mirror of
https://github.com/github/codeql-action.git
synced 2026-08-05 21:06:13 -05:00
Compare commits
268 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 4869139f44 | |||
| 712b51a568 | |||
| 0d61442a70 | |||
| c4b6a67406 | |||
| 90b2d28dad | |||
| 1314d3d17e | |||
| f7f9d3f341 | |||
| eb5bd2d0b9 | |||
| 9aa0515f67 | |||
| 0720e13f0b | |||
| 38ba96d2aa | |||
| 679da45cc3 | |||
| d5dd165f8b | |||
| fbf75ebd7b | |||
| 6a50972d16 | |||
| 5cb12c41c2 | |||
| e8f487178f | |||
| a0671be58e | |||
| 9ea34c5169 | |||
| 9fda641d8d | |||
| b126facd4e | |||
| 835dadecbf | |||
| a02edfe319 | |||
| 173919c9d5 | |||
| 6095dc4d51 | |||
| b333fc6f5b | |||
| 60b658ed10 | |||
| e4e324705e | |||
| faf7a50b01 | |||
| 2591c2031f | |||
| 34cae51104 | |||
| 9308bcd6bb | |||
| fa9b76ac37 | |||
| 6059a66dec | |||
| cb4fc9e8db | |||
| be82188a2a | |||
| c656a11252 | |||
| bd9f639752 | |||
| 0a0c3a2e09 | |||
| 46a8de52fc | |||
| f8cea24201 | |||
| b1993d9139 | |||
| ee1e1399e2 | |||
| e7d3af2e1e | |||
| 13a6d8be95 | |||
| b20883b0cd | |||
| bf20b3e07b | |||
| f1aa4f497a | |||
| 9a55d5bc5f | |||
| 17cd475099 | |||
| c9aa45dd0f | |||
| e3b8227a28 | |||
| 8a01181ce2 | |||
| 80e142568f | |||
| b748848f27 | |||
| 5e767eff5a | |||
| 9752869470 | |||
| c62c214723 | |||
| 18c2cfc765 | |||
| 1996ca9f5d | |||
| 12c4c7d0e9 | |||
| 25a224b808 | |||
| 919e8aaa40 | |||
| 4918026b93 | |||
| e8c164b902 | |||
| 3657da1eac | |||
| 605d404db0 | |||
| efea9cca02 | |||
| 9fccf271ff | |||
| c12cf8d49a | |||
| 0fcbec3eec | |||
| 0ae8b05d08 | |||
| 49cdf744d9 | |||
| aac4202424 | |||
| e7ece62b96 | |||
| d9e374ef85 | |||
| f4b47e7013 | |||
| 4e14537b54 | |||
| e142eee9b4 | |||
| dcd1b12beb | |||
| 55252c7a3a | |||
| 7381f9750d | |||
| 6e162a0930 | |||
| 19b2f06db2 | |||
| 03afde035d | |||
| 9469107033 | |||
| 1601acf88b | |||
| fba78720ca | |||
| a8dd5ab7a4 | |||
| 28bfb7b7b5 | |||
| 91f3460006 | |||
| edebb7861e | |||
| 529c266223 | |||
| 6bd84b6a82 | |||
| 5e98e18a17 | |||
| 229e0cd749 | |||
| 14bd76753f | |||
| b715292b74 | |||
| 7c72e12ecb | |||
| b5bb69ad4b | |||
| 1c4c0b36be | |||
| bc75091173 | |||
| dc2428c879 | |||
| cb2dd2ed29 | |||
| 9e2fa7419d | |||
| 6a02be43ee | |||
| e19f95e73f | |||
| 4325937dc6 | |||
| d5b3d42fd4 | |||
| 417a8c2176 | |||
| fa03060d60 | |||
| f58cb3d53e | |||
| 51975ff7b7 | |||
| 32d41f36fe | |||
| d60bbdfd70 | |||
| 93a99bf571 | |||
| dce83e1c1e | |||
| ec4eda1b42 | |||
| 1df1c9f85d | |||
| 9483bd5a7f | |||
| b880a1a7bd | |||
| 5ac04769eb | |||
| 1ac62705ed | |||
| 9a57e78a04 | |||
| 7e96d45489 | |||
| 13eb1818b9 | |||
| f950f7f442 | |||
| 69173ea009 | |||
| a886c30690 | |||
| 044ff10e29 | |||
| 84edfc05fa | |||
| df0cc0ca39 | |||
| 24f1cbdafb | |||
| 8881a4160f | |||
| 1191c09db6 | |||
| 90f4ffcc7e | |||
| 03e3f60d99 | |||
| 778f83ff16 | |||
| 75716abfa3 | |||
| ebffc48bf5 | |||
| d51b375a03 | |||
| 3a7caafd73 | |||
| 4d4ae1fbe8 | |||
| 064fafeb49 | |||
| a7783c507b | |||
| 0d94aab48f | |||
| 1ec7dd2bc4 | |||
| 1b4c62b79d | |||
| 4bd7556a48 | |||
| 7beb64218a | |||
| 546ea07303 | |||
| 9c3f69d7a3 | |||
| 5f5c095469 | |||
| c7d0b92094 | |||
| 055e6b6f36 | |||
| 644e2b9bd7 | |||
| 02b2c55c51 | |||
| 1782089bde | |||
| 6c5e0ea335 | |||
| c99e493099 | |||
| f687ebf1c9 | |||
| 070e2a5f21 | |||
| fb650c22f9 | |||
| 21c5dc0f33 | |||
| bdabb8f1bc | |||
| 39105f35da | |||
| dc7e2ff87d | |||
| 642eca368e | |||
| e20d24fb28 | |||
| f301585a01 | |||
| c8914af920 | |||
| a2d9de63c2 | |||
| 4672d7807f | |||
| be6e3c4480 | |||
| cdefb33c0f | |||
| cfa77c6b13 | |||
| 79939d8ca5 | |||
| d32cd4ddde | |||
| d6efb85cdf | |||
| 0fa411efd0 | |||
| c284324212 | |||
| 83e7d0046c | |||
| f6a16bef8e | |||
| c1f5f1a8b5 | |||
| 1805d8d0a4 | |||
| b2951d2a1e | |||
| 41448d92b9 | |||
| a7fe4ffe40 | |||
| fd448f79eb | |||
| 079ca18961 | |||
| 80dbba139d | |||
| 7edf2bd491 | |||
| db726913e9 | |||
| c327260b2b | |||
| ce7b1f8663 | |||
| 855c0888b6 | |||
| ec1705eb43 | |||
| 29ee0e040d | |||
| 35d39dfdb3 | |||
| 66bcc86d07 | |||
| 44e589b637 | |||
| 0d648eb4d1 | |||
| 3fd7db80f0 | |||
| 6b11018e07 | |||
| d0d445f91c | |||
| 60b2ba310b | |||
| 709d6de5f3 | |||
| efbc56d117 | |||
| f67ec12472 | |||
| 3b6fef64d5 | |||
| 8b428c0d4c | |||
| 034401b281 | |||
| 95246ce019 | |||
| 525b64847a | |||
| a7e88a44f8 | |||
| ff84c6f23c | |||
| 948c7fbf11 | |||
| cec3cc5782 | |||
| 358a55e232 | |||
| eb823a7a97 | |||
| 003ddaeef5 | |||
| a2c3c8e3e2 | |||
| a13b404670 | |||
| a2917b0733 | |||
| 67e683bd1b | |||
| cb26a026e5 | |||
| ac6c41b910 | |||
| 056581e05b | |||
| 9c5588d006 | |||
| 3765106c90 | |||
| e052dbd57d | |||
| 7673a2de65 | |||
| 32795b3c52 | |||
| 6b5763e5ee | |||
| 3322491022 | |||
| 6bc6217487 | |||
| faf6d35e7b | |||
| 3b94cfeb15 | |||
| b88acb2f6c | |||
| 241948c698 | |||
| da77f9f638 | |||
| de172624a1 | |||
| 488c1f1959 | |||
| f2ccf3b4f1 | |||
| f28848a66a | |||
| 5459b98ca0 | |||
| 0c8bfeaf84 | |||
| 1fe89fe9cb | |||
| 6dba00881c | |||
| d4d47c0d3d | |||
| 6c6e810910 | |||
| 393c074965 | |||
| c3dc529aef | |||
| fc2bbb041e | |||
| 89753aa84b | |||
| aff7998c4a | |||
| 7a5748cf0d | |||
| db75d46248 | |||
| a0fc644617 | |||
| e1058e4d74 | |||
| d4f39b0766 | |||
| b4db38273c | |||
| 846f8590dc | |||
| 3eaf00092b | |||
| 1512f400b3 | |||
| 7bb4bfc7c2 | |||
| 6678cee8aa | |||
| 79e9b8a130 |
@@ -0,0 +1,6 @@
|
|||||||
|
name: Verify that the best-effort debug artifact scan completed
|
||||||
|
description: Verifies that the best-effort debug artifact scan completed successfully during tests
|
||||||
|
runs:
|
||||||
|
using: node24
|
||||||
|
main: index.js
|
||||||
|
post: post.js
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
// The main step is a no-op, since we can only verify artifact scan completion in the post step.
|
||||||
|
console.log("Will verify artifact scan completion in the post step.");
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
// Post step - runs after the workflow completes, when artifact scan has finished
|
||||||
|
const process = require("process");
|
||||||
|
|
||||||
|
const scanFinished = process.env.CODEQL_ACTION_ARTIFACT_SCAN_FINISHED;
|
||||||
|
|
||||||
|
if (scanFinished !== "true") {
|
||||||
|
console.error("Error: Best-effort artifact scan did not complete. Expected CODEQL_ACTION_ARTIFACT_SCAN_FINISHED=true");
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
|
||||||
|
console.log("✓ Best-effort artifact scan completed successfully");
|
||||||
@@ -4,14 +4,15 @@ updates:
|
|||||||
directory: "/"
|
directory: "/"
|
||||||
schedule:
|
schedule:
|
||||||
interval: weekly
|
interval: weekly
|
||||||
|
cooldown:
|
||||||
|
default-days: 7
|
||||||
|
exclude:
|
||||||
|
- "@actions/*"
|
||||||
labels:
|
labels:
|
||||||
- Rebuild
|
- Rebuild
|
||||||
# Ignore incompatible dependency updates
|
# Ignore incompatible dependency updates
|
||||||
ignore:
|
ignore:
|
||||||
# There is a type incompatibility issue between v0.0.9 and our other dependencies.
|
# This is broken due to the way configuration files have changed.
|
||||||
- dependency-name: "@octokit/plugin-retry"
|
|
||||||
versions: ["~6.0.0"]
