs:
|
|||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
output: ${{ runner.temp }}/results
|
output: '${{ runner.temp }}/results'
|
||||||
upload-database: false
|
upload-database: false
|
||||||
post-processed-sarif-path: ${{ runner.temp }}/post-processed
|
post-processed-sarif-path: '${{ runner.temp }}/post-processed'
|
||||||
- name: Upload security SARIF
|
|
||||||
if: contains(matrix.analysis-kinds, 'code-scanning')
|
- name: Upload SARIF files
|
||||||
uses: actions/upload-artifact@v6
|
uses: actions/upload-artifact@v7
|
||||||
with:
|
with:
|
||||||
name: |
|
name: |
|
||||||
quality-queries-${{ matrix.os }}-${{ matrix.version }}-${{ matrix.analysis-kinds }}.sarif.json
|
analysis-kinds-${{ matrix.os }}-${{ matrix.version }}-${{ matrix.analysis-kinds }}
|
||||||
path: ${{ runner.temp }}/results/javascript.sarif
|
path: '${{ runner.temp }}/results/*.sarif'
|
||||||
retention-days: 7
|
|
||||||
- name: Upload quality SARIF
|
|
||||||
if: contains(matrix.analysis-kinds, 'code-quality')
|
|
||||||
uses: actions/upload-artifact@v6
|
|
||||||
with:
|
|
||||||
name: |
|
|
||||||
quality-queries-${{ matrix.os }}-${{ matrix.version }}-${{ matrix.analysis-kinds }}.quality.sarif.json
|
|
||||||
path: ${{ runner.temp }}/results/javascript.quality.sarif
|
|
||||||
retention-days: 7
|
retention-days: 7
|
||||||
|
|
||||||
- name: Upload post-processed SARIF
|
- name: Upload post-processed SARIF
|
||||||
uses: actions/upload-artifact@v6
|
uses: actions/upload-artifact@v7
|
||||||
with:
|
with:
|
||||||
name: |
|
name: |
|
||||||
post-processed-${{ matrix.os }}-${{ matrix.version }}-${{ matrix.analysis-kinds }}.sarif.json
|
post-processed-${{ matrix.os }}-${{ matrix.version }}-${{ matrix.analysis-kinds }}
|
||||||
path: ${{ runner.temp }}/post-processed
|
path: '${{ runner.temp }}/post-processed'
|
||||||
retention-days: 7
|
retention-days: 7
|
||||||
if-no-files-found: error
|
if-no-files-found: error
|
||||||
|
|
||||||
- name: Check quality query does not appear in security SARIF
|
- name: Check quality query does not appear in security SARIF
|
||||||
if: contains(matrix.analysis-kinds, 'code-scanning')
|
if: contains(matrix.analysis-kinds, 'code-scanning')
|
||||||
uses: actions/github-script@v8
|
uses: actions/github-script@v8
|
||||||
env:
|
env:
|
||||||
SARIF_PATH: ${{ runner.temp }}/results/javascript.sarif
|
SARIF_PATH: '${{ runner.temp }}/results/javascript.sarif'
|
||||||
EXPECT_PRESENT: 'false'
|
EXPECT_PRESENT: 'false'
|
||||||
with:
|
with:
|
||||||
script: ${{ env.CHECK_SCRIPT }}
|
script: ${{ env.CHECK_SCRIPT }}
|
||||||
@@ -117,11 +120,12 @@ jobs:
|
|||||||
if: contains(matrix.analysis-kinds, 'code-quality')
|
if: contains(matrix.analysis-kinds, 'code-quality')
|
||||||
uses: actions/github-script@v8
|
uses: actions/github-script@v8
|
||||||
env:
|
env:
|
||||||
SARIF_PATH: ${{ runner.temp }}/results/javascript.quality.sarif
|
SARIF_PATH: '${{ runner.temp }}/results/javascript.quality.sarif'
|
||||||
EXPECT_PRESENT: 'true'
|
EXPECT_PRESENT: 'true'
|
||||||
with:
|
with:
|
||||||
script: ${{ env.CHECK_SCRIPT }}
|
script: ${{ env.CHECK_SCRIPT }}
|
||||||
env:
|
env:
|
||||||
|
CODEQL_ACTION_RISK_ASSESSMENT_ID: 1
|
||||||
CHECK_SCRIPT: |
|
CHECK_SCRIPT: |
|
||||||
const fs = require('fs');
|
const fs = require('fs');
|
||||||
|
|
||||||
+7
-6
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -59,8 +62,7 @@ defaults:
|
|||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: analyze-ref-input-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
||||||
analyze-ref-input-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
analyze-ref-input:
|
analyze-ref-input:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -104,13 +106,12 @@ jobs:
|
|||||||
with:
|
with:
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
languages: cpp,csharp,java,javascript,python
|
languages: cpp,csharp,java,javascript,python
|
||||||
config-file: ${{ github.repository }}/tests/multi-language-repo/.github/codeql/custom-queries.yml@${{
|
config-file: ${{ github.repository }}/tests/multi-language-repo/.github/codeql/custom-queries.yml@${{ github.sha }}
|
||||||
github.sha }}
|
|
||||||
- name: Build code
|
- name: Build code
|
||||||
run: ./build.sh
|
run: ./build.sh
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
ref: refs/heads/main
|
ref: 'refs/heads/main'
|
||||||
sha: 5e235361806c361d4d3f8859e3c897658025a9a2
|
sha: '5e235361806c361d4d3f8859e3c897658025a9a2'
|
||||||
env:
|
env:
|
||||||
CODEQL_ACTION_TEST_MODE: true
|
CODEQL_ACTION_TEST_MODE: true
|
||||||
|
|||||||
Generated
+4
-1
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -79,7 +82,7 @@ jobs:
|
|||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
- uses: ./../action/autobuild
|
- uses: ./../action/autobuild
|
||||||
env:
|
env:
|
||||||
# Explicitly disable the CLR tracer.
|
# Explicitly disable the CLR tracer.
|
||||||
COR_ENABLE_PROFILING: ''
|
COR_ENABLE_PROFILING: ''
|
||||||
COR_PROFILER: ''
|
COR_PROFILER: ''
|
||||||
COR_PROFILER_PATH_64: ''
|
COR_PROFILER_PATH_64: ''
|
||||||
|
|||||||
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -39,8 +42,7 @@ defaults:
|
|||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: autobuild-direct-tracing-with-working-dir-${{github.ref}}-${{inputs.java-version}}
|
||||||
autobuild-direct-tracing-with-working-dir-${{github.ref}}-${{inputs.java-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
autobuild-direct-tracing-with-working-dir:
|
autobuild-direct-tracing-with-working-dir:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+3
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|||||||
+4
-1
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -94,7 +97,7 @@ jobs:
|
|||||||
id: init
|
id: init
|
||||||
with:
|
with:
|
||||||
build-mode: autobuild
|
build-mode: autobuild
|
||||||
db-location: ${{ runner.temp }}/customDbLocation
|
db-location: '${{ runner.temp }}/customDbLocation'
|
||||||
languages: java
|
languages: java
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
|
|
||||||
|
|||||||
+5
-3
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -49,8 +52,7 @@ defaults:
|
|||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: build-mode-manual-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
||||||
build-mode-manual-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
build-mode-manual:
|
build-mode-manual:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -89,7 +91,7 @@ jobs:
|
|||||||
id: init
|
id: init
|
||||||
with:
|
with:
|
||||||
build-mode: manual
|
build-mode: manual
|
||||||
db-location: ${{ runner.temp }}/customDbLocation
|
db-location: '${{ runner.temp }}/customDbLocation'
|
||||||
languages: java
|
languages: java
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
|
|
||||||
|
|||||||
Generated
+5
-2
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -61,7 +64,7 @@ jobs:
|
|||||||
id: init
|
id: init
|
||||||
with:
|
with:
|
||||||
build-mode: none
|
build-mode: none
|
||||||
db-location: ${{ runner.temp }}/customDbLocation
|
db-location: '${{ runner.temp }}/customDbLocation'
|
||||||
languages: java
|
languages: java
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
|
|
||||||
@@ -74,7 +77,7 @@ jobs:
|
|||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# The latest nightly supports omitting the autobuild Action when the build mode is specified.
|
# The latest nightly supports omitting the autobuild Action when the build mode is specified.
|
||||||
- uses: ./../action/autobuild
|
- uses: ./../action/autobuild
|
||||||
if: matrix.version != 'nightly-latest'
|
if: matrix.version != 'nightly-latest'
|
||||||
|
|
||||||
|
|||||||
+4
-1
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -65,7 +68,7 @@ jobs:
|
|||||||
id: init
|
id: init
|
||||||
with:
|
with:
|
||||||
build-mode: none
|
build-mode: none
|
||||||
db-location: ${{ runner.temp }}/customDbLocation
|
db-location: '${{ runner.temp }}/customDbLocation'
|
||||||
languages: java
|
languages: java
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
|
|
||||||
|
|||||||
+15
-30
@@ -3,7 +3,7 @@
|
|||||||
# pr-checks/sync.sh
|
# pr-checks/sync.sh
|
||||||
# to regenerate this file.
|
# to regenerate this file.
|
||||||
|
|
||||||
name: PR Check - CCR
|
name: 'PR Check - Bundle: From nightly'
|
||||||
env:
|
env:
|
||||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||||
GO111MODULE: auto
|
GO111MODULE: auto
|
||||||
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -29,32 +32,16 @@ defaults:
|
|||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ccr-${{github.ref}}
|
group: bundle-from-nightly-${{github.ref}}
|
||||||
jobs:
|
jobs:
|
||||||
ccr:
|
bundle-from-nightly:
|
||||||
strategy:
|
strategy:
|
||||||
fail-fast: false
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
include:
|
include:
|
||||||
- os: ubuntu-latest
|
|
||||||
version: stable-v2.17.6
|
|
||||||
- os: ubuntu-latest
|
|
||||||
version: stable-v2.18.4
|
|
||||||
- os: ubuntu-latest
|
|
||||||
version: stable-v2.19.4
|
|
||||||
- os: ubuntu-latest
|
|
||||||
version: stable-v2.20.7
|
|
||||||
- os: ubuntu-latest
|
|
||||||
version: stable-v2.21.4
|
|
||||||
- os: ubuntu-latest
|
|
||||||
version: stable-v2.22.4
|
|
||||||
- os: ubuntu-latest
|
|
||||||
version: default
|
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: linked
|
version: linked
|
||||||
- os: ubuntu-latest
|
name: 'Bundle: From nightly'
|
||||||
version: nightly-latest
|
|
||||||
name: CCR
|
|
||||||
if: github.triggering_actor != 'dependabot[bot]'
|
if: github.triggering_actor != 'dependabot[bot]'
|
||||||
permissions:
|
permissions:
|
||||||
contents: read
|
contents: read
|
||||||
@@ -71,17 +58,15 @@ jobs:
|
|||||||
version: ${{ matrix.version }}
|
version: ${{ matrix.version }}
|
||||||
use-all-platform-bundle: 'false'
|
use-all-platform-bundle: 'false'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- uses: ./../action/init
|
- id: init
|
||||||
id: init
|
uses: ./../action/init
|
||||||
|
env:
|
||||||
|
CODEQL_ACTION_FORCE_NIGHTLY: true
|
||||||
with:
|
with:
|
||||||
languages: javascript
|
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
|
languages: javascript
|
||||||
- uses: ./../action/analyze
|
- name: Fail if the CodeQL version is not a nightly
|
||||||
id: analysis
|
if: ${{ !contains(steps.init.outputs.codeql-version, '+') }}
|
||||||
with:
|
run: exit 1
|
||||||
upload-database: false
|
|
||||||
|
|
||||||
env:
|
env:
|
||||||
CODEQL_ACTION_ANALYSIS_KEY: dynamic/copilot-pull-request-reviewer/codeql-action-test
|
|
||||||
CODEQL_ACTION_TEST_MODE: true
|
CODEQL_ACTION_TEST_MODE: true
|
||||||
+4
-1
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -56,7 +59,7 @@ jobs:
|
|||||||
use-all-platform-bundle: 'false'
|
use-all-platform-bundle: 'false'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- name: Install @actions/tool-cache
|
- name: Install @actions/tool-cache
|
||||||
run: npm install @actions/tool-cache
|
run: npm install @actions/tool-cache@3
|
||||||
- name: Check toolcache contains CodeQL
|
- name: Check toolcache contains CodeQL
|
||||||
continue-on-error: true
|
continue-on-error: true
|
||||||
uses: actions/github-script@v8
|
uses: actions/github-script@v8
|
||||||
|
|||||||
Generated
+4
-1
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -68,7 +71,7 @@ jobs:
|
|||||||
const codeqlPath = path.join(process.env['RUNNER_TOOL_CACHE'], 'CodeQL');
|
const codeqlPath = path.join(process.env['RUNNER_TOOL_CACHE'], 'CodeQL');
|
||||||
fs.rmdirSync(codeqlPath, { recursive: true });
|
fs.rmdirSync(codeqlPath, { recursive: true });
|
||||||
- name: Install @actions/tool-cache
|
- name: Install @actions/tool-cache
|
||||||
run: npm install @actions/tool-cache
|
run: npm install @actions/tool-cache@3
|
||||||
- name: Check toolcache does not contain CodeQL
|
- name: Check toolcache does not contain CodeQL
|
||||||
uses: actions/github-script@v8
|
uses: actions/github-script@v8
|
||||||
with:
|
with:
|
||||||
|
|||||||
Generated
+4
-1
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -79,7 +82,7 @@ jobs:
|
|||||||
output: ${{ runner.temp }}/results
|
output: ${{ runner.temp }}/results
|
||||||
upload-database: false
|
upload-database: false
|
||||||
- name: Upload SARIF
|
- name: Upload SARIF
|
||||||
uses: actions/upload-artifact@v6
|
uses: actions/upload-artifact@v7
|
||||||
with:
|
with:
|
||||||
name: ${{ matrix.os }}-zstd-bundle.sarif
|
name: ${{ matrix.os }}-zstd-bundle.sarif
|
||||||
path: ${{ runner.temp }}/results/javascript.sarif
|
path: ${{ runner.temp }}/results/javascript.sarif
|
||||||
|
|||||||
+4
-1
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -64,7 +67,7 @@ jobs:
|
|||||||
id: init
|
id: init
|
||||||
with:
|
with:
|
||||||
build-mode: none
|
build-mode: none
|
||||||
db-location: ${{ runner.temp }}/customDbLocation
