mirror of
https://github.com/github/codeql-action.git
synced 2026-08-05 21:06:13 -05:00
Compare commits
412 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 97837dd278 | |||
| 8b92d05ba7 | |||
| a899987af2 | |||
| 191d7c6f13 | |||
| aa69c483cd | |||
| fe775da508 | |||
| 353802f9f2 | |||
| cc7db4a1f9 | |||
| 6010f9d8e2 | |||
| c10b8064de | |||
| c5ffd06837 | |||
| d6d1743b8e | |||
| 999119ba45 | |||
| 65d2efa733 | |||
| 2437b20ab3 | |||
| f13c600724 | |||
| 7dcea06663 | |||
| ea5f71947c | |||
| 45ceeea896 | |||
| 24448c9843 | |||
| 7c51060631 | |||
| b8bb9f28b8 | |||
| e9cf68bb33 | |||
| 36791d8d66 | |||
| 22eba96a28 | |||
| 0078ad667e | |||
| fa7a15b909 | |||
| 8c29faa7ab | |||
| f94817b9f0 | |||
| dd060970a5 | |||
| 5cc552f43e | |||
| 6b1a9f2131 | |||
| 9d3ec5727a | |||
| 3ff82aacd0 | |||
| 4bdd4e7526 | |||
| 23a0098b57 | |||
| ea7b090925 | |||
| a663d0174a | |||
| b659882aae | |||
| d5bb39fa0b | |||
| 521c3536d3 | |||
| 972365e142 | |||
| 8a0b4f2746 | |||
| a5418e172c | |||
| fae4c28b51 | |||
| 661a8fbbe3 | |||
| e7c7b68c5f | |||
| fa568ebc69 | |||
| 0da3139813 | |||
| 0abe92ed20 | |||
| 07f235e5f2 | |||
| 9fd40ff508 | |||
| 75ed461aaa | |||
| cfc18781e0 | |||
| 9fe42f69b7 | |||
| c5a984e1aa | |||
| 0543156694 | |||
| 4cec5d2830 | |||
| 74dd691a45 | |||
| a5244bf7dd | |||
| 1bc611ed0c | |||
| d2008eee7c | |||
| 9481177f3d | |||
| 9813849e61 | |||
| 4867f5927a | |||
| 49af37b7ab | |||
| b72f4fec40 | |||
| 0d87a75829 | |||
| 3db9a05c73 | |||
| aa2773169b | |||
| 054745baee | |||
| 3d564d9359 | |||
| 137e0dec2b | |||
| d128e5daa8 | |||
| eedab83377 | |||
| 8c023a6b07 | |||
| 28f56f2bed | |||
| d48d054533 | |||
| 72c0b0efb7 | |||
| 05b1a5d28f | |||
| 8dc2e5d9d2 | |||
| 8fd6c0e573 | |||
| 3869755554 | |||
| 20e68ac12b | |||
| 095e0fe505 | |||
| 47b94fe61c | |||
| 51a1d6917f | |||
| 510cf736e3 | |||
| 89f0c86efa | |||
| c3f90ba975 | |||
| c6f931105c | |||
| eeb9b3f424 | |||
| 64507ed148 | |||
| 1a45a9b9d0 | |||
| 30c555a528 | |||
| 39191bd27f | |||
| 147e93e5dc | |||
| e6d83bce6d | |||
| 0d057ccbce | |||
| 074a0dbd16 | |||
| ab3b6fd199 | |||
| ce4a1feb6a | |||
| 899a672743 | |||
| f4be604881 | |||
| 0bc1b6f632 | |||
| 3d8036cf7f | |||
| 9fecf32c77 | |||
| 07d509fbaf | |||
| 23674c1f2a | |||
| ecd1c77ffa | |||
| 5b630489d6 | |||
| 582d08c553 | |||
| 60a0dce0ad | |||
| 7da6361ba5 | |||
| 08d1198b01 | |||
| 5e54629286 | |||
| f254006ed7 | |||
| 573e7dd341 | |||
| f88d49ee5d | |||
| 28f515d9ad | |||
| de06821112 | |||
| ddafddb826 | |||
| 740f177889 | |||
| 0393130759 | |||
| f86097dfdb | |||
| 6e67ef61f2 | |||
| 193dd19c2d | |||