|
|
||||||
# This is broken due to the way configuration files have changed.
|
|
||||||
# This might be fixed when we move to eslint v9.
|
# This might be fixed when we move to eslint v9.
|
||||||
- dependency-name: "eslint-plugin-import"
|
- dependency-name: "eslint-plugin-import"
|
||||||
versions: [">=2.30.0"]
|
versions: [">=2.30.0"]
|
||||||
@@ -28,6 +29,10 @@ updates:
|
|||||||
- "/.github/actions"
|
- "/.github/actions"
|
||||||
schedule:
|
schedule:
|
||||||
interval: weekly
|
interval: weekly
|
||||||
|
cooldown:
|
||||||
|
default-days: 7
|
||||||
|
exclude:
|
||||||
|
- "actions/*"
|
||||||
labels:
|
labels:
|
||||||
- Rebuild
|
- Rebuild
|
||||||
groups:
|
groups:
|
||||||
|
|||||||
+3
-2
@@ -48,8 +48,9 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group:
|
||||||
|
all-platform-bundle-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
||||||
jobs:
|
jobs:
|
||||||
all-platform-bundle:
|
all-platform-bundle:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+3
-2
@@ -58,8 +58,9 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group:
|
||||||
|
analyze-ref-input-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
||||||
jobs:
|
jobs:
|
||||||
analyze-ref-input:
|
analyze-ref-input:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
Generated
+2
-2
@@ -38,8 +38,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: autobuild-action-${{github.ref}}-${{inputs.dotnet-version}}
|
||||||
jobs:
|
jobs:
|
||||||
autobuild-action:
|
autobuild-action:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
@@ -38,8 +38,9 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group:
|
||||||
|
autobuild-direct-tracing-with-working-dir-${{github.ref}}-${{inputs.java-version}}
|
||||||
jobs:
|
jobs:
|
||||||
autobuild-direct-tracing-with-working-dir:
|
autobuild-direct-tracing-with-working-dir:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+2
-2
@@ -28,8 +28,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: autobuild-working-dir-${{github.ref}}
|
||||||
jobs:
|
jobs:
|
||||||
autobuild-working-dir:
|
autobuild-working-dir:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+10
-7
@@ -38,8 +38,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: build-mode-autobuild-${{github.ref}}-${{inputs.java-version}}
|
||||||
jobs:
|
jobs:
|
||||||
build-mode-autobuild:
|
build-mode-autobuild:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -76,6 +76,14 @@ jobs:
|
|||||||
with:
|
with:
|
||||||
java-version: ${{ inputs.java-version || '17' }}
|
java-version: ${{ inputs.java-version || '17' }}
|
||||||
distribution: temurin
|
distribution: temurin
|
||||||
|
- name: Install yq
|
||||||
|
if: runner.os == 'Windows'
|
||||||
|
env:
|
||||||
|
YQ_PATH: ${{ runner.temp }}/yq
|
||||||
|
YQ_VERSION: v4.50.1
|
||||||
|
run: |-
|
||||||
|
gh release download --repo mikefarah/yq --pattern "yq_windows_amd64.exe" "$YQ_VERSION" -O "$YQ_PATH/yq.exe"
|
||||||
|
echo "$YQ_PATH" >> "$GITHUB_PATH"
|
||||||
- name: Set up Java test repo configuration
|
- name: Set up Java test repo configuration
|
||||||
run: |
|
run: |
|
||||||
mv * .github ../action/tests/multi-language-repo/
|
mv * .github ../action/tests/multi-language-repo/
|
||||||
@@ -90,11 +98,6 @@ jobs:
|
|||||||
languages: java
|
languages: java
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
|
|
||||||
- name: Install yq
|
|
||||||
if: runner.os == 'Windows'
|
|
||||||
run: |
|
|
||||||
choco install yq -y
|
|
||||||
|
|
||||||
- name: Validate database build mode
|
- name: Validate database build mode
|
||||||
run: |
|
run: |
|
||||||
metadata_path="$RUNNER_TEMP/customDbLocation/java/codeql-database.yml"
|
metadata_path="$RUNNER_TEMP/customDbLocation/java/codeql-database.yml"
|
||||||
|
|||||||
+3
-2
@@ -48,8 +48,9 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group:
|
||||||
|
build-mode-manual-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
||||||
jobs:
|
jobs:
|
||||||
build-mode-manual:
|
build-mode-manual:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
Generated
+2
-2
@@ -28,8 +28,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: build-mode-none-${{github.ref}}
|
||||||
jobs:
|
jobs:
|
||||||
build-mode-none:
|
build-mode-none:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+2
-2
@@ -28,8 +28,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: build-mode-rollback-${{github.ref}}
|
||||||
jobs:
|
jobs:
|
||||||
build-mode-rollback:
|
build-mode-rollback:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+2
-2
@@ -28,8 +28,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: bundle-from-toolcache-${{github.ref}}
|
||||||
jobs:
|
jobs:
|
||||||
bundle-from-toolcache:
|
bundle-from-toolcache:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
Generated
+2
-2
@@ -28,8 +28,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: bundle-toolcache-${{github.ref}}
|
||||||
jobs:
|
jobs:
|
||||||
bundle-toolcache:
|
bundle-toolcache:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
Generated
+2
-2
@@ -28,8 +28,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: bundle-zstd-${{github.ref}}
|
||||||
jobs:
|
jobs:
|
||||||
bundle-zstd:
|
bundle-zstd:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
Generated
+87
@@ -0,0 +1,87 @@
|
|||||||
|
# Warning: This file is generated automatically, and should not be modified.
|
||||||
|
# Instead, please modify the template in the pr-checks directory and run:
|
||||||
|
# pr-checks/sync.sh
|
||||||
|
# to regenerate this file.
|
||||||
|
|
||||||
|
name: PR Check - CCR
|
||||||
|
env:
|
||||||
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
GO111MODULE: auto
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches:
|
||||||
|
- main
|
||||||
|
- releases/v*
|
||||||
|
pull_request:
|
||||||
|
types:
|
||||||
|
- opened
|
||||||
|
- synchronize
|
||||||
|
- reopened
|
||||||
|
- ready_for_review
|
||||||
|
schedule:
|
||||||
|
- cron: '0 5 * * *'
|
||||||
|
workflow_dispatch:
|
||||||
|
inputs: {}
|
||||||
|
workflow_call:
|
||||||
|
inputs: {}
|
||||||
|
defaults:
|
||||||
|
run:
|
||||||
|
shell: bash
|
||||||
|
concurrency:
|
||||||
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
|
group: ccr-${{github.ref}}
|
||||||
|
jobs:
|
||||||
|
ccr:
|
||||||
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
|
matrix:
|
||||||
|
include:
|
||||||
|
- os: ubuntu-latest
|
||||||
|
version: stable-v2.17.6
|
||||||
|
- os: ubuntu-latest
|
||||||
|
version: stable-v2.18.4
|
||||||
|
- os: ubuntu-latest
|
||||||
|
version: stable-v2.19.4
|
||||||
|
- os: ubuntu-latest
|
||||||
|
version: stable-v2.20.7
|
||||||
|
- os: ubuntu-latest
|
||||||
|
version: stable-v2.21.4
|
||||||
|
- os: ubuntu-latest
|
||||||
|
version: stable-v2.22.4
|
||||||
|
- os: ubuntu-latest
|
||||||
|
version: default
|
||||||
|
- os: ubuntu-latest
|
||||||
|
version: linked
|
||||||
|
- os: ubuntu-latest
|
||||||
|
version: nightly-latest
|
||||||
|
name: CCR
|
||||||
|
if: github.triggering_actor != 'dependabot[bot]'
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
security-events: read
|
||||||
|
timeout-minutes: 45
|
||||||
|
runs-on: ${{ matrix.os }}
|
||||||
|
steps:
|
||||||
|
- name: Check out repository
|
||||||
|
uses: actions/checkout@v6
|
||||||
|
- name: Prepare test
|
||||||
|
id: prepare-test
|
||||||
|
uses: ./.github/actions/prepare-test
|
||||||
|
with:
|
||||||
|
version: ${{ matrix.version }}
|
||||||
|
use-all-platform-bundle: 'false'
|
||||||
|
setup-kotlin: 'true'
|
||||||
|
- uses: ./../action/init
|
||||||
|
id: init
|
||||||
|
with:
|
||||||
|
languages: javascript
|
||||||
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
|
|
||||||
|
- uses: ./../action/analyze
|
||||||
|
id: analysis
|
||||||
|
with:
|
||||||
|
upload-database: false
|
||||||
|
|
||||||
|
env:
|
||||||
|
CODEQL_ACTION_ANALYSIS_KEY: dynamic/copilot-pull-request-reviewer/codeql-action-test
|
||||||
|
CODEQL_ACTION_TEST_MODE: true
|
||||||
+2
-2
@@ -28,8 +28,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: cleanup-db-cluster-dir-${{github.ref}}
|
||||||
jobs:
|
jobs:
|
||||||
cleanup-db-cluster-dir:
|
cleanup-db-cluster-dir:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
Generated
+2
-2
@@ -28,8 +28,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: config-export-${{github.ref}}
|
||||||
jobs:
|
jobs:
|
||||||
config-export:
|
config-export:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
Generated
+2
-2
@@ -28,8 +28,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: config-input-${{github.ref}}
|
||||||
jobs:
|
jobs:
|
||||||
config-input:
|
config-input:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+2
-2
@@ -28,8 +28,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: cpp-deptrace-disabled-${{github.ref}}
|
||||||
jobs:
|
jobs:
|
||||||
cpp-deptrace-disabled:
|
cpp-deptrace-disabled:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+2
-2
@@ -28,8 +28,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: cpp-deptrace-enabled-on-macos-${{github.ref}}
|
||||||
jobs:
|
jobs:
|
||||||
cpp-deptrace-enabled-on-macos:
|
cpp-deptrace-enabled-on-macos:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+2
-2
@@ -28,8 +28,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: cpp-deptrace-enabled-${{github.ref}}
|
||||||
jobs:
|
jobs:
|
||||||
cpp-deptrace-enabled:
|
cpp-deptrace-enabled:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+2
-2
@@ -28,8 +28,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: diagnostics-export-${{github.ref}}
|
||||||
jobs:
|
jobs:
|
||||||
diagnostics-export:
|
diagnostics-export:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+4
-2
@@ -48,8 +48,9 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group:
|
||||||
|
export-file-baseline-information-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
||||||
jobs:
|
jobs:
|
||||||
export-file-baseline-information:
|
export-file-baseline-information:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -124,5 +125,6 @@ jobs:
|
|||||||
fi
|
fi
|
||||||
done
|
done
|
||||||
env:
|
env:
|
||||||
|
CODEQL_ACTION_SKIP_FILE_COVERAGE_ON_PRS: false
|
||||||
CODEQL_ACTION_SUBLANGUAGE_FILE_COVERAGE: true
|
CODEQL_ACTION_SUBLANGUAGE_FILE_COVERAGE: true
|
||||||
CODEQL_ACTION_TEST_MODE: true
|
CODEQL_ACTION_TEST_MODE: true
|
||||||
|
|||||||
+2
-2
@@ -28,8 +28,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: extractor-ram-threads-${{github.ref}}
|
||||||
jobs:
|
jobs:
|
||||||
extractor-ram-threads:
|
extractor-ram-threads:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
Generated
+3
-14
@@ -28,8 +28,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: global-proxy-${{github.ref}}
|
||||||
jobs:
|
jobs:
|
||||||
global-proxy:
|
global-proxy:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -48,18 +48,6 @@ jobs:
|
|||||||
timeout-minutes: 45
|
timeout-minutes: 45
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
# These steps are required to initialise the `gh` cli in a container that doesn't
|
|
||||||
# come pre-installed with it. The reason for that is that this is later
|
|
||||||
# needed by the `prepare-test` workflow to find the latest release of CodeQL.
|
|
||||||
- name: Set up GitHub CLI
|
|
||||||
run: |
|
|
||||||
apt update
|
|
||||||
apt install -y curl libreadline8 gnupg2 software-properties-common zstd
|
|
||||||
curl -fsSL https://cli.github.com/packages/githubcli-archive-keyring.gpg | dd of=/usr/share/keyrings/githubcli-archive-keyring.gpg
|
|
||||||
apt-key add /usr/share/keyrings/githubcli-archive-keyring.gpg
|
|
||||||
apt-add-repository https://cli.github.com/packages
|
|
||||||
apt install -y gh
|
|
||||||
env: {}
|
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v6
|
||||||
- name: Prepare test
|
- name: Prepare test
|
||||||
@@ -76,6 +64,7 @@ jobs:
|
|||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
env:
|
env:
|
||||||
https_proxy: http://squid-proxy:3128
|
https_proxy: http://squid-proxy:3128
|
||||||
|
CODEQL_ACTION_TOLERATE_MISSING_GIT_VERSION: true
|
||||||
CODEQL_ACTION_TEST_MODE: true
|
CODEQL_ACTION_TEST_MODE: true
|
||||||
container:
|
container:
|
||||||
image: ubuntu:22.04
|
image: ubuntu:22.04
|
||||||
|
|||||||
+3
-2
@@ -48,8 +48,9 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group:
|
||||||
|
go-custom-queries-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
||||||
jobs:
|
jobs:
|
||||||
go-custom-queries:
|
go-custom-queries:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
@@ -38,8 +38,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: go-indirect-tracing-workaround-diagnostic-${{github.ref}}-${{inputs.go-version}}
|
||||||
jobs:
|
jobs:
|
||||||
go-indirect-tracing-workaround-diagnostic:
|
go-indirect-tracing-workaround-diagnostic:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
@@ -38,8 +38,9 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group:
|
||||||
|
go-indirect-tracing-workaround-no-file-program-${{github.ref}}-${{inputs.go-version}}
|
||||||
jobs:
|
jobs:
|
||||||
go-indirect-tracing-workaround-no-file-program:
|
go-indirect-tracing-workaround-no-file-program:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+2
-2
@@ -38,8 +38,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: go-indirect-tracing-workaround-${{github.ref}}-${{inputs.go-version}}
|
||||||
jobs:
|
jobs:
|
||||||
go-indirect-tracing-workaround:
|
go-indirect-tracing-workaround:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+2
-2
@@ -38,8 +38,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: go-tracing-autobuilder-${{github.ref}}-${{inputs.go-version}}
|
||||||
jobs:
|
jobs:
|
||||||
go-tracing-autobuilder:
|
go-tracing-autobuilder:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+2
-2
@@ -38,8 +38,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: go-tracing-custom-build-steps-${{github.ref}}-${{inputs.go-version}}
|
||||||
jobs:
|
jobs:
|
||||||
go-tracing-custom-build-steps:
|
go-tracing-custom-build-steps:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+2
-2
@@ -38,8 +38,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: go-tracing-legacy-workflow-${{github.ref}}-${{inputs.go-version}}
|
||||||
jobs:
|
jobs:
|
||||||
go-tracing-legacy-workflow:
|
go-tracing-legacy-workflow:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+2
-2
@@ -28,8 +28,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: init-with-registries-${{github.ref}}
|
||||||
jobs:
|
jobs:
|
||||||
init-with-registries:
|
init-with-registries:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+2
-2
@@ -28,8 +28,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: javascript-source-root-${{github.ref}}
|
||||||
jobs:
|
jobs:
|
||||||
javascript-source-root:
|
javascript-source-root:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+2
-2
@@ -28,8 +28,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: job-run-uuid-sarif-${{github.ref}}
|
||||||
jobs:
|
jobs:
|
||||||
job-run-uuid-sarif:
|
job-run-uuid-sarif:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
Generated
+2
-2
@@ -28,8 +28,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: language-aliases-${{github.ref}}
|
||||||
jobs:
|
jobs:
|
||||||
language-aliases:
|
language-aliases:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
Generated
+3
-2
@@ -58,8 +58,9 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group:
|
||||||
|
local-bundle-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
||||||
jobs:
|
jobs:
|
||||||
local-bundle:
|
local-bundle:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+3
-2
@@ -58,8 +58,9 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group:
|
||||||
|
multi-language-autodetect-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
||||||
jobs:
|
jobs:
|
||||||
multi-language-autodetect:
|
multi-language-autodetect:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+2
-2
@@ -28,8 +28,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: overlay-init-fallback-${{github.ref}}
|
||||||
jobs:
|
jobs:
|
||||||
overlay-init-fallback:
|
overlay-init-fallback:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
@@ -58,8 +58,9 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group:
|
||||||
|
packaging-codescanning-config-inputs-js-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
||||||
jobs:
|
jobs:
|
||||||
packaging-codescanning-config-inputs-js:
|
packaging-codescanning-config-inputs-js:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+3
-2
@@ -48,8 +48,9 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group:
|
||||||
|
packaging-config-inputs-js-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
||||||
jobs:
|
jobs:
|
||||||
packaging-config-inputs-js:
|
packaging-config-inputs-js:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+3
-2
@@ -48,8 +48,9 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group:
|
||||||
|
packaging-config-js-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
||||||
jobs:
|
jobs:
|
||||||
packaging-config-js:
|
packaging-config-js:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+3
-2
@@ -48,8 +48,9 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group:
|
||||||
|
packaging-inputs-js-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
||||||
jobs:
|
jobs:
|
||||||
packaging-inputs-js:
|
packaging-inputs-js:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
Generated
+2
-2
@@ -28,8 +28,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: quality-queries-${{github.ref}}
|
||||||
jobs:
|
jobs:
|
||||||
quality-queries:
|
quality-queries:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
Generated
+3
-2
@@ -58,8 +58,9 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group:
|
||||||
|
remote-config-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
||||||
jobs:
|
jobs:
|
||||||
remote-config:
|
remote-config:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+2
-2
@@ -28,8 +28,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: resolve-environment-action-${{github.ref}}
|
||||||
jobs:
|
jobs:
|
||||||
resolve-environment-action:
|
resolve-environment-action:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+3
-3
@@ -28,8 +28,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: rubocop-multi-language-${{github.ref}}
|
||||||
jobs:
|
jobs:
|
||||||
rubocop-multi-language:
|
rubocop-multi-language:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -56,7 +56,7 @@ jobs:
|
|||||||
use-all-platform-bundle: 'false'
|
use-all-platform-bundle: 'false'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- name: Set up Ruby
|
- name: Set up Ruby
|
||||||
uses: ruby/setup-ruby@ac793fdd38cc468a4dd57246fa9d0e868aba9085 # v1.270.0
|
uses: ruby/setup-ruby@90be1154f987f4dc0fe0dd0feedac9e473aa4ba8 # v1.286.0
|
||||||
with:
|
with:
|
||||||
ruby-version: 2.6
|
ruby-version: 2.6
|
||||||
- name: Install Code Scanning integration
|
- name: Install Code Scanning integration
|
||||||
|
|||||||
Generated
+2
-2
@@ -28,8 +28,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: ruby-${{github.ref}}
|
||||||
jobs:
|
jobs:
|
||||||
ruby:
|
ruby:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
Generated
+2
-2
@@ -28,8 +28,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: rust-${{github.ref}}
|
||||||
jobs:
|
jobs:
|
||||||
rust:
|
rust:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
Generated
+2
-2
@@ -48,8 +48,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: split-workflow-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
||||||
jobs:
|
jobs:
|
||||||
split-workflow:
|
split-workflow:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
Generated
+2
-2
@@ -28,8 +28,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: start-proxy-${{github.ref}}
|
||||||
jobs:
|
jobs:
|
||||||
start-proxy:
|
start-proxy:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+2
-2
@@ -28,8 +28,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: submit-sarif-failure-${{github.ref}}
|
||||||
jobs:
|
jobs:
|
||||||
submit-sarif-failure:
|
submit-sarif-failure:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
Generated
+2
-2
@@ -28,8 +28,8 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group: swift-autobuild-${{github.ref}}
|
||||||
jobs:
|
jobs:
|
||||||
swift-autobuild:
|
swift-autobuild:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+3
-2
@@ -48,8 +48,9 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group:
|
||||||
|
swift-custom-build-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
||||||
jobs:
|
jobs:
|
||||||
swift-custom-build:
|
swift-custom-build:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+3
-2
@@ -58,8 +58,9 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group:
|
||||||
|
unset-environment-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
||||||
jobs:
|
jobs:
|
||||||
unset-environment:
|
unset-environment:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+3
-2
@@ -58,8 +58,9 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group:
|
||||||
|
upload-ref-sha-input-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
||||||
jobs:
|
jobs:
|
||||||
upload-ref-sha-input:
|
upload-ref-sha-input:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
Generated
+3
-2
@@ -58,8 +58,9 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group:
|
||||||
|
upload-sarif-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
||||||
jobs:
|
jobs:
|
||||||
upload-sarif:
|
upload-sarif:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
+3
-2
@@ -58,8 +58,9 @@ defaults:
|
|||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: ${{ github.workflow }}-${{ github.ref }}
|
group:
|
||||||
|
with-checkout-path-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
||||||
jobs:
|
jobs:
|
||||||
with-checkout-path:
|
with-checkout-path:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
@@ -6,6 +6,11 @@ env:
|
|||||||
# Diff informed queries add an additional query filter which is not yet
|
# Diff informed queries add an additional query filter which is not yet
|
||||||
# taken into account by these tests.
|
# taken into account by these tests.
|
||||||
CODEQL_ACTION_DIFF_INFORMED_QUERIES: false
|
CODEQL_ACTION_DIFF_INFORMED_QUERIES: false
|
||||||
|
# Specify overlay enablement manually to ensure stability around the exclude-from-incremental
|
||||||
|
# query filter. Here we only enable for the default code scanning suite.
|
||||||
|
CODEQL_ACTION_OVERLAY_ANALYSIS: true
|
||||||
|
CODEQL_ACTION_OVERLAY_ANALYSIS_JAVASCRIPT: false
|
||||||
|
CODEQL_ACTION_OVERLAY_ANALYSIS_CODE_SCANNING_JAVASCRIPT: true
|
||||||
|
|
||||||
on:
|
on:
|
||||||
push:
|
push:
|
||||||
|
|||||||
@@ -58,6 +58,8 @@ jobs:
|
|||||||
uses: actions/setup-dotnet@v5
|
uses: actions/setup-dotnet@v5
|
||||||
with:
|
with:
|
||||||
dotnet-version: '9.x'
|
dotnet-version: '9.x'
|
||||||
|
- name: Assert best-effort artifact scan completed
|
||||||
|
uses: ./../action/.github/actions/verify-debug-artifact-scan-completed
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
|
|||||||
@@ -54,6 +54,8 @@ jobs:
|
|||||||
uses: actions/setup-dotnet@v5
|
uses: actions/setup-dotnet@v5
|
||||||
with:
|
with:
|
||||||
dotnet-version: '9.x'
|
dotnet-version: '9.x'
|
||||||
|
- name: Assert best-effort artifact scan completed
|
||||||
|
uses: ./../action/.github/actions/verify-debug-artifact-scan-completed
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
id: init
|
id: init
|
||||||
with:
|
with:
|
||||||
|
|||||||
@@ -123,24 +123,13 @@ jobs:
|
|||||||
- name: Prepare partial Changelog
|
- name: Prepare partial Changelog
|
||||||
env:
|
env:
|
||||||
PARTIAL_CHANGELOG: "${{ runner.temp }}/partial_changelog.md"
|
PARTIAL_CHANGELOG: "${{ runner.temp }}/partial_changelog.md"
|
||||||
VERSION: "${{ steps.getVersion.outputs.version }}"
|
|
||||||
run: |
|
run: |
|
||||||
python .github/workflows/script/prepare_changelog.py CHANGELOG.md "$VERSION" > $PARTIAL_CHANGELOG
|
python .github/workflows/script/prepare_changelog.py CHANGELOG.md > $PARTIAL_CHANGELOG
|
||||||
|
|
||||||
echo "::group::Partial CHANGELOG"
|
echo "::group::Partial CHANGELOG"
|
||||||
cat $PARTIAL_CHANGELOG
|
cat $PARTIAL_CHANGELOG
|
||||||
echo "::endgroup::"
|
echo "::endgroup::"
|
||||||
|
|
||||||
- name: Create mergeback branch and PR
|
|
||||||
if: ${{ steps.check.outputs.exists != 'true' && endsWith(github.ref_name, steps.getVersion.outputs.latest_release_branch) }}
|
|
||||||
uses: ./.github/actions/prepare-mergeback-branch
|
|
||||||
with:
|
|
||||||
base: "${{ env.BASE_BRANCH }}"
|
|
||||||
head: "${{ env.HEAD_BRANCH }}"
|
|
||||||
branch: "${{ steps.getVersion.outputs.newBranch }}"
|
|
||||||
version: "${{ steps.getVersion.outputs.version }}"
|
|
||||||
token: "${{ secrets.GITHUB_TOKEN }}"
|
|
||||||
|
|
||||||
- name: Generate token
|
- name: Generate token
|
||||||
uses: actions/create-github-app-token@v2.2.1
|
uses: actions/create-github-app-token@v2.2.1
|
||||||
id: app-token
|
id: app-token
|
||||||
@@ -161,3 +150,13 @@ jobs:
|
|||||||
--latest=false \
|
--latest=false \
|
||||||
--title "$VERSION" \
|
--title "$VERSION" \
|
||||||
--notes-file "$PARTIAL_CHANGELOG"
|
--notes-file "$PARTIAL_CHANGELOG"
|
||||||
|
|
||||||
|
- name: Create mergeback branch and PR
|
||||||
|
if: ${{ endsWith(github.ref_name, steps.getVersion.outputs.latest_release_branch) }}
|
||||||
|
uses: ./.github/actions/prepare-mergeback-branch
|
||||||
|
with:
|
||||||
|
base: "${{ env.BASE_BRANCH }}"
|
||||||
|
head: "${{ env.HEAD_BRANCH }}"
|
||||||
|
branch: "${{ steps.getVersion.outputs.newBranch }}"
|
||||||
|
version: "${{ steps.getVersion.outputs.version }}"
|
||||||
|
token: "${{ secrets.GITHUB_TOKEN }}"
|
||||||
|
|||||||
@@ -127,9 +127,8 @@ jobs:
|
|||||||
env:
|
env:
|
||||||
NEW_CHANGELOG: "${{ runner.temp }}/new_changelog.md"
|
NEW_CHANGELOG: "${{ runner.temp }}/new_changelog.md"
|
||||||
PARTIAL_CHANGELOG: "${{ runner.temp }}/partial_changelog.md"
|
PARTIAL_CHANGELOG: "${{ runner.temp }}/partial_changelog.md"
|
||||||
VERSION: "${{ needs.prepare.outputs.version }}"
|
|
||||||
run: |
|
run: |
|
||||||
python .github/workflows/script/prepare_changelog.py $NEW_CHANGELOG "$VERSION" > $PARTIAL_CHANGELOG
|
python .github/workflows/script/prepare_changelog.py $NEW_CHANGELOG > $PARTIAL_CHANGELOG
|
||||||
|
|
||||||
echo "::group::Partial CHANGELOG"
|
echo "::group::Partial CHANGELOG"
|
||||||
cat $PARTIAL_CHANGELOG
|
cat $PARTIAL_CHANGELOG
|
||||||
|
|||||||
Regular → Executable
+6
-1
@@ -1,9 +1,14 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
import os
|
import os
|
||||||
import re
|
import re
|
||||||
|
|
||||||
|
cli_version = os.environ['CLI_VERSION']
|
||||||
|
|
||||||
|
# The GitHub Release for the new bundle version.
|
||||||
|
bundle_release_url = f"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v{cli_version}"
|
||||||
# Get the PR number from the PR URL.
|
# Get the PR number from the PR URL.
|
||||||
pr_number = os.environ['PR_URL'].split('/')[-1]
|
pr_number = os.environ['PR_URL'].split('/')[-1]
|
||||||
changelog_note = f"- Update default CodeQL bundle version to {os.environ['CLI_VERSION']}. [#{pr_number}]({os.environ['PR_URL']})"
|
changelog_note = f"- Update default CodeQL bundle version to [{cli_version}]({bundle_release_url}). [#{pr_number}]({os.environ['PR_URL']})"
|
||||||
|
|
||||||
# If the "[UNRELEASED]" section starts with "no user facing changes", remove that line.
|
# If the "[UNRELEASED]" section starts with "no user facing changes", remove that line.
|
||||||
with open('CHANGELOG.md', 'r') as f:
|
with open('CHANGELOG.md', 'r') as f:
|
||||||
|
|||||||
Regular → Executable
+10
-12
@@ -1,3 +1,4 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
import os
|
import os
|
||||||
import sys
|
import sys
|
||||||
|
|
||||||
@@ -6,7 +7,7 @@ EMPTY_CHANGELOG = 'No changes.\n\n'
|
|||||||
# Prepare the changelog for the new release
|
# Prepare the changelog for the new release
|
||||||
# This function will extract the part of the changelog that
|
# This function will extract the part of the changelog that
|
||||||
# we want to include in the new release.
|
# we want to include in the new release.
|
||||||
def extract_changelog_snippet(changelog_file, version_tag):
|
def extract_changelog_snippet(changelog_file):
|
||||||
output = ''
|
output = ''
|
||||||
if (not os.path.exists(changelog_file)):
|
if (not os.path.exists(changelog_file)):
|
||||||
output = EMPTY_CHANGELOG
|
output = EMPTY_CHANGELOG
|
||||||
@@ -15,23 +16,20 @@ def extract_changelog_snippet(changelog_file, version_tag):
|
|||||||
with open(changelog_file, 'r') as f:
|
with open(changelog_file, 'r') as f:
|
||||||
lines = f.readlines()
|
lines = f.readlines()
|
||||||
|
|
||||||
# Include everything up to, but excluding the second heading
|
# Include only the contents of the first section
|
||||||
found_first_section = False
|
found_first_section = False
|
||||||
for i, line in enumerate(lines):
|
for line in lines:
|
||||||
if line.startswith('## '):
|
if line.startswith('## '):
|
||||||
if found_first_section:
|
if found_first_section:
|
||||||
break
|
break
|
||||||
found_first_section = True
|
found_first_section = True
|
||||||
output += line
|
elif found_first_section:
|
||||||
|
output += line
|
||||||
|
|
||||||
output += f"See the full [CHANGELOG.md](https://github.com/github/codeql-action/blob/{version_tag}/CHANGELOG.md) for more information."
|
return output.strip()
|
||||||
|
|
||||||
return output
|
|
||||||
|
|
||||||
|
|
||||||
if len(sys.argv) < 3:
|
if len(sys.argv) < 2:
|
||||||
raise Exception('Expecting argument: changelog_file version_tag')
|
raise Exception('Expecting argument: changelog_file')
|
||||||
changelog_file = sys.argv[1]
|
changelog_file = sys.argv[1]
|
||||||
version_tag = sys.argv[2]
|
print(extract_changelog_snippet(changelog_file))
|
||||||
|
|
||||||
print(extract_changelog_snippet(changelog_file, version_tag))
|
|
||||||
|
|||||||
@@ -57,6 +57,24 @@ jobs:
|
|||||||
- name: Update bundle
|
- name: Update bundle
|
||||||
uses: ./.github/actions/update-bundle
|
uses: ./.github/actions/update-bundle
|
||||||
|
|
||||||
|
- name: Bump Action minor version if new CodeQL minor version series
|
||||||
|
id: bump-action-version
|
||||||
|
run: |
|
||||||
|
prior_cli_version=$(jq -r '.priorCliVersion' src/defaults.json)
|
||||||
|
cli_version=$(jq -r '.cliVersion' src/defaults.json)
|
||||||
|
|
||||||
|
prior_minor=$(echo "$prior_cli_version" | cut -d. -f2)
|
||||||
|
current_minor=$(echo "$cli_version" | cut -d. -f2)
|
||||||
|
|
||||||
|
if [[ "$current_minor" != "$prior_minor" ]]; then
|
||||||
|
echo "New CodeQL minor version series ($prior_cli_version -> $cli_version), bumping Action minor version"
|
||||||
|
npm version minor --no-git-tag-version
|
||||||
|
echo "bumped=true" >> "$GITHUB_OUTPUT"
|
||||||
|
else
|
||||||
|
echo "Same minor version series ($prior_cli_version -> $cli_version), skipping Action version bump"
|
||||||
|
echo "bumped=false" >> "$GITHUB_OUTPUT"
|
||||||
|
fi
|
||||||
|
|
||||||
- name: Rebuild Action
|
- name: Rebuild Action
|
||||||
run: npm run build
|
run: npm run build
|
||||||
|
|
||||||
@@ -71,11 +89,19 @@ jobs:
|
|||||||
- name: Open pull request
|
- name: Open pull request
|
||||||
env:
|
env:
|
||||||
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
ACTION_VERSION_BUMPED: ${{ steps.bump-action-version.outputs.bumped }}
|
||||||
run: |
|
run: |
|
||||||
cli_version=$(jq -r '.cliVersion' src/defaults.json)
|
cli_version=$(jq -r '.cliVersion' src/defaults.json)
|
||||||
|
action_version=$(jq -r '.version' package.json)
|
||||||
|
|
||||||
|
pr_body="This pull request updates the default CodeQL bundle, as used with \`tools: linked\` and on GHES, to $cli_version."