|
db-location: '${{ runner.temp }}/customDbLocation'
|
||||||
languages: javascript
|
languages: javascript
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
|
|
||||||
|
|||||||
Generated
+7
-4
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -64,18 +67,18 @@ jobs:
|
|||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
output: ${{ runner.temp }}/results
|
output: '${{ runner.temp }}/results'
|
||||||
upload-database: false
|
upload-database: false
|
||||||
- name: Upload SARIF
|
- name: Upload SARIF
|
||||||
uses: actions/upload-artifact@v6
|
uses: actions/upload-artifact@v7
|
||||||
with:
|
with:
|
||||||
name: config-export-${{ matrix.os }}-${{ matrix.version }}.sarif.json
|
name: config-export-${{ matrix.os }}-${{ matrix.version }}.sarif.json
|
||||||
path: ${{ runner.temp }}/results/javascript.sarif
|
path: '${{ runner.temp }}/results/javascript.sarif'
|
||||||
retention-days: 7
|
retention-days: 7
|
||||||
- name: Check config properties appear in SARIF
|
- name: Check config properties appear in SARIF
|
||||||
uses: actions/github-script@v8
|
uses: actions/github-script@v8
|
||||||
env:
|
env:
|
||||||
SARIF_PATH: ${{ runner.temp }}/results/javascript.sarif
|
SARIF_PATH: '${{ runner.temp }}/results/javascript.sarif'
|
||||||
with:
|
with:
|
||||||
script: |
|
script: |
|
||||||
const fs = require('fs');
|
const fs = require('fs');
|
||||||
|
|||||||
Generated
+3
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|||||||
+3
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|||||||
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|||||||
+3
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|||||||
+7
-4
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -75,18 +78,18 @@ jobs:
|
|||||||
--ready-for-status-page
|
--ready-for-status-page
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
output: ${{ runner.temp }}/results
|
output: '${{ runner.temp }}/results'
|
||||||
upload-database: false
|
upload-database: false
|
||||||
- name: Upload SARIF
|
- name: Upload SARIF
|
||||||
uses: actions/upload-artifact@v6
|
uses: actions/upload-artifact@v7
|
||||||
with:
|
with:
|
||||||
name: diagnostics-export-${{ matrix.os }}-${{ matrix.version }}.sarif.json
|
name: diagnostics-export-${{ matrix.os }}-${{ matrix.version }}.sarif.json
|
||||||
path: ${{ runner.temp }}/results/javascript.sarif
|
path: '${{ runner.temp }}/results/javascript.sarif'
|
||||||
retention-days: 7
|
retention-days: 7
|
||||||
- name: Check diagnostics appear in SARIF
|
- name: Check diagnostics appear in SARIF
|
||||||
uses: actions/github-script@v8
|
uses: actions/github-script@v8
|
||||||
env:
|
env:
|
||||||
SARIF_PATH: ${{ runner.temp }}/results/javascript.sarif
|
SARIF_PATH: '${{ runner.temp }}/results/javascript.sarif'
|
||||||
with:
|
with:
|
||||||
script: |
|
script: |
|
||||||
const fs = require('fs');
|
const fs = require('fs');
|
||||||
|
|||||||
+7
-5
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -49,8 +52,7 @@ defaults:
|
|||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: export-file-baseline-information-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
||||||
export-file-baseline-information-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
export-file-baseline-information:
|
export-file-baseline-information:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -98,12 +100,12 @@ jobs:
|
|||||||
run: ./build.sh
|
run: ./build.sh
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
output: ${{ runner.temp }}/results
|
output: '${{ runner.temp }}/results'
|
||||||
- name: Upload SARIF
|
- name: Upload SARIF
|
||||||
uses: actions/upload-artifact@v6
|
uses: actions/upload-artifact@v7
|
||||||
with:
|
with:
|
||||||
name: with-baseline-information-${{ matrix.os }}-${{ matrix.version }}.sarif.json
|
name: with-baseline-information-${{ matrix.os }}-${{ matrix.version }}.sarif.json
|
||||||
path: ${{ runner.temp }}/results/javascript.sarif
|
path: '${{ runner.temp }}/results/javascript.sarif'
|
||||||
retention-days: 7
|
retention-days: 7
|
||||||
- name: Check results
|
- name: Check results
|
||||||
run: |
|
run: |
|
||||||
|
|||||||
+3
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|||||||
Generated
+3
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|||||||
+4
-2
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -49,8 +52,7 @@ defaults:
|
|||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: go-custom-queries-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
||||||
go-custom-queries-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
go-custom-queries:
|
go-custom-queries:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -74,7 +77,7 @@ jobs:
|
|||||||
with:
|
with:
|
||||||
languages: go
|
languages: go
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
# Deliberately change Go after the `init` step
|
# Deliberately change Go after the `init` step
|
||||||
- uses: actions/setup-go@v6
|
- uses: actions/setup-go@v6
|
||||||
with:
|
with:
|
||||||
go-version: '1.20'
|
go-version: '1.20'
|
||||||
@@ -82,12 +85,12 @@ jobs:
|
|||||||
run: go build main.go
|
run: go build main.go
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
output: ${{ runner.temp }}/results
|
output: '${{ runner.temp }}/results'
|
||||||
upload-database: false
|
upload-database: false
|
||||||
- name: Check diagnostic appears in SARIF
|
- name: Check diagnostic appears in SARIF
|
||||||
uses: actions/github-script@v8
|
uses: actions/github-script@v8
|
||||||
env:
|
env:
|
||||||
SARIF_PATH: ${{ runner.temp }}/results/go.sarif
|
SARIF_PATH: '${{ runner.temp }}/results/go.sarif'
|
||||||
with:
|
with:
|
||||||
script: |
|
script: |
|
||||||
const fs = require('fs');
|
const fs = require('fs');
|
||||||
|
|||||||
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -39,8 +42,7 @@ defaults:
|
|||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: go-indirect-tracing-workaround-no-file-program-${{github.ref}}-${{inputs.go-version}}
|
||||||
go-indirect-tracing-workaround-no-file-program-${{github.ref}}-${{inputs.go-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
go-indirect-tracing-workaround-no-file-program:
|
go-indirect-tracing-workaround-no-file-program:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -84,12 +86,12 @@ jobs:
|
|||||||
run: go build main.go
|
run: go build main.go
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
output: ${{ runner.temp }}/results
|
output: '${{ runner.temp }}/results'
|
||||||
upload-database: false
|
upload-database: false
|
||||||
- name: Check diagnostic appears in SARIF
|
- name: Check diagnostic appears in SARIF
|
||||||
uses: actions/github-script@v8
|
uses: actions/github-script@v8
|
||||||
env:
|
env:
|
||||||
SARIF_PATH: ${{ runner.temp }}/results/go.sarif
|
SARIF_PATH: '${{ runner.temp }}/results/go.sarif'
|
||||||
with:
|
with:
|
||||||
script: |
|
script: |
|
||||||
const fs = require('fs');
|
const fs = require('fs');
|
||||||
|
|||||||
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|||||||
+3
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|||||||
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|||||||
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|||||||
+4
-2
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -47,7 +50,6 @@ jobs:
|
|||||||
permissions:
|
permissions:
|
||||||
contents: read
|
contents: read
|
||||||
packages: read
|
packages: read
|
||||||
|
|
||||||
timeout-minutes: 45
|
timeout-minutes: 45
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
@@ -63,7 +65,7 @@ jobs:
|
|||||||
- name: Init with registries
|
- name: Init with registries
|
||||||
uses: ./../action/init
|
uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
db-location: ${{ runner.temp }}/customDbLocation
|
db-location: '${{ runner.temp }}/customDbLocation'
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
config-file: ./.github/codeql/codeql-config-registries.yml
|
config-file: ./.github/codeql/codeql-config-registries.yml
|
||||||
languages: javascript
|
languages: javascript
|
||||||
|
|||||||
+3
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|||||||
+6
-3
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -62,12 +65,12 @@ jobs:
|
|||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
output: ${{ runner.temp }}/results
|
output: '${{ runner.temp }}/results'
|
||||||
- name: Upload SARIF
|
- name: Upload SARIF
|
||||||
uses: actions/upload-artifact@v6
|
uses: actions/upload-artifact@v7
|
||||||
with:
|
with:
|
||||||
name: ${{ matrix.os }}-${{ matrix.version }}.sarif.json
|
name: ${{ matrix.os }}-${{ matrix.version }}.sarif.json
|
||||||
path: ${{ runner.temp }}/results/javascript.sarif
|
path: '${{ runner.temp }}/results/javascript.sarif'
|
||||||
retention-days: 7
|
retention-days: 7
|
||||||
- name: Check results
|
- name: Check results
|
||||||
run: |
|
run: |
|
||||||
|
|||||||
Generated
+4
-1
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -60,7 +63,7 @@ jobs:
|
|||||||
languages: C#,java-kotlin,swift,typescript
|
languages: C#,java-kotlin,swift,typescript
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
|
|
||||||
- name: Check languages
|
- name: 'Check languages'
|
||||||
run: |
|
run: |
|
||||||
expected_languages="csharp,java,swift,javascript"
|
expected_languages="csharp,java,swift,javascript"
|
||||||
actual_languages=$(jq -r '.languages | join(",")' "$RUNNER_TEMP"/config)
|
actual_languages=$(jq -r '.languages | join(",")' "$RUNNER_TEMP"/config)
|
||||||
|
|||||||
Generated
+5
-3
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -59,8 +62,7 @@ defaults:
|
|||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: local-bundle-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
||||||
local-bundle-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
local-bundle:
|
local-bundle:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -106,7 +108,7 @@ jobs:
|
|||||||
- id: init
|
- id: init
|
||||||
uses: ./../action/init
|
uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
# Swift is not supported on Ubuntu so we manually exclude it from the list here
|
# Swift is not supported on Ubuntu so we manually exclude it from the list here
|
||||||
languages: cpp,csharp,go,java,javascript,python,ruby
|
languages: cpp,csharp,go,java,javascript,python,ruby
|
||||||
tools: ./codeql-bundle-linux64.tar.zst
|
tools: ./codeql-bundle-linux64.tar.zst
|
||||||
- name: Build code
|
- name: Build code
|
||||||
|
|||||||
+6
-5
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -59,8 +62,7 @@ defaults:
|
|||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: multi-language-autodetect-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
||||||
multi-language-autodetect-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
multi-language-autodetect:
|
multi-language-autodetect:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -141,9 +143,8 @@ jobs:
|
|||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
id: init
|
id: init
|
||||||
with:
|
with:
|
||||||
db-location: ${{ runner.temp }}/customDbLocation
|
db-location: '${{ runner.temp }}/customDbLocation'
|
||||||
languages: ${{ runner.os == 'Linux' && 'cpp,csharp,go,java,javascript,python,ruby'
|
languages: ${{ runner.os == 'Linux' && 'cpp,csharp,go,java,javascript,python,ruby' || '' }}
|
||||||
|| '' }}
|
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
|
|
||||||
- name: Build code
|
- name: Build code
|
||||||
|
|||||||
+3
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|||||||
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -59,8 +62,7 @@ defaults:
|
|||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: packaging-codescanning-config-inputs-js-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
||||||
packaging-codescanning-config-inputs-js-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
packaging-codescanning-config-inputs-js:
|
packaging-codescanning-config-inputs-js:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -113,7 +115,7 @@ jobs:
|
|||||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
config-file: .github/codeql/codeql-config-packaging3.yml
|
config-file: '.github/codeql/codeql-config-packaging3.yml'
|
||||||
packs: +codeql-testing/codeql-pack1@1.0.0
|
packs: +codeql-testing/codeql-pack1@1.0.0
|
||||||
languages: javascript
|
languages: javascript
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
@@ -121,15 +123,14 @@ jobs:
|
|||||||
run: ./build.sh
|
run: ./build.sh
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
output: ${{ runner.temp }}/results
|
output: '${{ runner.temp }}/results'
|
||||||
upload-database: false
|
upload-database: false
|
||||||
|
|
||||||
- name: Check results
|
- name: Check results
|
||||||
uses: ./../action/.github/actions/check-sarif
|