|
||||||
|
if [[ "$ACTION_VERSION_BUMPED" == "true" ]]; then
|
||||||
|
pr_body+=$'\n\n'"Since this is a new CodeQL minor version series, this PR also bumps the Action version to $action_version."
|
||||||
|
fi
|
||||||
|
|
||||||
pr_url=$(gh pr create \
|
pr_url=$(gh pr create \
|
||||||
--title "Update default bundle to $cli_version" \
|
--title "Update default bundle to $cli_version" \
|
||||||
--body "This pull request updates the default CodeQL bundle, as used with \`tools: linked\` and on GHES, to $cli_version." \
|
--body "$pr_body" \
|
||||||
--assignee "$GITHUB_ACTOR" \
|
--assignee "$GITHUB_ACTOR" \
|
||||||
--draft \
|
--draft \
|
||||||
)
|
)
|
||||||
|
|||||||
@@ -2,6 +2,25 @@
|
|||||||
|
|
||||||
See the [releases page](https://github.com/github/codeql-action/releases) for the relevant changes to the CodeQL CLI and language packs.
|
See the [releases page](https://github.com/github/codeql-action/releases) for the relevant changes to the CodeQL CLI and language packs.
|
||||||
|
|
||||||
|
## [UNRELEASED]
|
||||||
|
|
||||||
|
No user facing changes.
|
||||||
|
|
||||||
|
## 4.32.0 - 26 Jan 2026
|
||||||
|
|
||||||
|
- Update default CodeQL bundle version to [2.24.0](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.0). [#3425](https://github.com/github/codeql-action/pull/3425)
|
||||||
|
|
||||||
|
## 4.31.11 - 23 Jan 2026
|
||||||
|
|
||||||
|
- When running a Default Setup workflow with [Actions debugging enabled](https://docs.github.com/en/actions/how-tos/monitor-workflows/enable-debug-logging), the CodeQL Action will now use more unique names when uploading logs from the Dependabot authentication proxy as workflow artifacts. This ensures that the artifact names do not clash between multiple jobs in a build matrix. [#3409](https://github.com/github/codeql-action/pull/3409)
|
||||||
|
- Improved error handling throughout the CodeQL Action. [#3415](https://github.com/github/codeql-action/pull/3415)
|
||||||
|
- Added experimental support for automatically excluding [generated files](https://docs.github.com/en/repositories/working-with-files/managing-files/customizing-how-changed-files-appear-on-github) from the analysis. This feature is not currently enabled for any analysis. In the future, it may be enabled by default for some GitHub-managed analyses. [#3318](https://github.com/github/codeql-action/pull/3318)
|
||||||
|
- The changelog extracts that are included with releases of the CodeQL Action are now shorter to avoid duplicated information from appearing in Dependabot PRs. [#3403](https://github.com/github/codeql-action/pull/3403)
|
||||||
|
|
||||||
|
## 4.31.10 - 12 Jan 2026
|
||||||
|
|
||||||
|
- Update default CodeQL bundle version to 2.23.9. [#3393](https://github.com/github/codeql-action/pull/3393)
|
||||||
|
|
||||||
## 4.31.9 - 16 Dec 2025
|
## 4.31.9 - 16 Dec 2025
|
||||||
|
|
||||||
No user facing changes.
|
No user facing changes.
|
||||||
|
|||||||
+4
-1
@@ -78,7 +78,7 @@ export default [
|
|||||||
|
|
||||||
typescript: {},
|
typescript: {},
|
||||||
},
|
},
|
||||||
"import/ignore": ["sinon", "uuid", "@octokit/plugin-retry", "del", "get-folder-size"],
|
"import/ignore": ["sinon", "uuid", "@octokit/plugin-retry", "del", "get-folder-size", "@actions/github"],
|
||||||
},
|
},
|
||||||
|
|
||||||
rules: {
|
rules: {
|
||||||
@@ -152,9 +152,12 @@ export default [
|
|||||||
|
|
||||||
rules: {
|
rules: {
|
||||||
"@typescript-eslint/no-explicit-any": "off",
|
"@typescript-eslint/no-explicit-any": "off",
|
||||||
|
"@typescript-eslint/no-unsafe-argument": "off",
|
||||||
"@typescript-eslint/no-unsafe-assignment": "off",
|
"@typescript-eslint/no-unsafe-assignment": "off",
|
||||||
|
"@typescript-eslint/no-unsafe-call": "off",
|
||||||
"@typescript-eslint/no-unsafe-enum-comparison": "off",
|
"@typescript-eslint/no-unsafe-enum-comparison": "off",
|
||||||
"@typescript-eslint/no-unsafe-member-access": "off",
|
"@typescript-eslint/no-unsafe-member-access": "off",
|
||||||
|
"@typescript-eslint/no-unsafe-return": "off",
|
||||||
"@typescript-eslint/no-var-requires": "off",
|
"@typescript-eslint/no-var-requires": "off",
|
||||||
"@typescript-eslint/prefer-regexp-exec": "off",
|
"@typescript-eslint/prefer-regexp-exec": "off",
|
||||||
"@typescript-eslint/require-await": "off",
|
"@typescript-eslint/require-await": "off",
|
||||||
|
|||||||
Generated
+114550
-88029
File diff suppressed because one or more lines are too long
Generated
+42796
-22417
File diff suppressed because one or more lines are too long
Generated
+42632
-21184
File diff suppressed because one or more lines are too long
+4
-4
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"bundleVersion": "codeql-bundle-v2.23.8",
|
"bundleVersion": "codeql-bundle-v2.24.0",
|
||||||
"cliVersion": "2.23.8",
|
"cliVersion": "2.24.0",
|
||||||
"priorBundleVersion": "codeql-bundle-v2.23.7",
|
"priorBundleVersion": "codeql-bundle-v2.23.9",
|
||||||
"priorCliVersion": "2.23.7"
|
"priorCliVersion": "2.23.9"
|
||||||
}
|
}
|
||||||
|
|||||||
Generated
+115030
-88440
File diff suppressed because one or more lines are too long
Generated
+43672
-23082
File diff suppressed because one or more lines are too long
Generated
+42612
-21172
File diff suppressed because one or more lines are too long
Generated
+42638
-21190
File diff suppressed because one or more lines are too long
Generated
+113535
-86989
File diff suppressed because one or more lines are too long
Generated
+42653
-20396
File diff suppressed because one or more lines are too long
Generated
+42588
-21178
File diff suppressed because one or more lines are too long
Generated
+106776
-80264
File diff suppressed because one or more lines are too long
Generated
+42655
-21204
File diff suppressed because one or more lines are too long
Generated
+1029
-1116
File diff suppressed because it is too large
Load Diff
+14
-14
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "codeql",
|
"name": "codeql",
|
||||||
"version": "4.31.9",
|
"version": "4.32.1",
|
||||||
"private": true,
|
"private": true,
|
||||||
"description": "CodeQL action",
|
"description": "CodeQL action",
|
||||||
"scripts": {
|
"scripts": {
|
||||||
@@ -24,17 +24,17 @@
|
|||||||
},
|
},
|
||||||
"license": "MIT",
|
"license": "MIT",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@actions/artifact": "^4.0.0",
|
"@actions/artifact": "^5.0.2",
|
||||||
"@actions/artifact-legacy": "npm:@actions/artifact@^1.1.2",
|
"@actions/artifact-legacy": "npm:@actions/artifact@^1.1.2",
|
||||||
"@actions/cache": "^4.1.0",
|
"@actions/cache": "^5.0.3",
|
||||||
"@actions/core": "^1.11.1",
|
"@actions/core": "^2.0.2",
|
||||||
"@actions/exec": "^1.1.1",
|
"@actions/exec": "^2.0.0",
|
||||||
"@actions/github": "^6.0.0",
|
"@actions/github": "^9.0.0",
|
||||||
"@actions/glob": "^0.5.0",
|
"@actions/glob": "^0.5.0",
|
||||||
"@actions/http-client": "^3.0.0",
|
"@actions/http-client": "^3.0.0",
|
||||||
"@actions/io": "^2.0.0",
|
"@actions/io": "^2.0.0",
|
||||||
"@actions/tool-cache": "^2.0.2",
|
"@actions/tool-cache": "^3.0.0",
|
||||||
"@octokit/plugin-retry": "^6.0.0",
|
"@octokit/plugin-retry": "^8.0.0",
|
||||||
"@schemastore/package": "0.0.10",
|
"@schemastore/package": "0.0.10",
|
||||||
"archiver": "^7.0.1",
|
"archiver": "^7.0.1",
|
||||||
"fast-deep-equal": "^3.1.3",
|
"fast-deep-equal": "^3.1.3",
|
||||||
@@ -49,9 +49,9 @@
|
|||||||
},
|
},
|
||||||
"devDependencies": {
|
"devDependencies": {
|
||||||
"@ava/typescript": "6.0.0",
|
"@ava/typescript": "6.0.0",
|
||||||
"@eslint/compat": "^2.0.0",
|
"@eslint/compat": "^2.0.1",
|
||||||
"@eslint/eslintrc": "^3.3.3",
|
"@eslint/eslintrc": "^3.3.3",
|
||||||
"@eslint/js": "^9.39.1",
|
"@eslint/js": "^9.39.2",
|
||||||
"@microsoft/eslint-formatter-sarif": "^3.1.0",
|
"@microsoft/eslint-formatter-sarif": "^3.1.0",
|
||||||
"@octokit/types": "^16.0.0",
|
"@octokit/types": "^16.0.0",
|
||||||
"@types/archiver": "^7.0.0",
|
"@types/archiver": "^7.0.0",
|
||||||
@@ -61,20 +61,20 @@
|
|||||||
"@types/node-forge": "^1.3.14",
|
"@types/node-forge": "^1.3.14",
|
||||||
"@types/semver": "^7.7.1",
|
"@types/semver": "^7.7.1",
|
||||||
"@types/sinon": "^21.0.0",
|
"@types/sinon": "^21.0.0",
|
||||||
"@typescript-eslint/eslint-plugin": "^8.48.1",
|
"@typescript-eslint/eslint-plugin": "^8.53.1",
|
||||||
"@typescript-eslint/parser": "^8.48.0",
|
"@typescript-eslint/parser": "^8.48.0",
|
||||||
"ava": "^6.4.1",
|
"ava": "^6.4.1",
|
||||||
"esbuild": "^0.27.1",