uses: ./../action/.github/actions/check-sarif
|
||||||
with:
|
with:
|
||||||
sarif-file: ${{ runner.temp }}/results/javascript.sarif
|
sarif-file: ${{ runner.temp }}/results/javascript.sarif
|
||||||
queries-run:
|
queries-run: javascript/example/empty-or-one-block,javascript/example/empty-or-one-block,javascript/example/other-query-block,javascript/example/two-block
|
||||||
javascript/example/empty-or-one-block,javascript/example/empty-or-one-block,javascript/example/other-query-block,javascript/example/two-block
|
|
||||||
queries-not-run: foo,bar
|
queries-not-run: foo,bar
|
||||||
|
|
||||||
- name: Assert Results
|
- name: Assert Results
|
||||||
|
|||||||
+7
-6
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -49,8 +52,7 @@ defaults:
|
|||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: packaging-config-inputs-js-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
||||||
packaging-config-inputs-js-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
packaging-config-inputs-js:
|
packaging-config-inputs-js:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -98,7 +100,7 @@ jobs:
|
|||||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
config-file: .github/codeql/codeql-config-packaging3.yml
|
config-file: '.github/codeql/codeql-config-packaging3.yml'
|
||||||
packs: +codeql-testing/codeql-pack1@1.0.0
|
packs: +codeql-testing/codeql-pack1@1.0.0
|
||||||
languages: javascript
|
languages: javascript
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
@@ -106,15 +108,14 @@ jobs:
|
|||||||
run: ./build.sh
|
run: ./build.sh
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
output: ${{ runner.temp }}/results
|
output: '${{ runner.temp }}/results'
|
||||||
upload-database: false
|
upload-database: false
|
||||||
|
|
||||||
- name: Check results
|
- name: Check results
|
||||||
uses: ./../action/.github/actions/check-sarif
|
uses: ./../action/.github/actions/check-sarif
|
||||||
with:
|
with:
|
||||||
sarif-file: ${{ runner.temp }}/results/javascript.sarif
|
sarif-file: ${{ runner.temp }}/results/javascript.sarif
|
||||||
queries-run:
|
queries-run: javascript/example/empty-or-one-block,javascript/example/empty-or-one-block,javascript/example/other-query-block,javascript/example/two-block
|
||||||
javascript/example/empty-or-one-block,javascript/example/empty-or-one-block,javascript/example/other-query-block,javascript/example/two-block
|
|
||||||
queries-not-run: foo,bar
|
queries-not-run: foo,bar
|
||||||
|
|
||||||
- name: Assert Results
|
- name: Assert Results
|
||||||
|
|||||||
+7
-6
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -49,8 +52,7 @@ defaults:
|
|||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: packaging-config-js-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
||||||
packaging-config-js-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
packaging-config-js:
|
packaging-config-js:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -98,22 +100,21 @@ jobs:
|
|||||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
config-file: .github/codeql/codeql-config-packaging.yml
|
config-file: '.github/codeql/codeql-config-packaging.yml'
|
||||||
languages: javascript
|
languages: javascript
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
- name: Build code
|
- name: Build code
|
||||||
run: ./build.sh
|
run: ./build.sh
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
output: ${{ runner.temp }}/results
|
output: '${{ runner.temp }}/results'
|
||||||
upload-database: false
|
upload-database: false
|
||||||
|
|
||||||
- name: Check results
|
- name: Check results
|
||||||
uses: ./../action/.github/actions/check-sarif
|
uses: ./../action/.github/actions/check-sarif
|
||||||
with:
|
with:
|
||||||
sarif-file: ${{ runner.temp }}/results/javascript.sarif
|
sarif-file: ${{ runner.temp }}/results/javascript.sarif
|
||||||
queries-run:
|
queries-run: javascript/example/empty-or-one-block,javascript/example/empty-or-one-block,javascript/example/other-query-block,javascript/example/two-block
|
||||||
javascript/example/empty-or-one-block,javascript/example/empty-or-one-block,javascript/example/other-query-block,javascript/example/two-block
|
|
||||||
queries-not-run: foo,bar
|
queries-not-run: foo,bar
|
||||||
|
|
||||||
- name: Assert Results
|
- name: Assert Results
|
||||||
|
|||||||
+7
-6
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -49,8 +52,7 @@ defaults:
|
|||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: packaging-inputs-js-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
||||||
packaging-inputs-js-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
packaging-inputs-js:
|
packaging-inputs-js:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -98,7 +100,7 @@ jobs:
|
|||||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
config-file: .github/codeql/codeql-config-packaging2.yml
|
config-file: '.github/codeql/codeql-config-packaging2.yml'
|
||||||
languages: javascript
|
languages: javascript
|
||||||
packs: codeql-testing/codeql-pack1@1.0.0, codeql-testing/codeql-pack2, codeql-testing/codeql-pack3:other-query.ql
|
packs: codeql-testing/codeql-pack1@1.0.0, codeql-testing/codeql-pack2, codeql-testing/codeql-pack3:other-query.ql
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
@@ -106,14 +108,13 @@ jobs:
|
|||||||
run: ./build.sh
|
run: ./build.sh
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
output: ${{ runner.temp }}/results
|
output: '${{ runner.temp }}/results'
|
||||||
|
|
||||||
- name: Check results
|
- name: Check results
|
||||||
uses: ./../action/.github/actions/check-sarif
|
uses: ./../action/.github/actions/check-sarif
|
||||||
with:
|
with:
|
||||||
sarif-file: ${{ runner.temp }}/results/javascript.sarif
|
sarif-file: ${{ runner.temp }}/results/javascript.sarif
|
||||||
queries-run:
|
queries-run: javascript/example/empty-or-one-block,javascript/example/empty-or-one-block,javascript/example/other-query-block,javascript/example/two-block
|
||||||
javascript/example/empty-or-one-block,javascript/example/empty-or-one-block,javascript/example/other-query-block,javascript/example/two-block
|
|
||||||
queries-not-run: foo,bar
|
queries-not-run: foo,bar
|
||||||
|
|
||||||
- name: Assert Results
|
- name: Assert Results
|
||||||
|
|||||||
Generated
+5
-4
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -59,8 +62,7 @@ defaults:
|
|||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: remote-config-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
||||||
remote-config-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
remote-config:
|
remote-config:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -106,8 +108,7 @@ jobs:
|
|||||||
with:
|
with:
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
languages: cpp,csharp,java,javascript,python
|
languages: cpp,csharp,java,javascript,python
|
||||||
config-file: ${{ github.repository }}/tests/multi-language-repo/.github/codeql/custom-queries.yml@${{
|
config-file: ${{ github.repository }}/tests/multi-language-repo/.github/codeql/custom-queries.yml@${{ github.sha }}
|
||||||
github.sha }}
|
|
||||||
- name: Build code
|
- name: Build code
|
||||||
run: ./build.sh
|
run: ./build.sh
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
|
|||||||
+4
-2
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -81,8 +84,7 @@ jobs:
|
|||||||
language: javascript-typescript
|
language: javascript-typescript
|
||||||
|
|
||||||
- name: Fail if JavaScript/TypeScript configuration present
|
- name: Fail if JavaScript/TypeScript configuration present
|
||||||
if:
|
if: fromJSON(steps.resolve-environment-js.outputs.environment).configuration.javascript
|
||||||
fromJSON(steps.resolve-environment-js.outputs.environment).configuration.javascript
|
|
||||||
run: exit 1
|
run: exit 1
|
||||||
env:
|
env:
|
||||||
CODEQL_ACTION_TEST_MODE: true
|
CODEQL_ACTION_TEST_MODE: true
|
||||||
|
|||||||
+4
-1
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -56,7 +59,7 @@ jobs:
|
|||||||
use-all-platform-bundle: 'false'
|
use-all-platform-bundle: 'false'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- name: Set up Ruby
|
- name: Set up Ruby
|
||||||
uses: ruby/setup-ruby@90be1154f987f4dc0fe0dd0feedac9e473aa4ba8 # v1.286.0
|
uses: ruby/setup-ruby@09a7688d3b55cf0e976497ff046b70949eeaccfd # v1.288.0
|
||||||
with:
|
with:
|
||||||
ruby-version: 2.6
|
ruby-version: 2.6
|
||||||
- name: Install Code Scanning integration
|
- name: Install Code Scanning integration
|
||||||
|
|||||||
Generated
+3
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|||||||
Generated
+3
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|||||||
Generated
+6
-3
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -96,7 +99,7 @@ jobs:
|
|||||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
config-file: .github/codeql/codeql-config-packaging3.yml
|
config-file: '.github/codeql/codeql-config-packaging3.yml'
|
||||||
packs: +codeql-testing/codeql-pack1@1.0.0
|
packs: +codeql-testing/codeql-pack1@1.0.0
|
||||||
languages: javascript
|
languages: javascript
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
@@ -105,7 +108,7 @@ jobs:
|
|||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
skip-queries: true
|
skip-queries: true
|
||||||
output: ${{ runner.temp }}/results
|
output: '${{ runner.temp }}/results'
|
||||||
upload-database: false
|
upload-database: false
|
||||||
|
|
||||||
- name: Assert No Results
|
- name: Assert No Results
|
||||||
@@ -116,7 +119,7 @@ jobs:
|
|||||||
fi
|
fi
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
output: ${{ runner.temp }}/results
|
output: '${{ runner.temp }}/results'
|
||||||
upload-database: false
|
upload-database: false
|
||||||
- name: Assert Results
|
- name: Assert Results
|
||||||
run: |
|
run: |
|
||||||
|
|||||||
Generated
+5
-4
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -68,8 +71,7 @@ jobs:
|
|||||||
id: proxy
|
id: proxy
|
||||||
uses: ./../action/start-proxy
|
uses: ./../action/start-proxy
|
||||||
with:
|
with:
|
||||||
registry_secrets: '[{ "type": "nuget_feed", "url": "https://api.nuget.org/v3/index.json"
|
registry_secrets: '[{ "type": "nuget_feed", "url": "https://api.nuget.org/v3/index.json" }]'
|
||||||
}]'
|
|
||||||
|
|
||||||
- name: Print proxy outputs
|
- name: Print proxy outputs
|
||||||
run: |
|
run: |
|
||||||
@@ -78,8 +80,7 @@ jobs:
|
|||||||
echo "${{ steps.proxy.outputs.proxy_urls }}"
|
echo "${{ steps.proxy.outputs.proxy_urls }}"
|
||||||
|
|
||||||
- name: Fail if proxy outputs are not set
|
- name: Fail if proxy outputs are not set
|
||||||
if: (!steps.proxy.outputs.proxy_host) || (!steps.proxy.outputs.proxy_port)
|
if: (!steps.proxy.outputs.proxy_host) || (!steps.proxy.outputs.proxy_port) || (!steps.proxy.outputs.proxy_ca_certificate) || (!steps.proxy.outputs.proxy_urls)
|
||||||
|| (!steps.proxy.outputs.proxy_ca_certificate) || (!steps.proxy.outputs.proxy_urls)
|
|
||||||
run: exit 1
|
run: exit 1
|
||||||
env:
|
env:
|
||||||
CODEQL_ACTION_TEST_MODE: true
|
CODEQL_ACTION_TEST_MODE: true
|
||||||
|
|||||||
+11
-15
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -46,8 +49,7 @@ jobs:
|
|||||||
if: github.triggering_actor != 'dependabot[bot]'
|
if: github.triggering_actor != 'dependabot[bot]'
|
||||||
permissions:
|
permissions:
|
||||||
contents: read
|
contents: read
|
||||||
security-events: write # needed to upload the SARIF file
|
security-events: write
|
||||||
|
|
||||||
timeout-minutes: 45
|
timeout-minutes: 45
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
@@ -66,26 +68,20 @@ jobs:
|
|||||||
languages: javascript
|
languages: javascript
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
- name: Fail
|
- name: Fail
|
||||||
# We want this job to pass if the Action correctly uploads the SARIF file for
|
# We want this job to pass if the Action correctly uploads the SARIF file for
|
||||||
# the failed run.
|
# the failed run.
|
||||||
# Setting this step to continue on error means that it is marked as completing
|
# Setting this step to continue on error means that it is marked as completing
|
||||||
# successfully, so will not fail the job.
|
# successfully, so will not fail the job.
|
||||||
continue-on-error: true
|
continue-on-error: true
|
||||||
run: exit 1
|
run: exit 1
|
||||||
- uses: ./analyze
|
- uses: ./analyze
|
||||||
# In a real workflow, this step wouldn't run. Since we used `continue-on-error`
|
# In a real workflow, this step wouldn't run. Since we used `continue-on-error`
|
||||||
# above, we manually disable it with an `if` condition.
|
# above, we manually disable it with an `if` condition.
|
||||||
if: false
|
if: false
|
||||||
with:
|
with:
|
||||||
category: /test-codeql-version:${{ matrix.version }}
|
category: '/test-codeql-version:${{ matrix.version }}'
|
||||||
env:
|
env:
|
||||||
# Internal-only environment variable used to indicate that the post-init Action
|
|
||||||
# should expect to upload a SARIF file for the failed run.
|
|
||||||
CODEQL_ACTION_EXPECT_UPLOAD_FAILED_SARIF: true
|
CODEQL_ACTION_EXPECT_UPLOAD_FAILED_SARIF: true
|
||||||
# Make sure the uploading SARIF files feature is enabled.
|
|
||||||
CODEQL_ACTION_UPLOAD_FAILED_SARIF: true
|
CODEQL_ACTION_UPLOAD_FAILED_SARIF: true
|
||||||
# Upload the failed SARIF file as an integration test of the API endpoint.
|
|
||||||
CODEQL_ACTION_TEST_MODE: false
|
CODEQL_ACTION_TEST_MODE: false
|
||||||
# Mark telemetry for this workflow so it can be treated separately.
|
|
||||||
CODEQL_ACTION_TESTING_ENVIRONMENT: codeql-action-pr-checks
|
CODEQL_ACTION_TESTING_ENVIRONMENT: codeql-action-pr-checks
|
||||||
|
|
||||||
|
|||||||
Generated
+3
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|||||||
+4
-2
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -49,8 +52,7 @@ defaults:
|
|||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: swift-custom-build-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
||||||
swift-custom-build-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
swift-custom-build:
|
swift-custom-build:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+5
-3
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -59,8 +62,7 @@ defaults:
|
|||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: unset-environment-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
||||||
unset-environment-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
unset-environment:
|
unset-environment:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -106,7 +108,7 @@ jobs:
|
|||||||
id: init
|
id: init
|
||||||
with:
|
with:
|
||||||
db-location: ${{ runner.temp }}/customDbLocation
|
db-location: ${{ runner.temp }}/customDbLocation
|
||||||
# Swift is not supported on Ubuntu so we manually exclude it from the list here
|
# Swift is not supported on Ubuntu so we manually exclude it from the list here
|
||||||
languages: cpp,csharp,go,java,javascript,python,ruby
|
languages: cpp,csharp,go,java,javascript,python,ruby
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
- name: Build code
|
- name: Build code
|
||||||
|
|||||||
+10
-9
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -59,8 +62,7 @@ defaults:
|
|||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: upload-ref-sha-input-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
||||||
upload-ref-sha-input-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
upload-ref-sha-input:
|
upload-ref-sha-input:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -104,19 +106,18 @@ jobs:
|
|||||||
with:
|
with:
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
languages: cpp,csharp,java,javascript,python
|
languages: cpp,csharp,java,javascript,python
|
||||||
config-file: ${{ github.repository }}/tests/multi-language-repo/.github/codeql/custom-queries.yml@${{
|
config-file: ${{ github.repository }}/tests/multi-language-repo/.github/codeql/custom-queries.yml@${{ github.sha }}
|
||||||
github.sha }}
|
|
||||||
- name: Build code
|
- name: Build code
|
||||||
run: ./build.sh
|
run: ./build.sh
|
||||||
# Generate some SARIF we can upload with the upload-sarif step
|
# Generate some SARIF we can upload with the upload-sarif step
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
ref: refs/heads/main
|
ref: 'refs/heads/main'
|
||||||
sha: 5e235361806c361d4d3f8859e3c897658025a9a2
|
sha: '5e235361806c361d4d3f8859e3c897658025a9a2'
|
||||||
upload: never
|
upload: never
|
||||||
- uses: ./../action/upload-sarif
|
- uses: ./../action/upload-sarif
|
||||||
with:
|
with:
|
||||||
ref: refs/heads/main
|
ref: 'refs/heads/main'
|
||||||
sha: 5e235361806c361d4d3f8859e3c897658025a9a2
|
sha: '5e235361806c361d4d3f8859e3c897658025a9a2'
|
||||||
env:
|
env:
|
||||||
CODEQL_ACTION_TEST_MODE: true
|
CODEQL_ACTION_TEST_MODE: true
|
||||||
|
|||||||
Generated
+22
-22
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -59,8 +62,7 @@ defaults:
|
|||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: upload-sarif-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
||||||
upload-sarif-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
upload-sarif:
|
upload-sarif:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -114,11 +116,11 @@ jobs:
|
|||||||
analysis-kinds: ${{ matrix.analysis-kinds }}
|
analysis-kinds: ${{ matrix.analysis-kinds }}
|
||||||
- name: Build code
|
- name: Build code
|
||||||
run: ./build.sh
|
run: ./build.sh
|
||||||
# Generate some SARIF we can upload with the upload-sarif step
|
# Generate some SARIF we can upload with the upload-sarif step
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
ref: refs/heads/main
|
ref: 'refs/heads/main'
|
||||||
sha: 5e235361806c361d4d3f8859e3c897658025a9a2
|
sha: '5e235361806c361d4d3f8859e3c897658025a9a2'
|
||||||
upload: never
|
upload: never
|
||||||
output: ${{ runner.temp }}/results
|
output: ${{ runner.temp }}/results
|
||||||
|
|
||||||
@@ -127,15 +129,15 @@ jobs:
|
|||||||
uses: ./../action/upload-sarif
|
uses: ./../action/upload-sarif
|
||||||
id: upload-sarif
|
id: upload-sarif
|
||||||
with:
|
with:
|
||||||
ref: refs/heads/main
|
ref: 'refs/heads/main'
|
||||||
sha: 5e235361806c361d4d3f8859e3c897658025a9a2
|
sha: '5e235361806c361d4d3f8859e3c897658025a9a2'
|
||||||
sarif_file: ${{ runner.temp }}/results
|
sarif_file: ${{ runner.temp }}/results
|
||||||
category: |
|
category: |
|
||||||
${{ github.workflow }}:upload-sarif/analysis-kinds:${{ matrix.analysis-kinds }}/os:${{ matrix.os }}/version:${{ matrix.version }}/test:all-files/
|
${{ github.workflow }}:upload-sarif/analysis-kinds:${{ matrix.analysis-kinds }}/os:${{ matrix.os }}/version:${{ matrix.version }}/test:all-files/
|
||||||
- name: Fail for missing output from `upload-sarif` step for `code-scanning`
|
- name: 'Fail for missing output from `upload-sarif` step for `code-scanning`'
|
||||||
if: contains(matrix.analysis-kinds, 'code-scanning') && !(fromJSON(steps.upload-sarif.outputs.sarif-ids).code-scanning)
|
if: contains(matrix.analysis-kinds, 'code-scanning') && !(fromJSON(steps.upload-sarif.outputs.sarif-ids).code-scanning)
|
||||||
run: exit 1
|
run: exit 1
|
||||||
- name: Fail for missing output from `upload-sarif` step for `code-quality`
|
- name: 'Fail for missing output from `upload-sarif` step for `code-quality`'
|
||||||
if: contains(matrix.analysis-kinds, 'code-quality') && !(fromJSON(steps.upload-sarif.outputs.sarif-ids).code-quality)
|
if: contains(matrix.analysis-kinds, 'code-quality') && !(fromJSON(steps.upload-sarif.outputs.sarif-ids).code-quality)
|
||||||
run: exit 1
|
run: exit 1
|
||||||
|
|
||||||
@@ -144,28 +146,26 @@ jobs:
|
|||||||
id: upload-single-sarif-code-scanning
|
id: upload-single-sarif-code-scanning
|
||||||
if: contains(matrix.analysis-kinds, 'code-scanning')
|
if: contains(matrix.analysis-kinds, 'code-scanning')
|
||||||
with:
|
with:
|
||||||
ref: refs/heads/main
|
ref: 'refs/heads/main'
|
||||||
sha: 5e235361806c361d4d3f8859e3c897658025a9a2
|
sha: '5e235361806c361d4d3f8859e3c897658025a9a2'
|
||||||
sarif_file: ${{ runner.temp }}/results/javascript.sarif
|
sarif_file: ${{ runner.temp }}/results/javascript.sarif
|
||||||
category: |
|
category: |
|
||||||
${{ github.workflow }}:upload-sarif/analysis-kinds:${{ matrix.analysis-kinds }}/os:${{ matrix.os }}/version:${{ matrix.version }}/test:single-code-scanning/
|
${{ github.workflow }}:upload-sarif/analysis-kinds:${{ matrix.analysis-kinds }}/os:${{ matrix.os }}/version:${{ matrix.version }}/test:single-code-scanning/
|
||||||
- name: Fail for missing output from `upload-single-sarif-code-scanning` step
|
- name: 'Fail for missing output from `upload-single-sarif-code-scanning` step'
|
||||||
if: contains(matrix.analysis-kinds, 'code-scanning') &&
|
if: contains(matrix.analysis-kinds, 'code-scanning') && !(fromJSON(steps.upload-single-sarif-code-scanning.outputs.sarif-ids).code-scanning)
|
||||||
!(fromJSON(steps.upload-single-sarif-code-scanning.outputs.sarif-ids).code-scanning)
|
|
||||||
run: exit 1
|
run: exit 1
|
||||||
- name: Upload single SARIF file for Code Quality
|
- name: Upload single SARIF file for Code Quality
|
||||||
uses: ./../action/upload-sarif
|
uses: ./../action/upload-sarif
|
||||||
id: upload-single-sarif-code-quality
|
id: upload-single-sarif-code-quality
|
||||||
if: contains(matrix.analysis-kinds, 'code-quality')
|
if: contains(matrix.analysis-kinds, 'code-quality')
|
||||||
with:
|
with:
|
||||||
ref: refs/heads/main
|
ref: 'refs/heads/main'
|
||||||
sha: 5e235361806c361d4d3f8859e3c897658025a9a2
|
sha: '5e235361806c361d4d3f8859e3c897658025a9a2'
|
||||||
sarif_file: ${{ runner.temp }}/results/javascript.quality.sarif
|
sarif_file: ${{ runner.temp }}/results/javascript.quality.sarif
|
||||||
category: |
|
category: |
|
||||||
${{ github.workflow }}:upload-sarif/analysis-kinds:${{ matrix.analysis-kinds }}/os:${{ matrix.os }}/version:${{ matrix.version }}/test:single-code-quality/
|
${{ github.workflow }}:upload-sarif/analysis-kinds:${{ matrix.analysis-kinds }}/os:${{ matrix.os }}/version:${{ matrix.version }}/test:single-code-quality/
|
||||||
- name: Fail for missing output from `upload-single-sarif-code-quality` step
|
- name: 'Fail for missing output from `upload-single-sarif-code-quality` step'
|
||||||
if: contains(matrix.analysis-kinds, 'code-quality') &&
|
if: contains(matrix.analysis-kinds, 'code-quality') && !(fromJSON(steps.upload-single-sarif-code-quality.outputs.sarif-ids).code-quality)
|
||||||
!(fromJSON(steps.upload-single-sarif-code-quality.outputs.sarif-ids).code-quality)
|
|
||||||
run: exit 1
|
run: exit 1
|
||||||
|
|
||||||
- name: Change SARIF file extension
|
- name: Change SARIF file extension
|
||||||
@@ -176,12 +176,12 @@ jobs:
|
|||||||
id: upload-single-non-sarif
|
id: upload-single-non-sarif
|
||||||
if: contains(matrix.analysis-kinds, 'code-scanning')
|
if: contains(matrix.analysis-kinds, 'code-scanning')
|
||||||
with:
|
with:
|
||||||
ref: refs/heads/main
|
ref: 'refs/heads/main'
|
||||||
sha: 5e235361806c361d4d3f8859e3c897658025a9a2
|
sha: '5e235361806c361d4d3f8859e3c897658025a9a2'
|
||||||
sarif_file: ${{ runner.temp }}/results/javascript.sarif.json
|
sarif_file: ${{ runner.temp }}/results/javascript.sarif.json
|
||||||
category: |
|
category: |
|
||||||
${{ github.workflow }}:upload-sarif/analysis-kinds:${{ matrix.analysis-kinds }}/os:${{ matrix.os }}/version:${{ matrix.version }}/test:non-sarif/
|
${{ github.workflow }}:upload-sarif/analysis-kinds:${{ matrix.analysis-kinds }}/os:${{ matrix.os }}/version:${{ matrix.version }}/test:non-sarif/
|
||||||
- name: Fail for missing output from `upload-single-non-sarif` step
|
- name: 'Fail for missing output from `upload-single-non-sarif` step'
|
||||||
if: contains(matrix.analysis-kinds, 'code-scanning') && !(fromJSON(steps.upload-single-non-sarif.outputs.sarif-ids).code-scanning)
|
if: contains(matrix.analysis-kinds, 'code-scanning') && !(fromJSON(steps.upload-single-non-sarif.outputs.sarif-ids).code-scanning)
|
||||||
run: exit 1
|
run: exit 1
|
||||||
env:
|
env:
|
||||||
|
|||||||
+8
-5
@@ -18,6 +18,9 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types:
|
||||||
|
- checks_requested
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -59,8 +62,7 @@ defaults:
|
|||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: with-checkout-path-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
||||||
with-checkout-path-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
with-checkout-path:
|
with-checkout-path:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -77,6 +79,7 @@ jobs:
|
|||||||
timeout-minutes: 45
|
timeout-minutes: 45
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
|
# This ensures we don't accidentally use the original checkout for any part of the test.
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v6
|
||||||
- name: Prepare test
|
- name: Prepare test
|
||||||
@@ -106,8 +109,8 @@ jobs:
|
|||||||
# Actions does not support deleting the current working directory, so we
|
# Actions does not support deleting the current working directory, so we
|
||||||
# delete the contents of the directory instead.
|
# delete the contents of the directory instead.
|
||||||
rm -rf ./* .github .git
|
rm -rf ./* .github .git
|
||||||
# Check out the actions repo again, but at a different location.
|
# Check out the actions repo again, but at a different location.
|
||||||
# choose an arbitrary SHA so that we can later test that the commit_oid is not from main
|
# choose an arbitrary SHA so that we can later test that the commit_oid is not from main
|
||||||
- uses: actions/checkout@v6
|
- uses: actions/checkout@v6
|
||||||
with:
|
with:
|
||||||
ref: 474bbf07f9247ffe1856c6a0f94aeeb10e7afee6
|
ref: 474bbf07f9247ffe1856c6a0f94aeeb10e7afee6
|
||||||
@@ -116,7 +119,7 @@ jobs:
|
|||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
# it's enough to test one compiled language and one interpreted language
|
# it's enough to test one compiled language and one interpreted language
|
||||||
languages: csharp,javascript
|
languages: csharp,javascript
|
||||||
source-root: x/y/z/some-path/tests/multi-language-repo
|
source-root: x/y/z/some-path/tests/multi-language-repo
|
||||||
|
|
||||||
|
|||||||
@@ -7,6 +7,8 @@ on:
|
|||||||
# Run checks on reopened draft PRs to support triggering PR checks on draft PRs that were opened
|
# Run checks on reopened draft PRs to support triggering PR checks on draft PRs that were opened
|
||||||
# by other workflows.
|
# by other workflows.
|
||||||
types: [opened, synchronize, reopened, ready_for_review]
|
types: [opened, synchronize, reopened, ready_for_review]
|
||||||
|
merge_group:
|
||||||
|
types: [checks_requested]
|
||||||
schedule:
|
schedule:
|
||||||
# Weekly on Sunday.
|
# Weekly on Sunday.
|
||||||
- cron: '30 1 * * 0'
|
- cron: '30 1 * * 0'
|
||||||
@@ -29,34 +31,29 @@ jobs:
|
|||||||
|
|
||||||
permissions:
|
permissions:
|
||||||
contents: read
|
contents: read
|
||||||
|
# We currently need `security-events: read` to access feature flags.
|
||||||
|
security-events: read
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v6
|
- uses: actions/checkout@v6
|
||||||
- name: Init with default CodeQL bundle from the VM image
|
- name: Set up default CodeQL bundle
|
||||||
id: init-default
|
id: setup-default
|
||||||
uses: ./init
|
uses: ./setup-codeql
|
||||||
with:
|
- name: Set up linked CodeQL bundle
|
||||||
languages: javascript
|
id: setup-linked
|
||||||
- name: Remove empty database
|
uses: ./setup-codeql
|
||||||
# allows us to run init a second time
|
|
||||||
run: |
|
|
||||||
rm -rf "$RUNNER_TEMP/codeql_databases"
|
|
||||||
- name: Init with latest CodeQL bundle
|
|
||||||
id: init-latest
|
|
||||||
uses: ./init
|
|
||||||
with:
|
with:
|
||||||
tools: linked
|
tools: linked
|
||||||
languages: javascript
|
- name: Compare default and linked CodeQL bundle versions
|
||||||
- name: Compare default and latest CodeQL bundle versions
|
|
||||||
id: compare
|
id: compare
|
||||||
env:
|
env:
|
||||||
CODEQL_DEFAULT: ${{ steps.init-default.outputs.codeql-path }}
|
CODEQL_DEFAULT: ${{ steps.setup-default.outputs.codeql-path }}
|
||||||
CODEQL_LATEST: ${{ steps.init-latest.outputs.codeql-path }}
|
CODEQL_LINKED: ${{ steps.setup-linked.outputs.codeql-path }}
|
||||||
run: |
|
run: |
|
||||||
CODEQL_VERSION_DEFAULT="$("$CODEQL_DEFAULT" version --format terse)"
|
CODEQL_VERSION_DEFAULT="$("$CODEQL_DEFAULT" version --format terse)"
|
||||||
CODEQL_VERSION_LATEST="$("$CODEQL_LATEST" version --format terse)"
|
CODEQL_VERSION_LINKED="$("$CODEQL_LINKED" version --format terse)"
|
||||||
echo "Default CodeQL bundle version is $CODEQL_VERSION_DEFAULT"
|
echo "Default CodeQL bundle version is $CODEQL_VERSION_DEFAULT"
|
||||||
echo "Latest CodeQL bundle version is $CODEQL_VERSION_LATEST"
|
echo "Linked CodeQL bundle version is $CODEQL_VERSION_LINKED"
|
||||||
|
|
||||||
# If we're running on a pull request, run with both bundles, even if `tools: linked` would
|
# If we're running on a pull request, run with both bundles, even if `tools: linked` would
|
||||||
# be the same as `tools: null`. This allows us to make the job for each of the bundles a
|
# be the same as `tools: null`. This allows us to make the job for each of the bundles a
|
||||||
@@ -64,7 +61,7 @@ jobs:
|
|||||||
#
|
#
|
||||||
# If we're running on push or schedule, then we can skip running with `tools: linked` when it would be
|
# If we're running on push or schedule, then we can skip running with `tools: linked` when it would be
|
||||||
# the same as running with `tools: null`.
|
# the same as running with `tools: null`.
|
||||||
if [[ "$GITHUB_EVENT_NAME" != "pull_request" && "$CODEQL_VERSION_DEFAULT" == "$CODEQL_VERSION_LATEST" ]]; then
|
if [[ "$GITHUB_EVENT_NAME" != "pull_request" && "$GITHUB_EVENT_NAME" != "merge_group" && "$CODEQL_VERSION_DEFAULT" == "$CODEQL_VERSION_LINKED" ]]; then
|
||||||
VERSIONS_JSON='[null]'
|
VERSIONS_JSON='[null]'
|
||||||
else
|
else
|
||||||
VERSIONS_JSON='[null, "linked"]'
|
VERSIONS_JSON='[null, "linked"]'
|
||||||
@@ -108,7 +105,7 @@ jobs:
|
|||||||
uses: ./analyze
|
uses: ./analyze
|
||||||
with:
|
with:
|
||||||
category: "/language:javascript"
|
category: "/language:javascript"
|
||||||
upload: ${{ (matrix.os == 'ubuntu-24.04' && !matrix.tools && 'always') || 'never' }}
|
upload: ${{ (matrix.os == 'ubuntu-24.04' && !matrix.tools && github.event_name != 'merge_group' && 'always' ) || 'never' }}
|
||||||
|
|
||||||
analyze-other:
|
analyze-other:
|
||||||
if: github.triggering_actor != 'dependabot[bot]'
|
if: github.triggering_actor != 'dependabot[bot]'
|
||||||
@@ -143,3 +140,4 @@ jobs:
|
|||||||
uses: ./analyze
|
uses: ./analyze
|
||||||
with:
|
with:
|
||||||
category: "/language:${{ matrix.language }}"
|
category: "/language:${{ matrix.language }}"
|
||||||
|
upload: ${{ (github.event_name != 'merge_group' && 'always') || 'never' }}
|
||||||
|
|||||||
@@ -11,6 +11,8 @@ env:
|
|||||||
CODEQL_ACTION_OVERLAY_ANALYSIS: true
|
CODEQL_ACTION_OVERLAY_ANALYSIS: true
|
||||||
CODEQL_ACTION_OVERLAY_ANALYSIS_JAVASCRIPT: false
|
CODEQL_ACTION_OVERLAY_ANALYSIS_JAVASCRIPT: false
|
||||||
CODEQL_ACTION_OVERLAY_ANALYSIS_CODE_SCANNING_JAVASCRIPT: true
|
CODEQL_ACTION_OVERLAY_ANALYSIS_CODE_SCANNING_JAVASCRIPT: true
|
||||||
|
CODEQL_ACTION_OVERLAY_ANALYSIS_STATUS_CHECK: false
|
||||||
|
CODEQL_ACTION_OVERLAY_ANALYSIS_SKIP_RESOURCE_CHECKS: true
|
||||||
|
|
||||||
on:
|
on:
|
||||||
push:
|
push:
|
||||||
@@ -23,9 +25,11 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types: [checks_requested]
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch: {}
|
workflow_dispatch:
|
||||||
|
|
||||||
defaults:
|
defaults:
|
||||||
run:
|
run:
|
||||||
|
|||||||
@@ -14,9 +14,11 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types: [checks_requested]
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch: {}
|
workflow_dispatch:
|
||||||
|
|
||||||
defaults:
|
defaults:
|
||||||
run:
|
run:
|
||||||
@@ -39,6 +41,8 @@ jobs:
|
|||||||
CODEQL_ACTION_TEST_MODE: true
|
CODEQL_ACTION_TEST_MODE: true
|
||||||
permissions:
|
permissions:
|
||||||
contents: read
|
contents: read
|
||||||
|
# We currently need `security-events: read` to access feature flags.
|
||||||
|
security-events: read
|
||||||
timeout-minutes: 45
|
timeout-minutes: 45
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
@@ -85,7 +89,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Download all artifacts
|
- name: Download all artifacts
|
||||||
uses: actions/download-artifact@v7
|
uses: actions/download-artifact@v8
|
||||||
- name: Check expected artifacts exist
|
- name: Check expected artifacts exist
|
||||||
run: |
|
run: |
|
||||||
LANGUAGES="cpp csharp go java javascript python"
|
LANGUAGES="cpp csharp go java javascript python"
|
||||||
|
|||||||
@@ -13,9 +13,11 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types: [checks_requested]
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch: {}
|
workflow_dispatch:
|
||||||
|
|
||||||
defaults:
|
defaults:
|
||||||
run:
|
run:
|
||||||
@@ -38,6 +40,8 @@ jobs:
|
|||||||
timeout-minutes: 45
|
timeout-minutes: 45
|
||||||
permissions:
|
permissions:
|
||||||
contents: read
|
contents: read
|
||||||
|
# We currently need `security-events: read` to access feature flags.
|
||||||
|
security-events: read
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
@@ -79,7 +83,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Download all artifacts
|
- name: Download all artifacts
|
||||||
uses: actions/download-artifact@v7
|
uses: actions/download-artifact@v8
|
||||||
- name: Check expected artifacts exist
|
- name: Check expected artifacts exist
|
||||||
run: |
|
run: |
|
||||||
VERSIONS="stable-v2.20.3 default linked nightly-latest"
|
VERSIONS="stable-v2.20.3 default linked nightly-latest"
|
||||||
|
|||||||
@@ -17,6 +17,7 @@ jobs:
|
|||||||
sizeup:
|
sizeup:
|
||||||
name: Label PR with size
|
name: Label PR with size
|
||||||
runs-on: ubuntu-slim
|
runs-on: ubuntu-slim
|
||||||
|
if: github.event.pull_request.merged != true
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: Run sizeup
|
- name: Run sizeup
|
||||||
|
|||||||
@@ -6,6 +6,8 @@ on:
|
|||||||
# Run checks on reopened draft PRs to support triggering PR checks on draft PRs that were opened
|
# Run checks on reopened draft PRs to support triggering PR checks on draft PRs that were opened
|
||||||
# by other workflows.
|
# by other workflows.
|
||||||
types: [opened, synchronize, reopened, ready_for_review]
|
types: [opened, synchronize, reopened, ready_for_review]
|
||||||
|
merge_group:
|
||||||
|
types: [checks_requested]
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|
||||||
defaults:
|
defaults:
|
||||||
@@ -40,11 +42,6 @@ jobs:
|
|||||||
node-version: ${{ matrix.node-version }}
|
node-version: ${{ matrix.node-version }}
|
||||||
cache: 'npm'
|
cache: 'npm'
|
||||||
|
|
||||||
- name: Set up Python
|
|
||||||
uses: actions/setup-python@v6
|
|
||||||
with:
|
|
||||||
python-version: 3.11
|
|
||||||
|
|
||||||
- name: Install dependencies
|
- name: Install dependencies
|
||||||
run: |
|
run: |
|
||||||
# Use the system Bash shell to ensure we can run commands like `npm ci`
|
# Use the system Bash shell to ensure we can run commands like `npm ci`
|
||||||
@@ -66,7 +63,7 @@ jobs:
|
|||||||
- name: Run pr-checks tests
|
- name: Run pr-checks tests
|
||||||
if: always()
|
if: always()
|
||||||
working-directory: pr-checks
|
working-directory: pr-checks
|
||||||
run: python -m unittest discover
|
run: npm ci && npx tsx --test
|
||||||
|
|
||||||
- name: Lint
|
- name: Lint
|
||||||
if: always() && matrix.os != 'windows-latest'
|
if: always() && matrix.os != 'windows-latest'
|
||||||
@@ -80,7 +77,7 @@ jobs:
|
|||||||
category: eslint
|
category: eslint
|
||||||
|
|
||||||
check-node-version:
|
check-node-version:
|
||||||
if: github.event.pull_request && github.triggering_actor != 'dependabot[bot]'
|
if: github.triggering_actor != 'dependabot[bot]'
|
||||||
name: Check Action Node versions
|
name: Check Action Node versions
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
timeout-minutes: 45
|
timeout-minutes: 45
|
||||||
|
|||||||
@@ -7,6 +7,8 @@ on:
|
|||||||
# Run checks on reopened draft PRs to support triggering PR checks on draft PRs that were opened
|
# Run checks on reopened draft PRs to support triggering PR checks on draft PRs that were opened
|
||||||
# by other workflows.
|
# by other workflows.
|
||||||
types: [opened, synchronize, reopened, ready_for_review]
|
types: [opened, synchronize, reopened, ready_for_review]
|
||||||
|
merge_group:
|
||||||
|
types: [checks_requested]
|
||||||
schedule:
|
schedule:
|
||||||
# Weekly on Monday.
|
# Weekly on Monday.
|
||||||
- cron: '0 0 * * 1'
|
- cron: '0 0 * * 1'
|
||||||
@@ -24,6 +26,8 @@ jobs:
|
|||||||
timeout-minutes: 45
|
timeout-minutes: 45
|
||||||
permissions:
|
permissions:
|
||||||
contents: read
|
contents: read
|
||||||
|
# We currently need `security-events: read` to access feature flags.
|
||||||
|
security-events: read
|
||||||
runs-on: windows-latest
|
runs-on: windows-latest
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
|
|||||||
@@ -11,9 +11,11 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types: [checks_requested]
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch: {}
|
workflow_dispatch:
|
||||||
|
|
||||||
defaults:
|
defaults:
|
||||||
run:
|
run:
|
||||||
|
|||||||
@@ -73,24 +73,17 @@ jobs:
|
|||||||
npm run lint -- --fix
|
npm run lint -- --fix
|
||||||
npm run build
|
npm run build
|
||||||
|
|
||||||
- name: Set up Python
|
|
||||||
uses: actions/setup-python@v6
|
|
||||||
with:
|
|
||||||
python-version: 3.11
|
|
||||||
|
|
||||||
- name: Sync back version updates to generated workflows
|
- name: Sync back version updates to generated workflows
|
||||||
# Only sync back versions on Dependabot update PRs
|
# Only sync back versions on Dependabot update PRs
|
||||||
if: startsWith(env.HEAD_REF, 'dependabot/')
|
if: startsWith(env.HEAD_REF, 'dependabot/')
|
||||||
working-directory: pr-checks
|
working-directory: pr-checks
|
||||||
run: |
|
run: |
|
||||||
python3 sync_back.py -v
|
npm ci
|
||||||
|
npx tsx sync_back.ts --verbose
|
||||||
|
|
||||||
- name: Generate workflows
|
- name: Generate workflows
|
||||||
working-directory: pr-checks
|
working-directory: pr-checks
|
||||||
run: |
|
run: ./sync.sh
|
||||||
python -m pip install --upgrade pip
|
|
||||||
pip install ruamel.yaml==0.17.31
|
|
||||||
python3 sync.py
|
|
||||||
|
|
||||||
- name: "Merge in progress: Finish merge and push"
|
- name: "Merge in progress: Finish merge and push"
|
||||||
if: steps.merge.outputs.merge-in-progress == 'true'
|
if: steps.merge.outputs.merge-in-progress == 'true'
|
||||||
@@ -111,7 +104,7 @@ jobs:
|
|||||||
# Otherwise, just commit the changes.
|
# Otherwise, just commit the changes.
|
||||||
if git rev-parse --verify MERGE_HEAD >/dev/null 2>&1; then
|
if git rev-parse --verify MERGE_HEAD >/dev/null 2>&1; then
|
||||||
echo "In progress merge detected, finishing it up."
|
echo "In progress merge detected, finishing it up."
|
||||||
git merge --continue
|
git merge --continue --no-edit
|
||||||
else
|
else
|
||||||
echo "No in-progress merge detected, committing changes."
|
echo "No in-progress merge detected, committing changes."