|
"esbuild": "^0.27.2",
|
||||||
"eslint": "^8.57.1",
|
"eslint": "^8.57.1",
|
||||||
"eslint-import-resolver-typescript": "^3.8.7",
|
"eslint-import-resolver-typescript": "^3.8.7",
|
||||||
"eslint-plugin-filenames": "^1.3.2",
|
"eslint-plugin-filenames": "^1.3.2",
|
||||||
"eslint-plugin-github": "^5.1.8",
|
"eslint-plugin-github": "^5.1.8",
|
||||||
"eslint-plugin-import": "2.29.1",
|
"eslint-plugin-import": "2.29.1",
|
||||||
"eslint-plugin-jsdoc": "^61.5.0",
|
"eslint-plugin-jsdoc": "^62.2.0",
|
||||||
"eslint-plugin-no-async-foreach": "^0.1.1",
|
"eslint-plugin-no-async-foreach": "^0.1.1",
|
||||||
"glob": "^11.1.0",
|
"glob": "^11.1.0",
|
||||||
"nock": "^14.0.10",
|
"nock": "^14.0.10",
|
||||||
"sinon": "^21.0.0",
|
"sinon": "^21.0.1",
|
||||||
"typescript": "^5.9.3"
|
"typescript": "^5.9.3"
|
||||||
},
|
},
|
||||||
"overrides": {
|
"overrides": {
|
||||||
|
|||||||
@@ -3,6 +3,7 @@ description: "An end-to-end integration test of a Java repository built using 'b
|
|||||||
operatingSystems: ["ubuntu", "windows"]
|
operatingSystems: ["ubuntu", "windows"]
|
||||||
versions: ["linked", "nightly-latest"]
|
versions: ["linked", "nightly-latest"]
|
||||||
installJava: "true"
|
installJava: "true"
|
||||||
|
installYq: "true"
|
||||||
steps:
|
steps:
|
||||||
- name: Set up Java test repo configuration
|
- name: Set up Java test repo configuration
|
||||||
run: |
|
run: |
|
||||||
@@ -18,11 +19,6 @@ steps:
|
|||||||
languages: java
|
languages: java
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
|
|
||||||
- name: Install yq
|
|
||||||
if: runner.os == 'Windows'
|
|
||||||
run: |
|
|
||||||
choco install yq -y
|
|
||||||
|
|
||||||
- name: Validate database build mode
|
- name: Validate database build mode
|
||||||
run: |
|
run: |
|
||||||
metadata_path="$RUNNER_TEMP/customDbLocation/java/codeql-database.yml"
|
metadata_path="$RUNNER_TEMP/customDbLocation/java/codeql-database.yml"
|
||||||
|
|||||||
@@ -0,0 +1,16 @@
|
|||||||
|
name: "CCR"
|
||||||
|
description: "A standard analysis in CCR mode"
|
||||||
|
env:
|
||||||
|
CODEQL_ACTION_ANALYSIS_KEY: "dynamic/copilot-pull-request-reviewer/codeql-action-test"
|
||||||
|
steps:
|
||||||
|
- uses: ./../action/init
|
||||||
|
id: init
|
||||||
|
with:
|
||||||
|
languages: javascript
|
||||||
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
|
|
||||||
|
- uses: ./../action/analyze
|
||||||
|
id: analysis
|
||||||
|
with:
|
||||||
|
upload-database: false
|
||||||
|
|
||||||
@@ -5,6 +5,7 @@ versions: ["nightly-latest"]
|
|||||||
installGo: true
|
installGo: true
|
||||||
installDotNet: true
|
installDotNet: true
|
||||||
env:
|
env:
|
||||||
|
CODEQL_ACTION_SKIP_FILE_COVERAGE_ON_PRS: false
|
||||||
CODEQL_ACTION_SUBLANGUAGE_FILE_COVERAGE: true
|
CODEQL_ACTION_SUBLANGUAGE_FILE_COVERAGE: true
|
||||||
steps:
|
steps:
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
|
|||||||
@@ -3,19 +3,6 @@ description: "Tests using a proxy specified by the https_proxy environment varia
|
|||||||
versions: ["linked", "nightly-latest"]
|
versions: ["linked", "nightly-latest"]
|
||||||
container:
|
container:
|
||||||
image: ubuntu:22.04
|
image: ubuntu:22.04
|
||||||
container-init-steps:
|
|
||||||
# These steps are required to initialise the `gh` cli in a container that doesn't
|
|
||||||
# come pre-installed with it. The reason for that is that this is later
|
|
||||||
# needed by the `prepare-test` workflow to find the latest release of CodeQL.
|
|
||||||
name: Set up GitHub CLI
|
|
||||||
run: |
|
|
||||||
apt update
|
|
||||||
apt install -y curl libreadline8 gnupg2 software-properties-common zstd
|
|
||||||
curl -fsSL https://cli.github.com/packages/githubcli-archive-keyring.gpg | dd of=/usr/share/keyrings/githubcli-archive-keyring.gpg
|
|
||||||
apt-key add /usr/share/keyrings/githubcli-archive-keyring.gpg
|
|
||||||
apt-add-repository https://cli.github.com/packages
|
|
||||||
apt install -y gh
|
|
||||||
env: {}
|
|
||||||
services:
|
services:
|
||||||
squid-proxy:
|
squid-proxy:
|
||||||
image: ubuntu/squid:latest
|
image: ubuntu/squid:latest
|
||||||
@@ -23,6 +10,7 @@ services:
|
|||||||
- 3128:3128
|
- 3128:3128
|
||||||
env:
|
env:
|
||||||
https_proxy: http://squid-proxy:3128
|
https_proxy: http://squid-proxy:3128
|
||||||
|
CODEQL_ACTION_TOLERATE_MISSING_GIT_VERSION: true
|
||||||
steps:
|
steps:
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
|
|||||||
@@ -4,7 +4,7 @@ description: "Tests using RuboCop to analyze a multi-language repository and the
|
|||||||
versions: ["default"]
|
versions: ["default"]
|
||||||
steps:
|
steps:
|
||||||
- name: Set up Ruby
|
- name: Set up Ruby
|
||||||
uses: ruby/setup-ruby@ac793fdd38cc468a4dd57246fa9d0e868aba9085 # v1.270.0
|
uses: ruby/setup-ruby@90be1154f987f4dc0fe0dd0feedac9e473aa4ba8 # v1.286.0
|
||||||
with:
|
with:
|
||||||
ruby-version: 2.6
|
ruby-version: 2.6
|
||||||
- name: Install Code Scanning integration
|
- name: Install Code Scanning integration
|
||||||
|
|||||||
+33
-4
@@ -1,7 +1,7 @@
|
|||||||
#!/usr/bin/env python
|
#!/usr/bin/env python
|
||||||
|
|
||||||
import ruamel.yaml
|
import ruamel.yaml
|
||||||
from ruamel.yaml.scalarstring import SingleQuotedScalarString
|
from ruamel.yaml.scalarstring import SingleQuotedScalarString, LiteralScalarString
|
||||||
import pathlib
|
import pathlib
|
||||||
import os
|
import os
|
||||||
|
|
||||||
@@ -223,6 +223,25 @@ for file in sorted((this_dir / 'checks').glob('*.yml')):
|
|||||||
}
|
}
|
||||||
})
|
})
|
||||||
|
|
||||||
|
installYq = is_truthy(checkSpecification.get('installYq', ''))
|
||||||
|
|
||||||
|
if installYq:
|
||||||
|
steps.append({
|
||||||
|
'name': 'Install yq',
|
||||||
|
'if': "runner.os == 'Windows'",
|
||||||
|
'env': {
|
||||||
|
'YQ_PATH': '${{ runner.temp }}/yq',
|
||||||
|
# This is essentially an arbitrary version of `yq`, which happened to be the one that
|
||||||
|
# `choco` fetched when we moved away from using that here.
|
||||||
|
# See https://github.com/github/codeql-action/pull/3423
|
||||||
|
'YQ_VERSION': 'v4.50.1'
|
||||||
|
},
|
||||||
|
'run': LiteralScalarString(
|
||||||
|
'gh release download --repo mikefarah/yq --pattern "yq_windows_amd64.exe" "$YQ_VERSION" -O "$YQ_PATH/yq.exe"\n'
|
||||||
|
'echo "$YQ_PATH" >> "$GITHUB_PATH"'
|
||||||
|
),
|
||||||
|
})
|
||||||
|
|
||||||
# If container initialisation steps are present in the check specification,
|
# If container initialisation steps are present in the check specification,
|
||||||
# make sure to execute them first.
|
# make sure to execute them first.
|
||||||
if 'container' in checkSpecification and 'container-init-steps' in checkSpecification:
|
if 'container' in checkSpecification and 'container-init-steps' in checkSpecification:
|
||||||
@@ -271,6 +290,10 @@ for file in sorted((this_dir / 'checks').glob('*.yml')):
|
|||||||
|
|
||||||
raw_file = this_dir.parent / ".github" / "workflows" / f"__{checkName}.yml.raw"
|
raw_file = this_dir.parent / ".github" / "workflows" / f"__{checkName}.yml.raw"
|
||||||
with open(raw_file, 'w', newline='\n') as output_stream:
|
with open(raw_file, 'w', newline='\n') as output_stream:
|
||||||
|
extraGroupName = ""
|
||||||
|
for inputName in workflowInputs.keys():
|
||||||
|
extraGroupName += "-${{inputs." + inputName + "}}"
|
||||||
|
|
||||||
writeHeader(output_stream)
|
writeHeader(output_stream)
|
||||||
yaml.dump({
|
yaml.dump({
|
||||||
'name': f"PR Check - {checkSpecification['name']}",
|
'name': f"PR Check - {checkSpecification['name']}",
|
||||||
@@ -305,9 +328,15 @@ for file in sorted((this_dir / 'checks').glob('*.yml')):
|
|||||||
# For other events, the new workflows should wait until earlier ones have finished.
|
# For other events, the new workflows should wait until earlier ones have finished.
|
||||||
# This should help reduce the number of concurrent workflows on the repo, and
|
# This should help reduce the number of concurrent workflows on the repo, and
|
||||||
# consequently the number of concurrent API requests.
|
# consequently the number of concurrent API requests.
|
||||||
'cancel-in-progress': "${{ github.event_name == 'pull_request' }}",
|
# Note, the `|| false` is intentional to rule out that this somehow ends up being
|
||||||
# The group is determined by the workflow name + the ref
|
# `true` since we observed workflows for non-`pull_request` events getting cancelled.
|
||||||
'group': "${{ github.workflow }}-${{ github.ref }}"