|
||||||
git commit -m "Rebuild"
|
git commit -m "Rebuild"
|
||||||
|
|||||||
@@ -29,7 +29,7 @@ fi
|
|||||||
echo "Getting checks for $GITHUB_SHA"
|
echo "Getting checks for $GITHUB_SHA"
|
||||||
|
|
||||||
# Ignore any checks with "https://", CodeQL, LGTM, Update, and ESLint checks.
|
# Ignore any checks with "https://", CodeQL, LGTM, Update, and ESLint checks.
|
||||||
CHECKS="$(gh api repos/github/codeql-action/commits/"${GITHUB_SHA}"/check-runs --paginate | jq --slurp --compact-output --raw-output '[.[].check_runs.[] | select(.conclusion != "skipped") | .name | select(contains("https://") or . == "CodeQL" or . == "Dependabot" or . == "check-expected-release-files" or contains("Update") or contains("ESLint") or contains("update") or contains("test-setup-python-scripts") or . == "Agent" or . == "Cleanup artifacts" or . == "Prepare" or . == "Upload results" | not)] | unique | sort')"
|
CHECKS="$(gh api repos/github/codeql-action/commits/"${GITHUB_SHA}"/check-runs --paginate | jq --slurp --compact-output --raw-output '[.[].check_runs.[] | select(.conclusion != "skipped") | .name | select(contains("https://") or . == "CodeQL" or . == "Dependabot" or . == "check-expected-release-files" or contains("Update") or contains("ESLint") or contains("update") or contains("test-setup-python-scripts") or . == "Agent" or . == "Cleanup artifacts" or . == "Prepare" or . == "Upload results" or . == "Label PR with size" | not)] | unique | sort')"
|
||||||
|
|
||||||
echo "$CHECKS" | jq
|
echo "$CHECKS" | jq
|
||||||
|
|
||||||
|
|||||||
@@ -19,7 +19,7 @@ if [ ! -z "$(git status --porcelain)" ]; then
|
|||||||
# If we get a fail here then the PR needs attention
|
# If we get a fail here then the PR needs attention
|
||||||
git diff
|
git diff
|
||||||
git status
|
git status
|
||||||
>&2 echo "Failed: PR checks are not up to date. Run 'cd pr-checks && python3 sync.py' to update"
|
>&2 echo "Failed: PR checks are not up to date. Run 'cd pr-checks && ./sync.sh' to update"
|
||||||
|
|
||||||
echo "### Generated workflows diff" >> $GITHUB_STEP_SUMMARY
|
echo "### Generated workflows diff" >> $GITHUB_STEP_SUMMARY
|
||||||
echo "" >> $GITHUB_STEP_SUMMARY
|
echo "" >> $GITHUB_STEP_SUMMARY
|
||||||
|
|||||||
@@ -13,9 +13,11 @@ on:
|
|||||||
- synchronize
|
- synchronize
|
||||||
- reopened
|
- reopened
|
||||||
- ready_for_review
|
- ready_for_review
|
||||||
|
merge_group:
|
||||||
|
types: [checks_requested]
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch: {}
|
workflow_dispatch:
|
||||||
defaults:
|
defaults:
|
||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
|
|||||||
@@ -6,6 +6,41 @@ See the [releases page](https://github.com/github/codeql-action/releases) for th
|
|||||||
|
|
||||||
No user facing changes.
|
No user facing changes.
|
||||||
|
|
||||||
|
## 4.32.6 - 05 Mar 2026
|
||||||
|
|
||||||
|
- Update default CodeQL bundle version to [2.24.3](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.3). [#3548](https://github.com/github/codeql-action/pull/3548)
|
||||||
|
|
||||||
|
## 4.32.5 - 02 Mar 2026
|
||||||
|
|
||||||
|
- Repositories owned by an organization can now set up the `github-codeql-disable-overlay` custom repository property to disable [improved incremental analysis for CodeQL](https://github.com/github/roadmap/issues/1158). First, create a custom repository property with the name `github-codeql-disable-overlay` and the type "True/false" in the organization's settings. Then in the repository's settings, set this property to `true` to disable improved incremental analysis. For more information, see [Managing custom properties for repositories in your organization](https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization). This feature is not yet available on GitHub Enterprise Server. [#3507](https://github.com/github/codeql-action/pull/3507)
|
||||||
|
- Added an experimental change so that when [improved incremental analysis](https://github.com/github/roadmap/issues/1158) fails on a runner — potentially due to insufficient disk space — the failure is recorded in the Actions cache so that subsequent runs will automatically skip improved incremental analysis until something changes (e.g. a larger runner is provisioned or a new CodeQL version is released). We expect to roll this change out to everyone in March. [#3487](https://github.com/github/codeql-action/pull/3487)
|
||||||
|
- The minimum memory check for improved incremental analysis is now skipped for CodeQL 2.24.3 and later, which has reduced peak RAM usage. [#3515](https://github.com/github/codeql-action/pull/3515)
|
||||||
|
- Reduced log levels for best-effort private package registry connection check failures to reduce noise from workflow annotations. [#3516](https://github.com/github/codeql-action/pull/3516)
|
||||||
|
- Added an experimental change which lowers the minimum disk space requirement for [improved incremental analysis](https://github.com/github/roadmap/issues/1158), enabling it to run on standard GitHub Actions runners. We expect to roll this change out to everyone in March. [#3498](https://github.com/github/codeql-action/pull/3498)
|
||||||
|
- Added an experimental change which allows the `start-proxy` action to resolve the CodeQL CLI version from feature flags instead of using the linked CLI bundle version. We expect to roll this change out to everyone in March. [#3512](https://github.com/github/codeql-action/pull/3512)
|
||||||
|
- The previously experimental changes from versions 4.32.3, 4.32.4, 3.32.3 and 3.32.4 are now enabled by default. [#3503](https://github.com/github/codeql-action/pull/3503), [#3504](https://github.com/github/codeql-action/pull/3504)
|
||||||
|
|
||||||
|
## 4.32.4 - 20 Feb 2026
|
||||||
|
|
||||||
|
- Update default CodeQL bundle version to [2.24.2](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.2). [#3493](https://github.com/github/codeql-action/pull/3493)
|
||||||
|
- Added an experimental change which improves how certificates are generated for the authentication proxy that is used by the CodeQL Action in Default Setup when [private package registries are configured](https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries). This is expected to generate more widely compatible certificates and should have no impact on analyses which are working correctly already. We expect to roll this change out to everyone in February. [#3473](https://github.com/github/codeql-action/pull/3473)
|
||||||
|
- When the CodeQL Action is run [with debugging enabled in Default Setup](https://docs.github.com/en/code-security/how-tos/scan-code-for-vulnerabilities/troubleshooting/troubleshooting-analysis-errors/logs-not-detailed-enough#creating-codeql-debugging-artifacts-for-codeql-default-setup) and [private package registries are configured](https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries), the "Setup proxy for registries" step will output additional diagnostic information that can be used for troubleshooting. [#3486](https://github.com/github/codeql-action/pull/3486)
|
||||||
|
- Added a setting which allows the CodeQL Action to enable network debugging for Java programs. This will help GitHub staff support customers with troubleshooting issues in GitHub-managed CodeQL workflows, such as Default Setup. This setting can only be enabled by GitHub staff. [#3485](https://github.com/github/codeql-action/pull/3485)
|
||||||
|
- Added a setting which enables GitHub-managed workflows, such as Default Setup, to use a [nightly CodeQL CLI release](https://github.com/dsp-testing/codeql-cli-nightlies) instead of the latest, stable release that is used by default. This will help GitHub staff support customers whose analyses for a given repository or organization require early access to a change in an upcoming CodeQL CLI release. This setting can only be enabled by GitHub staff. [#3484](https://github.com/github/codeql-action/pull/3484)
|
||||||
|
|
||||||
|
## 4.32.3 - 13 Feb 2026
|
||||||
|
|
||||||
|
- Added experimental support for testing connections to [private package registries](https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries). This feature is not currently enabled for any analysis. In the future, it may be enabled by default for Default Setup. [#3466](https://github.com/github/codeql-action/pull/3466)
|
||||||
|
|
||||||
|
## 4.32.2 - 05 Feb 2026
|
||||||
|
|
||||||
|
- Update default CodeQL bundle version to [2.24.1](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.1). [#3460](https://github.com/github/codeql-action/pull/3460)
|
||||||
|
|
||||||
|
## 4.32.1 - 02 Feb 2026
|
||||||
|
|
||||||
|
- A warning is now shown in Default Setup workflow logs if a [private package registry is configured](https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries) using a GitHub Personal Access Token (PAT), but no username is configured. [#3422](https://github.com/github/codeql-action/pull/3422)
|
||||||
|
- Fixed a bug which caused the CodeQL Action to fail when repository properties cannot successfully be retrieved. [#3421](https://github.com/github/codeql-action/pull/3421)
|
||||||
|
|
||||||
## 4.32.0 - 26 Jan 2026
|
## 4.32.0 - 26 Jan 2026
|
||||||
|
|
||||||
- Update default CodeQL bundle version to [2.24.0](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.0). [#3425](https://github.com/github/codeql-action/pull/3425)
|
- Update default CodeQL bundle version to [2.24.0](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.0). [#3425](https://github.com/github/codeql-action/pull/3425)
|
||||||
|
|||||||
+1
-1
@@ -92,7 +92,7 @@ We typically deprecate a version of CodeQL when the GitHub Enterprise Server (GH
|
|||||||
1. Remove support for the old version of CodeQL.
|
1. Remove support for the old version of CodeQL.
|
||||||
- Bump `CODEQL_MINIMUM_VERSION` in `src/codeql.ts` to the new minimum version of CodeQL.
|
- Bump `CODEQL_MINIMUM_VERSION` in `src/codeql.ts` to the new minimum version of CodeQL.
|
||||||
- Remove any code that is only needed to support the old version of CodeQL. This is often behind a version guard, so look for instances of version numbers between the old minimum version and the new minimum version in the codebase. A good place to start is the list of version numbers in `src/codeql.ts`.
|
- Remove any code that is only needed to support the old version of CodeQL. This is often behind a version guard, so look for instances of version numbers between the old minimum version and the new minimum version in the codebase. A good place to start is the list of version numbers in `src/codeql.ts`.
|
||||||
- Update the default set of CodeQL test versions in `pr-checks/sync.py`.
|
- Update the default set of CodeQL test versions in `pr-checks/sync.ts`.
|
||||||
- Remove the old minimum version of CodeQL.
|
- Remove the old minimum version of CodeQL.
|
||||||
- Add the latest patch release for any new CodeQL minor version series that have shipped in GHES.
|
- Add the latest patch release for any new CodeQL minor version series that have shipped in GHES.
|
||||||
- Run the script to update the generated PR checks.
|
- Run the script to update the generated PR checks.
|
||||||
|
|||||||
@@ -72,14 +72,22 @@ We typically release new minor versions of the CodeQL Action and Bundle when a n
|
|||||||
|
|
||||||
| Minimum CodeQL Action | Minimum CodeQL Bundle Version | GitHub Environment | Notes |
|
| Minimum CodeQL Action | Minimum CodeQL Bundle Version | GitHub Environment | Notes |
|
||||||
|-----------------------|-------------------------------|--------------------|-------|
|
|-----------------------|-------------------------------|--------------------|-------|
|
||||||
| `v3.28.21` | `2.21.3` | Enterprise Server 3.18 | |
|
| `v4.31.10` | `2.23.9` | Enterprise Server 3.20 | |
|
||||||
| `v3.28.12` | `2.20.7` | Enterprise Server 3.17 | |
|
| `v3.29.11` | `2.22.4` | Enterprise Server 3.19 | |
|
||||||
| `v3.28.6` | `2.20.3` | Enterprise Server 3.16 | |
|
| `v3.28.21` | `2.21.3` | Enterprise Server 3.18 | |
|
||||||
| `v3.28.6` | `2.20.3` | Enterprise Server 3.15 | |
|
| `v3.28.12` | `2.20.7` | Enterprise Server 3.17 | |
|
||||||
|
| `v3.28.6` | `2.20.3` | Enterprise Server 3.16 | |
|
||||||
|
| `v3.28.6` | `2.20.3` | Enterprise Server 3.15 | |
|
||||||
| `v3.28.6` | `2.20.3` | Enterprise Server 3.14 | |
|
| `v3.28.6` | `2.20.3` | Enterprise Server 3.14 | |
|
||||||
|
|
||||||
See the full list of GHES release and deprecation dates at [GitHub Enterprise Server releases](https://docs.github.com/en/enterprise-server/admin/all-releases#releases-of-github-enterprise-server).
|
See the full list of GHES release and deprecation dates at [GitHub Enterprise Server releases](https://docs.github.com/en/enterprise-server/admin/all-releases#releases-of-github-enterprise-server).
|
||||||
|
|
||||||
|
## Keeping the CodeQL Action up to date in advanced setups
|
||||||
|
|
||||||
|
If you are using an [advanced setup](https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/configuring-advanced-setup-for-code-scanning), we recommend referencing the CodeQL Action using a major version tag (e.g. `v4`) in your workflow file. This ensures your workflow automatically picks up the latest release within that major version, including bug fixes, new features, and updated CodeQL CLI versions.
|
||||||
|
|
||||||
|
If you pin to a specific commit SHA or patch version tag, ensure you keep it updated (e.g. via [Dependabot](https://docs.github.com/en/code-security/dependabot/working-with-dependabot/keeping-your-actions-up-to-date-with-dependabot)). Some CodeQL Action features are enabled by server-side flags that may be removed over time, which can cause old versions to lose functionality.
|
||||||
|
|
||||||
## Troubleshooting
|
## Troubleshooting
|
||||||
|
|
||||||
Read about [troubleshooting code scanning](https://docs.github.com/en/code-security/code-scanning/troubleshooting-code-scanning).
|
Read about [troubleshooting code scanning](https://docs.github.com/en/code-security/code-scanning/troubleshooting-code-scanning).
|
||||||
|
|||||||
+37
-41
@@ -1,27 +1,14 @@
|
|||||||
// Automatically generated by running npx @eslint/migrate-config .eslintrc.json
|
import { fixupPluginRules } from "@eslint/compat";
|
||||||
|
|
||||||
import path from "node:path";
|
|
||||||
import { fileURLToPath } from "node:url";
|
|
||||||
|
|
||||||
import { fixupConfigRules, fixupPluginRules } from "@eslint/compat";
|
|
||||||
import { FlatCompat } from "@eslint/eslintrc";
|
|
||||||
import js from "@eslint/js";
|
import js from "@eslint/js";
|
||||||
import typescriptEslint from "@typescript-eslint/eslint-plugin";
|
|
||||||
import tsParser from "@typescript-eslint/parser";
|
|
||||||
import filenames from "eslint-plugin-filenames";
|
|
||||||
import github from "eslint-plugin-github";
|
import github from "eslint-plugin-github";
|
||||||
import _import from "eslint-plugin-import";
|
import { importX, createNodeResolver } from "eslint-plugin-import-x";
|
||||||
|
import { createTypeScriptImportResolver } from "eslint-import-resolver-typescript";
|
||||||
import noAsyncForeach from "eslint-plugin-no-async-foreach";
|
import noAsyncForeach from "eslint-plugin-no-async-foreach";
|
||||||
import jsdoc from "eslint-plugin-jsdoc";
|
import jsdoc from "eslint-plugin-jsdoc";
|
||||||
|
import tseslint from "typescript-eslint";
|
||||||
import globals from "globals";
|
import globals from "globals";
|
||||||
|
|
||||||
const __filename = fileURLToPath(import.meta.url);
|
const githubFlatConfigs = github.getFlatConfigs();
|
||||||
const __dirname = path.dirname(__filename);
|
|
||||||
const compat = new FlatCompat({
|
|
||||||
baseDirectory: __dirname,
|
|
||||||
recommendedConfig: js.configs.recommended,
|
|
||||||
allConfig: js.configs.all,
|
|
||||||
});
|
|
||||||
|
|
||||||
export default [
|
export default [
|
||||||
{
|
{
|
||||||
@@ -34,31 +21,32 @@ export default [
|
|||||||
"build.mjs",
|
"build.mjs",
|
||||||
"eslint.config.mjs",
|
"eslint.config.mjs",
|
||||||
".github/**/*",
|
".github/**/*",
|
||||||
|
"pr-checks/**/*",
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
...fixupConfigRules(
|
// eslint recommended config
|
||||||
compat.extends(
|
js.configs.recommended,
|
||||||
"eslint:recommended",
|
// Type-checked rules from typescript-eslint
|
||||||
"plugin:@typescript-eslint/recommended",
|
...tseslint.configs.recommendedTypeChecked,
|
||||||
"plugin:@typescript-eslint/recommended-requiring-type-checking",
|
...tseslint.configs.strict,
|
||||||
"plugin:github/recommended",
|
// eslint-plugin-github recommended config
|
||||||
"plugin:github/typescript",
|
githubFlatConfigs.recommended,
|
||||||
"plugin:import/typescript",
|
// eslint-plugin-github typescript config
|
||||||
),
|
...githubFlatConfigs.typescript,
|
||||||
),
|
// import-x TypeScript settings
|
||||||
|
// This is needed for import-x rules to properly parse TypeScript files.
|
||||||
|
{
|
||||||
|
settings: importX.flatConfigs.typescript.settings,
|
||||||
|
},
|
||||||
{
|
{
|
||||||
plugins: {
|
plugins: {
|
||||||
"@typescript-eslint": fixupPluginRules(typescriptEslint),
|
"import-x": importX,
|
||||||
filenames: fixupPluginRules(filenames),
|
"no-async-foreach": fixupPluginRules(noAsyncForeach),
|
||||||
github: fixupPluginRules(github),
|
|
||||||
import: fixupPluginRules(_import),
|
|
||||||
"no-async-foreach": noAsyncForeach,
|
|
||||||
"jsdoc": jsdoc,
|
"jsdoc": jsdoc,
|
||||||
},
|
},
|
||||||
|
|
||||||
languageOptions: {
|
languageOptions: {
|
||||||
parser: tsParser,
|
ecmaVersion: "latest",
|
||||||
ecmaVersion: 5,
|
|
||||||
sourceType: "module",
|
sourceType: "module",
|
||||||
|
|
||||||
globals: {
|
globals: {
|
||||||
@@ -78,11 +66,17 @@ export default [
|
|||||||
|
|
||||||
typescript: {},
|
typescript: {},
|
||||||
},
|
},
|
||||||
"import/ignore": ["sinon", "uuid", "@octokit/plugin-retry", "del", "get-folder-size", "@actions/github"],
|
"import/ignore": ["sinon", "uuid", "@octokit/plugin-retry", "del", "get-folder-size"],
|
||||||
|
"import-x/resolver-next": [
|
||||||
|
createTypeScriptImportResolver(),
|
||||||
|
createNodeResolver({
|
||||||
|
extensions: [".ts", ".js", ".json"],
|
||||||
|
}),
|
||||||
|
],
|
||||||
},
|
},
|
||||||
|
|
||||||
rules: {
|
rules: {
|
||||||
"filenames/match-regex": ["error", "^[a-z0-9-]+(\\.test)?$"],
|
"github/filenames-match-regex": ["error", "^[a-z0-9-]+(\\.test)?$"],
|
||||||
"i18n-text/no-en": "off",
|
"i18n-text/no-en": "off",
|
||||||
|
|
||||||
"import/extensions": [
|
"import/extensions": [
|
||||||
@@ -94,7 +88,10 @@ export default [
|
|||||||
|
|
||||||
"import/no-amd": "error",
|
"import/no-amd": "error",
|
||||||
"import/no-commonjs": "error",
|
"import/no-commonjs": "error",
|
||||||
"import/no-cycle": "error",
|
// import/no-cycle does not seem to work with ESLint 9.
|
||||||
|
// Use import-x/no-cycle from eslint-plugin-import-x instead.
|
||||||
|
"import/no-cycle": "off",
|
||||||
|
"import-x/no-cycle": "error",
|
||||||
"import/no-dynamic-require": "error",
|
"import/no-dynamic-require": "error",
|
||||||
|
|
||||||
"import/no-extraneous-dependencies": [
|
"import/no-extraneous-dependencies": [
|
||||||
@@ -132,6 +129,8 @@ export default [
|
|||||||
"no-async-foreach/no-async-foreach": "error",
|
"no-async-foreach/no-async-foreach": "error",
|
||||||
"no-sequences": "error",
|
"no-sequences": "error",
|
||||||
"no-shadow": "off",
|
"no-shadow": "off",
|
||||||
|
// This is overly restrictive with unsetting `EnvVar`s
|
||||||
|
"@typescript-eslint/no-dynamic-delete": "off",
|
||||||
"@typescript-eslint/no-shadow": "error",
|
"@typescript-eslint/no-shadow": "error",
|
||||||
"@typescript-eslint/prefer-optional-chain": "error",
|
"@typescript-eslint/prefer-optional-chain": "error",
|
||||||
"one-var": ["error", "never"],
|
"one-var": ["error", "never"],
|
||||||
@@ -152,12 +151,9 @@ export default [
|
|||||||
|
|
||||||
rules: {
|
rules: {
|
||||||
"@typescript-eslint/no-explicit-any": "off",
|
"@typescript-eslint/no-explicit-any": "off",
|
||||||
"@typescript-eslint/no-unsafe-argument": "off",
|
|
||||||
"@typescript-eslint/no-unsafe-assignment": "off",
|
"@typescript-eslint/no-unsafe-assignment": "off",
|
||||||
"@typescript-eslint/no-unsafe-call": "off",
|
|
||||||
"@typescript-eslint/no-unsafe-enum-comparison": "off",
|
"@typescript-eslint/no-unsafe-enum-comparison": "off",
|
||||||
"@typescript-eslint/no-unsafe-member-access": "off",
|
"@typescript-eslint/no-unsafe-member-access": "off",
|
||||||
"@typescript-eslint/no-unsafe-return": "off",
|
|
||||||
"@typescript-eslint/no-var-requires": "off",
|
"@typescript-eslint/no-var-requires": "off",
|
||||||
"@typescript-eslint/prefer-regexp-exec": "off",
|
"@typescript-eslint/prefer-regexp-exec": "off",
|
||||||
"@typescript-eslint/require-await": "off",
|
"@typescript-eslint/require-await": "off",
|
||||||
|
|||||||
@@ -159,6 +159,11 @@ inputs:
|
|||||||
description: >-
|
description: >-
|
||||||
Explicitly enable or disable caching of project build dependencies.
|
Explicitly enable or disable caching of project build dependencies.
|
||||||
required: false
|
required: false
|
||||||
|
check-run-id:
|
||||||
|
description: >-
|
||||||
|
[Internal] The ID of the check run, as provided by the Actions runtime environment. Do not set this value manually.
|
||||||
|
default: ${{ job.check_run_id }}
|
||||||
|
required: false
|
||||||
outputs:
|
outputs:
|
||||||
codeql-path:
|
codeql-path:
|
||||||
description: The path of the CodeQL binary used for analysis
|
description: The path of the CodeQL binary used for analysis
|
||||||
|
|||||||
Generated
+32648
-16840
File diff suppressed because one or more lines are too long
Generated
+15229
-16332
File diff suppressed because one or more lines are too long
Generated
+14963
-16146
File diff suppressed because one or more lines are too long
+4
-4
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"bundleVersion": "codeql-bundle-v2.24.0",
|
"bundleVersion": "codeql-bundle-v2.24.3",
|
||||||
"cliVersion": "2.24.0",
|
"cliVersion": "2.24.3",
|
||||||
"priorBundleVersion": "codeql-bundle-v2.23.9",
|
"priorBundleVersion": "codeql-bundle-v2.24.2",
|
||||||
"priorCliVersion": "2.23.9"
|
"priorCliVersion": "2.24.2"
|
||||||
}
|
}
|
||||||
|
|||||||
Generated
+45533
-29447
File diff suppressed because one or more lines are too long
Generated
+27425
-28302
File diff suppressed because one or more lines are too long
Generated
+14875
-16105
File diff suppressed because one or more lines are too long
Generated
+27031
-28129
File diff suppressed because one or more lines are too long
Generated
+32642
-16838
File diff suppressed because one or more lines are too long
Generated
+55119
-55589
File diff suppressed because one or more lines are too long
Generated
+15404
-16503
File diff suppressed because one or more lines are too long
Generated
+32617
-16813
File diff suppressed because one or more lines are too long
Generated
+27287
-28348
File diff suppressed because one or more lines are too long
Generated
+2259
-1539
File diff suppressed because it is too large
Load Diff
+20
-21
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "codeql",
|
"name": "codeql",
|
||||||
"version": "4.32.1",
|
"version": "4.32.7",
|
||||||
"private": true,
|
"private": true,
|
||||||
"description": "CodeQL action",
|
"description": "CodeQL action",
|
||||||
"scripts": {
|
"scripts": {
|
||||||
@@ -9,7 +9,7 @@
|
|||||||
"lint": "eslint --report-unused-disable-directives --max-warnings=0 .",
|
"lint": "eslint --report-unused-disable-directives --max-warnings=0 .",
|
||||||
"lint-ci": "SARIF_ESLINT_IGNORE_SUPPRESSED=true eslint --report-unused-disable-directives --max-warnings=0 . --format @microsoft/eslint-formatter-sarif --output-file=eslint.sarif",
|
"lint-ci": "SARIF_ESLINT_IGNORE_SUPPRESSED=true eslint --report-unused-disable-directives --max-warnings=0 . --format @microsoft/eslint-formatter-sarif --output-file=eslint.sarif",
|
||||||
"lint-fix": "eslint --report-unused-disable-directives --max-warnings=0 . --fix",
|
"lint-fix": "eslint --report-unused-disable-directives --max-warnings=0 . --fix",
|
||||||
"ava": "npm run transpile && ava --serial --verbose",
|
"ava": "npm run transpile && ava --verbose",
|
||||||
"test": "npm run ava -- src/",
|
"test": "npm run ava -- src/",
|
||||||
"test-debug": "npm run test -- --timeout=20m",
|
"test-debug": "npm run test -- --timeout=20m",
|
||||||
"transpile": "tsc --build --verbose"
|
"transpile": "tsc --build --verbose"
|
||||||
@@ -24,34 +24,33 @@
|
|||||||
},
|
},
|
||||||
"license": "MIT",
|
"license": "MIT",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@actions/artifact": "^5.0.2",
|
"@actions/artifact": "^5.0.3",
|
||||||
"@actions/artifact-legacy": "npm:@actions/artifact@^1.1.2",
|
"@actions/artifact-legacy": "npm:@actions/artifact@^1.1.2",
|
||||||
"@actions/cache": "^5.0.3",
|
"@actions/cache": "^5.0.5",
|
||||||
"@actions/core": "^2.0.2",
|
"@actions/core": "^2.0.3",
|
||||||
"@actions/exec": "^2.0.0",
|
"@actions/exec": "^2.0.0",
|
||||||
"@actions/github": "^9.0.0",
|
"@actions/github": "^8.0.1",
|
||||||
"@actions/glob": "^0.5.0",
|
"@actions/glob": "^0.5.0",
|
||||||
"@actions/http-client": "^3.0.0",