|
'cancel-in-progress': "${{ github.event_name == 'pull_request' || false }}",
|
||||||
|
# The group is determined by the workflow name, the ref, and the input values.
|
||||||
|
# The base name is hard-coded to avoid issues when the workflow is triggered by
|
||||||
|
# a `workflow_call` event (where `github.workflow` would be the name of the caller).
|
||||||
|
# The input values are added, since they may result in different behaviour for a
|
||||||
|
# given workflow on the same ref.
|
||||||
|
'group': checkName + "-${{github.ref}}" + extraGroupName
|
||||||
},
|
},
|
||||||
'jobs': {
|
'jobs': {
|
||||||
checkName: checkJob
|
checkName: checkJob
|
||||||
|
|||||||
@@ -5,6 +5,9 @@ import {
|
|||||||
fixCodeQualityCategory,
|
fixCodeQualityCategory,
|
||||||
getPullRequestBranches,
|
getPullRequestBranches,
|
||||||
isAnalyzingPullRequest,
|
isAnalyzingPullRequest,
|
||||||
|
isCCR,
|
||||||
|
isDefaultSetup,
|
||||||
|
isDynamicWorkflow,
|
||||||
} from "./actions-util";
|
} from "./actions-util";
|
||||||
import { computeAutomationID } from "./api-client";
|
import { computeAutomationID } from "./api-client";
|
||||||
import { EnvVar } from "./environment";
|
import { EnvVar } from "./environment";
|
||||||
@@ -246,3 +249,24 @@ test("fixCodeQualityCategory", (t) => {
|
|||||||
},
|
},
|
||||||
);
|
);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
test("isDynamicWorkflow() returns true if event name is `dynamic`", (t) => {
|
||||||
|
process.env.GITHUB_EVENT_NAME = "dynamic";
|
||||||
|
t.assert(isDynamicWorkflow());
|
||||||
|
process.env.GITHUB_EVENT_NAME = "push";
|
||||||
|
t.false(isDynamicWorkflow());
|
||||||
|
});
|
||||||
|
|
||||||
|
test("isCCR() returns true when expected", (t) => {
|
||||||
|
process.env.GITHUB_EVENT_NAME = "dynamic";
|
||||||
|
process.env[EnvVar.ANALYSIS_KEY] = "dynamic/copilot-pull-request-reviewer";
|
||||||
|
t.assert(isCCR());
|
||||||
|
t.false(isDefaultSetup());
|
||||||
|
});
|
||||||
|
|
||||||
|
test("isDefaultSetup() returns true when expected", (t) => {
|
||||||
|
process.env.GITHUB_EVENT_NAME = "dynamic";
|
||||||
|
process.env[EnvVar.ANALYSIS_KEY] = "dynamic/github-code-scanning";
|
||||||
|
t.assert(isDefaultSetup());
|
||||||
|
t.false(isCCR());
|
||||||
|
});
|
||||||
|
|||||||
+10
-1
@@ -8,6 +8,7 @@ import * as io from "@actions/io";
|
|||||||
import { JSONSchemaForNPMPackageJsonFiles } from "@schemastore/package";
|
import { JSONSchemaForNPMPackageJsonFiles } from "@schemastore/package";
|
||||||
|
|
||||||
import type { Config } from "./config-utils";
|
import type { Config } from "./config-utils";
|
||||||
|
import { EnvVar } from "./environment";
|
||||||
import { Logger } from "./logging";
|
import { Logger } from "./logging";
|
||||||
import {
|
import {
|
||||||
doesDirectoryExist,
|
doesDirectoryExist,
|
||||||
@@ -254,7 +255,15 @@ export function isDynamicWorkflow(): boolean {
|
|||||||
|
|
||||||
/** Determines whether we are running in default setup. */
|
/** Determines whether we are running in default setup. */
|
||||||
export function isDefaultSetup(): boolean {
|
export function isDefaultSetup(): boolean {
|
||||||
return isDynamicWorkflow();
|
return isDynamicWorkflow() && !isCCR();
|
||||||
|
}
|
||||||
|
|
||||||
|
/* The analysis key prefix used for CCR. */
|
||||||
|
const CCR_KEY_PREFIX = "dynamic/copilot-pull-request-reviewer";
|
||||||
|
|
||||||
|
/** Determines whether we are running in CCR. */
|
||||||
|
export function isCCR(): boolean {
|
||||||
|
return process.env[EnvVar.ANALYSIS_KEY]?.startsWith(CCR_KEY_PREFIX) || false;
|
||||||
}
|
}
|
||||||
|
|
||||||
export function prettyPrintInvocation(cmd: string, args: string[]): string {
|
export function prettyPrintInvocation(cmd: string, args: string[]): string {
|
||||||
|
|||||||
@@ -21,6 +21,9 @@ import { getActionsLogger } from "./logging";
|
|||||||
import { checkGitHubVersionInRange, getErrorMessage } from "./util";
|
import { checkGitHubVersionInRange, getErrorMessage } from "./util";
|
||||||
|
|
||||||
async function runWrapper() {
|
async function runWrapper() {
|
||||||
|
// To capture errors appropriately, keep as much code within the try-catch as
|
||||||
|
// possible, and only use safe functions outside.
|
||||||
|
|
||||||
try {
|
try {
|
||||||
actionsUtil.restoreInputs();
|
actionsUtil.restoreInputs();
|
||||||
const logger = getActionsLogger();
|
const logger = getActionsLogger();
|
||||||
|
|||||||
+22
-9
@@ -41,6 +41,7 @@ import {
|
|||||||
createStatusReportBase,
|
createStatusReportBase,
|
||||||
DatabaseCreationTimings,
|
DatabaseCreationTimings,
|
||||||
getActionsStatus,
|
getActionsStatus,
|
||||||
|
sendUnhandledErrorStatusReport,
|
||||||
StatusReportBase,
|
StatusReportBase,
|
||||||
} from "./status-report";
|
} from "./status-report";
|
||||||
import {
|
import {
|
||||||
@@ -208,8 +209,10 @@ async function runAutobuildIfLegacyGoWorkflow(config: Config, logger: Logger) {
|
|||||||
await runAutobuild(config, KnownLanguage.go, logger);
|
await runAutobuild(config, KnownLanguage.go, logger);
|
||||||
}
|
}
|
||||||
|
|
||||||
async function run() {
|
async function run(startedAt: Date) {
|
||||||
const startedAt = new Date();
|
// To capture errors appropriately, keep as much code within the try-catch as
|
||||||
|
// possible, and only use safe functions outside.
|
||||||
|
|
||||||
let uploadResults:
|
let uploadResults:
|
||||||
| Partial<Record<analyses.AnalysisKind, UploadResult>>
|
| Partial<Record<analyses.AnalysisKind, UploadResult>>
|
||||||
| undefined = undefined;
|
| undefined = undefined;
|
||||||
@@ -222,14 +225,15 @@ async function run() {
|
|||||||
let didUploadTrapCaches = false;
|
let didUploadTrapCaches = false;
|
||||||
let dependencyCacheResults: DependencyCacheUploadStatusReport | undefined;
|
let dependencyCacheResults: DependencyCacheUploadStatusReport | undefined;
|
||||||
let databaseUploadResults: DatabaseUploadResult[] = [];
|
let databaseUploadResults: DatabaseUploadResult[] = [];
|
||||||
util.initializeEnvironment(actionsUtil.getActionVersion());
|
|
||||||
|
|
||||||
// Make inputs accessible in the `post` step, details at
|
|
||||||
// https://github.com/github/codeql-action/issues/2553
|
|
||||||
actionsUtil.persistInputs();
|
|
||||||
|
|
||||||
const logger = getActionsLogger();
|
const logger = getActionsLogger();
|
||||||
|
|
||||||
try {
|
try {
|
||||||
|
util.initializeEnvironment(actionsUtil.getActionVersion());
|
||||||
|
|
||||||
|
// Make inputs accessible in the `post` step, details at
|
||||||
|
// https://github.com/github/codeql-action/issues/2553
|
||||||
|
actionsUtil.persistInputs();
|
||||||
|
|
||||||
const statusReportBase = await createStatusReportBase(
|
const statusReportBase = await createStatusReportBase(
|
||||||
ActionName.Analyze,
|
ActionName.Analyze,
|
||||||
"starting",
|
"starting",
|
||||||
@@ -522,13 +526,22 @@ async function run() {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
export const runPromise = run();
|
// Module-level startedAt so it can be accessed by runWrapper for error reporting
|
||||||
|
const startedAt = new Date();
|
||||||
|
export const runPromise = run(startedAt);
|
||||||
|
|
||||||
async function runWrapper() {
|
async function runWrapper() {
|
||||||
|
const logger = getActionsLogger();
|
||||||
try {
|
try {
|
||||||
await runPromise;
|
await runPromise;
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
core.setFailed(`analyze action failed: ${util.getErrorMessage(error)}`);
|
core.setFailed(`analyze action failed: ${util.getErrorMessage(error)}`);
|
||||||
|
await sendUnhandledErrorStatusReport(
|
||||||
|
ActionName.Analyze,
|
||||||
|
startedAt,
|
||||||
|
error,
|
||||||
|
logger,
|
||||||
|
);
|
||||||
}
|
}
|
||||||
await util.checkForTimeout();
|
await util.checkForTimeout();
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -87,7 +87,6 @@ test("status report fields", async (t) => {
|
|||||||
);
|
);
|
||||||
return "";
|
return "";
|
||||||
},
|
},
|
||||||
databasePrintBaseline: async () => "",
|
|
||||||
});
|
});
|
||||||
|
|
||||||
const config = createTestConfig({
|
const config = createTestConfig({
|
||||||
|
|||||||
+10
-2
@@ -495,10 +495,18 @@ export async function runQueries(
|
|||||||
endTimeInterpretResults.getTime() - startTimeInterpretResults.getTime();
|
endTimeInterpretResults.getTime() - startTimeInterpretResults.getTime();
|
||||||
logger.endGroup();
|
logger.endGroup();
|
||||||
|
|
||||||
logger.info(analysisSummary);
|
if (analysisSummary.trim()) {
|
||||||
if (qualityAnalysisSummary) {
|
logger.info(analysisSummary);
|
||||||
|
}
|
||||||
|
if (qualityAnalysisSummary?.trim()) {
|
||||||
logger.info(qualityAnalysisSummary);
|
logger.info(qualityAnalysisSummary);
|
||||||
}
|
}
|
||||||
|
if (!config.enableFileCoverageInformation) {
|
||||||
|
logger.info(
|
||||||
|
"To speed up pull request analysis, file coverage information is only enabled when analyzing " +
|
||||||
|
"the default branch and protected branches.",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
if (await features.getValue(Feature.QaTelemetryEnabled)) {
|
if (await features.getValue(Feature.QaTelemetryEnabled)) {
|
||||||
// Note: QA adds the `code-quality` query suite to the `queries` input,
|
// Note: QA adds the `code-quality` query suite to the `queries` input,
|
||||||
|
|||||||
@@ -52,7 +52,6 @@ function mockGetMetaVersionHeader(
|
|||||||
};
|
};
|
||||||
const spyGetContents = sinon
|
const spyGetContents = sinon
|
||||||
.stub(client.rest.meta, "get")
|
.stub(client.rest.meta, "get")
|
||||||
// eslint-disable-next-line @typescript-eslint/no-unsafe-argument
|
|
||||||
.resolves(response as any);
|
.resolves(response as any);
|
||||||
sinon.stub(api, "getApiClient").value(() => client);
|
sinon.stub(api, "getApiClient").value(() => client);
|
||||||
return spyGetContents;
|
return spyGetContents;
|
||||||
|
|||||||
+3
-5
@@ -3,6 +3,7 @@ import * as githubUtils from "@actions/github/lib/utils";
|
|||||||
import * as retry from "@octokit/plugin-retry";
|
import * as retry from "@octokit/plugin-retry";
|
||||||
|
|
||||||
import { getActionVersion, getRequiredInput } from "./actions-util";
|
import { getActionVersion, getRequiredInput } from "./actions-util";
|
||||||
|
import { EnvVar } from "./environment";
|
||||||
import { Logger } from "./logging";
|
import { Logger } from "./logging";
|
||||||
import { getRepositoryNwo, RepositoryNwo } from "./repository";
|
import { getRepositoryNwo, RepositoryNwo } from "./repository";
|
||||||
import {
|
import {
|
||||||
@@ -115,7 +116,6 @@ export async function getGitHubVersionFromApi(
|
|||||||
|
|
||||||
// Doesn't strictly have to be the meta endpoint as we're only
|
// Doesn't strictly have to be the meta endpoint as we're only
|
||||||
// using the response headers which are available on every request.