|
"@actions/http-client": "^3.0.0",
|
||||||
"@actions/io": "^2.0.0",
|
"@actions/io": "^2.0.0",
|
||||||
"@actions/tool-cache": "^3.0.0",
|
"@actions/tool-cache": "^3.0.1",
|
||||||
"@octokit/plugin-retry": "^8.0.0",
|
"@octokit/plugin-retry": "^8.0.0",
|
||||||
"@schemastore/package": "0.0.10",
|
"@schemastore/package": "0.0.10",
|
||||||
"archiver": "^7.0.1",
|
"archiver": "^7.0.1",
|
||||||
"fast-deep-equal": "^3.1.3",
|
"fast-deep-equal": "^3.1.3",
|
||||||
"follow-redirects": "^1.15.11",
|
"follow-redirects": "^1.15.11",
|
||||||
"get-folder-size": "^5.0.0",
|
"get-folder-size": "^5.0.0",
|
||||||
|
"https-proxy-agent": "^7.0.6",
|
||||||
"js-yaml": "^4.1.1",
|
"js-yaml": "^4.1.1",
|
||||||
"jsonschema": "1.4.1",
|
"jsonschema": "1.4.1",
|
||||||
"long": "^5.3.2",
|
"long": "^5.3.2",
|
||||||
"node-forge": "^1.3.3",
|
"node-forge": "^1.3.3",
|
||||||
"semver": "^7.7.3",
|
"semver": "^7.7.4",
|
||||||
"uuid": "^13.0.0"
|
"uuid": "^13.0.0"
|
||||||
},
|
},
|
||||||
"devDependencies": {
|
"devDependencies": {
|
||||||
"@ava/typescript": "6.0.0",
|
"@ava/typescript": "6.0.0",
|
||||||
"@eslint/compat": "^2.0.1",
|
"@eslint/compat": "^2.0.2",
|
||||||
"@eslint/eslintrc": "^3.3.3",
|
|
||||||
"@eslint/js": "^9.39.2",
|
|
||||||
"@microsoft/eslint-formatter-sarif": "^3.1.0",
|
"@microsoft/eslint-formatter-sarif": "^3.1.0",
|
||||||
"@octokit/types": "^16.0.0",
|
"@octokit/types": "^16.0.0",
|
||||||
"@types/archiver": "^7.0.0",
|
"@types/archiver": "^7.0.0",
|
||||||
@@ -59,23 +58,23 @@
|
|||||||
"@types/js-yaml": "^4.0.9",
|
"@types/js-yaml": "^4.0.9",
|
||||||
"@types/node": "^20.19.9",
|
"@types/node": "^20.19.9",
|
||||||
"@types/node-forge": "^1.3.14",
|
"@types/node-forge": "^1.3.14",
|
||||||
|
"@types/sarif": "^2.1.7",
|
||||||
"@types/semver": "^7.7.1",
|
"@types/semver": "^7.7.1",
|
||||||
"@types/sinon": "^21.0.0",
|
"@types/sinon": "^21.0.0",
|
||||||
"@typescript-eslint/eslint-plugin": "^8.53.1",
|
|
||||||
"@typescript-eslint/parser": "^8.48.0",
|
|
||||||
"ava": "^6.4.1",
|
"ava": "^6.4.1",
|
||||||
"esbuild": "^0.27.2",
|
"esbuild": "^0.27.3",
|
||||||
"eslint": "^8.57.1",
|
"eslint": "^9.39.2",
|
||||||
"eslint-import-resolver-typescript": "^3.8.7",
|
"eslint-import-resolver-typescript": "^3.8.7",
|
||||||
"eslint-plugin-filenames": "^1.3.2",
|
"eslint-plugin-github": "^6.0.0",
|
||||||
"eslint-plugin-github": "^5.1.8",
|
"eslint-plugin-import-x": "^4.16.1",
|
||||||
"eslint-plugin-import": "2.29.1",
|
"eslint-plugin-jsdoc": "^62.7.1",
|
||||||
"eslint-plugin-jsdoc": "^62.2.0",
|
|
||||||
"eslint-plugin-no-async-foreach": "^0.1.1",
|
"eslint-plugin-no-async-foreach": "^0.1.1",
|
||||||
"glob": "^11.1.0",
|
"glob": "^11.1.0",
|
||||||
"nock": "^14.0.10",
|
"globals": "^17.3.0",
|
||||||
|
"nock": "^14.0.11",
|
||||||
"sinon": "^21.0.1",
|
"sinon": "^21.0.1",
|
||||||
"typescript": "^5.9.3"
|
"typescript": "^5.9.3",
|
||||||
|
"typescript-eslint": "^8.56.1"
|
||||||
},
|
},
|
||||||
"overrides": {
|
"overrides": {
|
||||||
"@actions/tool-cache": {
|
"@actions/tool-cache": {
|
||||||
|
|||||||
@@ -1,3 +1 @@
|
|||||||
env
|
node_modules/
|
||||||
__pycache__/
|
|
||||||
*.pyc
|
|
||||||
|
|||||||
@@ -0,0 +1,30 @@
|
|||||||
|
export const ACTION_VERSIONS = {
|
||||||
|
"actions/checkout": {
|
||||||
|
"version": "v6"
|
||||||
|
},
|
||||||
|
"actions/setup-go": {
|
||||||
|
"version": "v6"
|
||||||
|
},
|
||||||
|
"actions/setup-dotnet": {
|
||||||
|
"version": "v5"
|
||||||
|
},
|
||||||
|
"actions/upload-artifact": {
|
||||||
|
"version": "v7"
|
||||||
|
},
|
||||||
|
"actions/github-script": {
|
||||||
|
"version": "v8"
|
||||||
|
},
|
||||||
|
"actions/setup-python": {
|
||||||
|
"version": "v6"
|
||||||
|
},
|
||||||
|
"actions/setup-java": {
|
||||||
|
"version": "v5"
|
||||||
|
},
|
||||||
|
"actions/setup-node": {
|
||||||
|
"version": "v6"
|
||||||
|
},
|
||||||
|
"ruby/setup-ruby": {
|
||||||
|
"version": "09a7688d3b55cf0e976497ff046b70949eeaccfd",
|
||||||
|
"comment": " v1.288.0"
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -1,8 +1,9 @@
|
|||||||
name: "Quality queries input"
|
name: "Analysis kinds"
|
||||||
description: "Tests that queries specified in the quality-queries input are used."
|
description: "Tests basic functionality for different `analysis-kinds` inputs."
|
||||||
versions: ["linked", "nightly-latest"]
|
versions: ["linked", "nightly-latest"]
|
||||||
analysisKinds: ["code-scanning", "code-quality", "code-scanning,code-quality"]
|
analysisKinds: ["code-scanning", "code-quality", "code-scanning,code-quality", "risk-assessment"]
|
||||||
env:
|
env:
|
||||||
|
CODEQL_ACTION_RISK_ASSESSMENT_ID: 1
|
||||||
CHECK_SCRIPT: |
|
CHECK_SCRIPT: |
|
||||||
const fs = require('fs');
|
const fs = require('fs');
|
||||||
|
|
||||||
@@ -37,30 +38,24 @@ steps:
|
|||||||
output: "${{ runner.temp }}/results"
|
output: "${{ runner.temp }}/results"
|
||||||
upload-database: false
|
upload-database: false
|
||||||
post-processed-sarif-path: "${{ runner.temp }}/post-processed"
|
post-processed-sarif-path: "${{ runner.temp }}/post-processed"
|
||||||
- name: Upload security SARIF
|
|
||||||
if: contains(matrix.analysis-kinds, 'code-scanning')
|
- name: Upload SARIF files
|
||||||
uses: actions/upload-artifact@v6
|
uses: actions/upload-artifact@v7
|
||||||
with:
|
with:
|
||||||
name: |
|
name: |
|
||||||
quality-queries-${{ matrix.os }}-${{ matrix.version }}-${{ matrix.analysis-kinds }}.sarif.json
|
analysis-kinds-${{ matrix.os }}-${{ matrix.version }}-${{ matrix.analysis-kinds }}
|
||||||
path: "${{ runner.temp }}/results/javascript.sarif"
|
path: "${{ runner.temp }}/results/*.sarif"
|
||||||
retention-days: 7
|
|
||||||
- name: Upload quality SARIF
|
|
||||||
if: contains(matrix.analysis-kinds, 'code-quality')
|
|
||||||
uses: actions/upload-artifact@v6
|
|
||||||
with:
|
|
||||||
name: |
|
|
||||||
quality-queries-${{ matrix.os }}-${{ matrix.version }}-${{ matrix.analysis-kinds }}.quality.sarif.json
|
|
||||||
path: "${{ runner.temp }}/results/javascript.quality.sarif"
|
|
||||||
retention-days: 7
|
retention-days: 7
|
||||||
|
|
||||||
- name: Upload post-processed SARIF
|
- name: Upload post-processed SARIF
|
||||||
uses: actions/upload-artifact@v6
|
uses: actions/upload-artifact@v7
|
||||||
with:
|
with:
|
||||||
name: |
|
name: |
|
||||||
post-processed-${{ matrix.os }}-${{ matrix.version }}-${{ matrix.analysis-kinds }}.sarif.json
|
post-processed-${{ matrix.os }}-${{ matrix.version }}-${{ matrix.analysis-kinds }}
|
||||||
path: "${{ runner.temp }}/post-processed"
|
path: "${{ runner.temp }}/post-processed"
|
||||||
retention-days: 7
|
retention-days: 7
|
||||||
if-no-files-found: error
|
if-no-files-found: error
|
||||||
|
|
||||||
- name: Check quality query does not appear in security SARIF
|
- name: Check quality query does not appear in security SARIF
|
||||||
if: contains(matrix.analysis-kinds, 'code-scanning')
|
if: contains(matrix.analysis-kinds, 'code-scanning')
|
||||||
uses: actions/github-script@v8
|
uses: actions/github-script@v8
|
||||||
@@ -1,11 +1,11 @@
|
|||||||
name: "Autobuild direct tracing (custom working directory)"
|
name: "Autobuild direct tracing (custom working directory)"
|
||||||
description: >
|
description: |
|
||||||
An end-to-end integration test of a Java repository built using 'build-mode: autobuild',
|
An end-to-end integration test of a Java repository built using 'build-mode: autobuild',
|
||||||
with direct tracing enabled and a custom working directory specified as the input to the
|
with direct tracing enabled and a custom working directory specified as the input to the
|
||||||
autobuild Action.
|
autobuild Action.
|
||||||
operatingSystems: ["ubuntu", "windows"]
|
operatingSystems: ["ubuntu", "windows"]
|
||||||
versions: ["linked", "nightly-latest"]
|
versions: ["linked", "nightly-latest"]
|
||||||
installJava: "true"
|
installJava: true
|
||||||
env:
|
env:
|
||||||
CODEQL_ACTION_AUTOBUILD_BUILD_MODE_DIRECT_TRACING: true
|
CODEQL_ACTION_AUTOBUILD_BUILD_MODE_DIRECT_TRACING: true
|
||||||
steps:
|
steps:
|
||||||
|
|||||||
@@ -2,8 +2,8 @@ name: "Build mode autobuild"
|
|||||||
description: "An end-to-end integration test of a Java repository built using 'build-mode: autobuild'"
|
description: "An end-to-end integration test of a Java repository built using 'build-mode: autobuild'"
|
||||||
operatingSystems: ["ubuntu", "windows"]
|
operatingSystems: ["ubuntu", "windows"]
|
||||||
versions: ["linked", "nightly-latest"]
|
versions: ["linked", "nightly-latest"]
|
||||||
installJava: "true"
|
installJava: true
|
||||||
installYq: "true"
|
installYq: true
|
||||||
steps:
|
steps:
|
||||||
- name: Set up Java test repo configuration
|
- name: Set up Java test repo configuration
|
||||||
run: |
|
run: |
|
||||||
|
|||||||
@@ -0,0 +1,15 @@
|
|||||||
|
name: "Bundle: From nightly"
|
||||||
|
description: "The nightly CodeQL bundle should be used when forced"
|
||||||
|
versions:
|
||||||
|
- linked # overruled by the FF set below
|
||||||
|
steps:
|
||||||
|
- id: init
|
||||||
|
uses: ./../action/init
|
||||||
|
env:
|
||||||
|
CODEQL_ACTION_FORCE_NIGHTLY: true
|
||||||
|
with:
|
||||||
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
|
languages: javascript
|
||||||
|
- name: Fail if the CodeQL version is not a nightly
|
||||||
|
if: ${{ !contains(steps.init.outputs.codeql-version, '+') }}
|
||||||
|
run: exit 1
|
||||||
@@ -4,7 +4,7 @@ versions:
|
|||||||
- toolcache
|
- toolcache
|
||||||
steps:
|
steps:
|
||||||
- name: Install @actions/tool-cache
|
- name: Install @actions/tool-cache
|
||||||
run: npm install @actions/tool-cache
|
run: npm install @actions/tool-cache@3
|
||||||
- name: Check toolcache contains CodeQL
|
- name: Check toolcache contains CodeQL
|
||||||
continue-on-error: true
|
continue-on-error: true
|
||||||
uses: actions/github-script@v8
|
uses: actions/github-script@v8
|
||||||
|
|||||||
@@ -16,7 +16,7 @@ steps:
|
|||||||
const codeqlPath = path.join(process.env['RUNNER_TOOL_CACHE'], 'CodeQL');
|
const codeqlPath = path.join(process.env['RUNNER_TOOL_CACHE'], 'CodeQL');
|
||||||
fs.rmdirSync(codeqlPath, { recursive: true });
|
fs.rmdirSync(codeqlPath, { recursive: true });
|
||||||
- name: Install @actions/tool-cache
|
- name: Install @actions/tool-cache
|
||||||
run: npm install @actions/tool-cache
|
run: npm install @actions/tool-cache@3
|
||||||
- name: Check toolcache does not contain CodeQL
|
- name: Check toolcache does not contain CodeQL
|
||||||
uses: actions/github-script@v8
|
uses: actions/github-script@v8
|
||||||
with:
|
with:
|
||||||
|
|||||||
@@ -27,7 +27,7 @@ steps:
|
|||||||
output: ${{ runner.temp }}/results
|
output: ${{ runner.temp }}/results
|
||||||
upload-database: false
|
upload-database: false
|
||||||
- name: Upload SARIF
|
- name: Upload SARIF
|
||||||
uses: actions/upload-artifact@v6
|
uses: actions/upload-artifact@v7
|
||||||
with:
|
with:
|
||||||
name: ${{ matrix.os }}-zstd-bundle.sarif
|
name: ${{ matrix.os }}-zstd-bundle.sarif
|
||||||
path: ${{ runner.temp }}/results/javascript.sarif
|
path: ${{ runner.temp }}/results/javascript.sarif
|
||||||
|
|||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user