|
// using the response headers which are available on every request.
|
||||||
// eslint-disable-next-line @typescript-eslint/no-unsafe-call
|
|
||||||
const response = await apiClient.rest.meta.get();
|
const response = await apiClient.rest.meta.get();
|
||||||
|
|
||||||
// This happens on dotcom, although we expect to have already returned in that
|
// This happens on dotcom, although we expect to have already returned in that
|
||||||
@@ -189,9 +189,7 @@ export async function getWorkflowRelativePath(): Promise<string> {
|
|||||||
* the GitHub API, but after that the result will be cached.
|
* the GitHub API, but after that the result will be cached.
|
||||||
*/
|
*/
|
||||||
export async function getAnalysisKey(): Promise<string> {
|
export async function getAnalysisKey(): Promise<string> {
|
||||||
const analysisKeyEnvVar = "CODEQL_ACTION_ANALYSIS_KEY";
|
let analysisKey = process.env[EnvVar.ANALYSIS_KEY];
|
||||||
|
|
||||||
let analysisKey = process.env[analysisKeyEnvVar];
|
|
||||||
if (analysisKey !== undefined) {
|
if (analysisKey !== undefined) {
|
||||||
return analysisKey;
|
return analysisKey;
|
||||||
}
|
}
|
||||||
@@ -200,7 +198,7 @@ export async function getAnalysisKey(): Promise<string> {
|
|||||||
const jobName = getRequiredEnvParam("GITHUB_JOB");
|
const jobName = getRequiredEnvParam("GITHUB_JOB");
|
||||||
|
|
||||||
analysisKey = `${workflowPath}:${jobName}`;
|
analysisKey = `${workflowPath}:${jobName}`;
|
||||||
core.exportVariable(analysisKeyEnvVar, analysisKey);
|
core.exportVariable(EnvVar.ANALYSIS_KEY, analysisKey);
|
||||||
return analysisKey;
|
return analysisKey;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,183 @@
|
|||||||
|
import * as fs from "fs";
|
||||||
|
import * as os from "os";
|
||||||
|
import * as path from "path";
|
||||||
|
|
||||||
|
import test from "ava";
|
||||||
|
|
||||||
|
import {
|
||||||
|
GITHUB_PAT_CLASSIC_PATTERN,
|
||||||
|
isAuthToken,
|
||||||
|
scanArtifactsForTokens,
|
||||||
|
TokenType,
|
||||||
|
} from "./artifact-scanner";
|
||||||
|
import { getRunnerLogger } from "./logging";
|
||||||
|
import {
|
||||||
|
checkExpectedLogMessages,
|
||||||
|
getRecordingLogger,
|
||||||
|
LoggedMessage,
|
||||||
|
makeTestToken,
|
||||||
|
} from "./testing-utils";
|
||||||
|
|
||||||
|
test("makeTestToken", (t) => {
|
||||||
|
t.is(makeTestToken().length, 36);
|
||||||
|
t.is(makeTestToken(255).length, 255);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("isAuthToken", (t) => {
|
||||||
|
// Undefined for strings that aren't tokens
|
||||||
|
t.is(isAuthToken("some string"), undefined);
|
||||||
|
t.is(isAuthToken("ghp_"), undefined);
|
||||||
|
t.is(isAuthToken("ghp_123"), undefined);
|
||||||
|
|
||||||
|
// Token types for strings that are tokens.
|
||||||
|
t.is(isAuthToken(`ghp_${makeTestToken()}`), TokenType.PersonalAccessClassic);
|
||||||
|
t.is(isAuthToken(`ghp_${makeTestToken()}`), TokenType.PersonalAccessClassic);
|
||||||
|
t.is(
|
||||||
|
isAuthToken(`ghs_${makeTestToken(255)}`),
|
||||||
|
TokenType.AppInstallationAccess,
|
||||||
|
);
|
||||||
|
t.is(
|
||||||
|
isAuthToken(`github_pat_${makeTestToken(22)}_${makeTestToken(59)}`),
|
||||||
|
TokenType.PersonalAccessFineGrained,
|
||||||
|
);
|
||||||
|
|
||||||
|
// With a custom pattern set
|
||||||
|
t.is(
|
||||||
|
isAuthToken(`ghp_${makeTestToken()}`, [GITHUB_PAT_CLASSIC_PATTERN]),
|
||||||
|
TokenType.PersonalAccessClassic,
|
||||||
|
);
|
||||||
|
t.is(
|
||||||
|
isAuthToken(`github_pat_${makeTestToken(22)}_${makeTestToken(59)}`, [
|
||||||
|
GITHUB_PAT_CLASSIC_PATTERN,
|
||||||
|
]),
|
||||||
|
undefined,
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
const testTokens = [
|
||||||
|
{
|
||||||
|
type: TokenType.PersonalAccessClassic,
|
||||||
|
value: `ghp_${makeTestToken()}`,
|
||||||
|
checkPattern: "Personal Access Token",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
type: TokenType.PersonalAccessFineGrained,
|
||||||
|
value:
|
||||||
|
"github_pat_1234567890ABCDEFGHIJKL_MNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz1234567890ABCDEFGHI",
|
||||||
|
checkPattern: "Personal Access Token",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
type: TokenType.OAuth,
|
||||||
|
value: `gho_${makeTestToken()}`,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
type: TokenType.UserToServer,
|
||||||
|
value: `ghu_${makeTestToken()}`,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
type: TokenType.ServerToServer,
|
||||||
|
value: `ghs_${makeTestToken()}`,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
type: TokenType.Refresh,
|
||||||
|
value: `ghr_${makeTestToken()}`,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
type: TokenType.AppInstallationAccess,
|
||||||
|
value: `ghs_${makeTestToken(255)}`,
|
||||||
|
},
|
||||||
|
];
|
||||||
|
|
||||||
|
for (const { type, value, checkPattern } of testTokens) {
|
||||||
|
test(`scanArtifactsForTokens detects GitHub ${type} tokens in files`, async (t) => {
|
||||||
|
const logMessages = [];
|
||||||
|
const logger = getRecordingLogger(logMessages, { logToConsole: false });
|
||||||
|
const tempDir = fs.mkdtempSync(path.join(os.tmpdir(), "scanner-test-"));
|
||||||
|
|
||||||
|
try {
|
||||||
|
// Create a test file with a fake GitHub token
|
||||||
|
const testFile = path.join(tempDir, "test.txt");
|
||||||
|
fs.writeFileSync(testFile, `This is a test file with token ${value}`);
|
||||||
|
|
||||||
|
const error = await t.throwsAsync(
|
||||||
|
async () => await scanArtifactsForTokens([testFile], logger),
|
||||||
|
);
|
||||||
|
|
||||||
|
t.regex(
|
||||||
|
error?.message || "",
|
||||||
|
new RegExp(`Found 1 potential GitHub token.*${checkPattern || type}`),
|
||||||
|
);
|
||||||
|
t.regex(error?.message || "", /test\.txt/);
|
||||||
|
|
||||||
|
checkExpectedLogMessages(t, logMessages, [
|
||||||
|
"Starting best-effort check",
|
||||||
|
`Found 1 ${type}`,
|
||||||
|
]);
|
||||||
|
} finally {
|
||||||
|
// Clean up
|
||||||
|
fs.rmSync(tempDir, { recursive: true, force: true });
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
test("scanArtifactsForTokens handles files without tokens", async (t) => {
|
||||||
|
const logger = getRunnerLogger(true);
|
||||||
|
const tempDir = fs.mkdtempSync(path.join(os.tmpdir(), "scanner-test-"));
|
||||||
|
|
||||||
|
try {
|
||||||
|
// Create a test file without tokens
|
||||||
|
const testFile = path.join(tempDir, "test.txt");
|
||||||
|
fs.writeFileSync(
|
||||||
|
testFile,
|
||||||
|
"This is a test file without any sensitive data",
|
||||||
|
);
|
||||||
|
|
||||||
|
await t.notThrowsAsync(
|
||||||
|
async () => await scanArtifactsForTokens([testFile], logger),
|
||||||
|
);
|
||||||
|
} finally {
|
||||||
|
// Clean up
|
||||||
|
fs.rmSync(tempDir, { recursive: true, force: true });
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
if (os.platform() !== "win32") {
|
||||||
|
test("scanArtifactsForTokens finds token in debug artifacts", async (t) => {
|
||||||
|
t.timeout(15000); // 15 seconds
|
||||||
|
const messages: LoggedMessage[] = [];
|
||||||
|
const logger = getRecordingLogger(messages, { logToConsole: false });
|
||||||
|
// The zip here is a regression test based on
|
||||||
|
// https://github.com/github/codeql-action/security/advisories/GHSA-vqf5-2xx6-9wfm
|
||||||
|
const testZip = path.join(
|
||||||
|
__dirname,
|
||||||
|
"..",
|
||||||
|
"src",
|
||||||
|
"testdata",
|
||||||
|
"debug-artifacts-with-fake-token.zip",
|
||||||
|
);
|
||||||
|
|
||||||
|
// This zip file contains a nested structure with a fake token in:
|
||||||
|
// my-db-java-partial.zip/trap/java/invocations/kotlin.9017231652989744319.trap
|
||||||
|
const error = await t.throwsAsync(
|
||||||
|
async () => await scanArtifactsForTokens([testZip], logger),
|
||||||
|
);
|
||||||
|
|
||||||
|
t.regex(
|
||||||
|
error?.message || "",
|
||||||
|
/Found.*potential GitHub token/,
|
||||||
|
"Should detect token in nested zip",
|
||||||
|
);
|
||||||
|
t.regex(
|
||||||
|
error?.message || "",
|
||||||
|
/kotlin\.9017231652989744319\.trap/,
|
||||||
|
"Should report the .trap file containing the token",
|
||||||
|
);
|
||||||
|
|
||||||
|
const logOutput = messages.map((msg) => msg.message).join("\n");
|
||||||
|
t.regex(
|
||||||
|
logOutput,
|
||||||
|
/^Extracting gz file: .*\.gz$/m,
|
||||||
|
"Logs should show that .gz files were extracted",
|
||||||
|
);
|
||||||
|
});
|
||||||
|
}
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user