| fd1ca02d0d | |||
| a0e3ed6555 | |||
| fbb2eb9556 | |||
| b1bff81932 | |||
| e682234222 | |||
| 95be291f41 | |||
| 59bcb6025e | |||
| 7dd76e6bf7 | |||
| e3200e331b | |||
| 4c356c71a2 | |||
| b4937c19e5 | |||
| 136b8ab377 | |||
| a5aba5952c | |||
| dafe74070a | |||
| fc8d303906 | |||
| 3bc3228be2 | |||
| b4cb1049fb | |||
| b171c1c6d9 | |||
| 967ca853e1 | |||
| 7950e47b7f | |||
| e608db4784 | |||
| 7df3db2b6f | |||
| b5e1fb009d | |||
| ea703668e0 | |||
| c183dca871 | |||
| a717db1a90 | |||
| 1dbebad653 | |||
| 82d7a77abc | |||
| 926e6dfee5 | |||
| b1f1e7bd31 | |||
| a91b7a3e57 | |||
| 0d0df94d93 | |||
| 373dec9f22 | |||
| 9771a765ac | |||
| 363219d88d | |||
| 556dd79c4b | |||
| 19544bb9b4 | |||
| d74701caa1 | |||
| d05b50b13f | |||
| 70d5cccce1 | |||
| b04e63ffdf | |||
| 378e4b367d | |||
| 309fd2aac7 | |||
| b0f877255d | |||
| 567ca73ff8 | |||
| 5f3f250f83 | |||
| 6fb1c2a300 | |||
| 44720043ea | |||
| f9f5edb76f | |||
| de2997a8c8 | |||
| 117bf916af | |||
| 30ecc82e64 | |||
| 4174779474 | |||
| 2bc06587aa | |||
| 6c99ca514e | |||
| 1a97b0f94e | |||
| d1a7580bd3 | |||
| 89f63211ed | |||
| 6570ad3440 | |||
| be7fe2bca6 | |||
| 2e1f08fe70 | |||
| b9b42bed94 | |||
| 997acaf7eb | |||
| 2e7e91fd63 | |||
| 5cb13d6ab8 | |||
| a63886bff5 | |||
| a11c6cbbc8 | |||
| 048d0ea295 | |||
| cf972cde0e | |||
| ee5ede79f7 | |||
| e07c3055d7 | |||
| 55a0f2b2aa | |||
| c92efdb98d | |||
| c6e75ac1e8 | |||
| 79ea59d97e | |||
| 823869da10 | |||
| 131392e95f | |||
| bef08edf32 | |||
| edfcb0a509 | |||
| ca969a91db | |||
| 13c548978d | |||
| 87c3b7b6a1 | |||
| ce321daddb | |||
| 55ae11793a | |||
| 3d2bdbbd3b | |||
| e90d128a3c | |||
| 88bd340eb0 | |||
| 4649e158bc | |||
| 3d574205fc | |||
| e168f8e52a | |||
| 7263be2084 | |||
| 37eb89b173 | |||
| 9e26f9e6e0 | |||
| 01b52624a0 | |||
| 8bddab0644 | |||
| 65f7f36302 | |||
| 746f940d10 | |||
| babab88e54 | |||
| 0ad7d7be2f | |||
| 8ba8180559 | |||
| 3592fe5d7a | |||
| 3c97288d80 | |||
| 6773afd159 | |||
| a3fdd0e0b5 | |||
| 9e8c05933f | |||
| c102a6d8cd | |||
| 867f2b0e0a | |||
| e04697664c | |||
| fdecf48e22 | |||
| ab180c9eeb | |||
| 1b7fa1a121 | |||
| b0642f9e86 | |||
| a770e76359 | |||
| 8924dfb7d0 | |||
| b35c0d37b1 | |||
| b39251fe78 | |||
| f054eea342 | |||
| 6f90eb695f | |||
| 5ddbbbe614 | |||
| da11f44114 | |||
| 149fd14ac7 | |||
| 5311ed41ea | |||
| 58314dce95 | |||
| 58991590bd | |||
| 9c75a5f60c | |||
| 8e70ae21a1 | |||
| 9082319f5c | |||
| cdafc35ccb | |||
| d1a65275e8 | |||
| c10020e6a8 | |||
| 0ccdcb8c0a | |||
| 05a48207b3 | |||
| 0d579ffd05 | |||
| d4c6be7cf1 | |||
| b2de4934cf | |||
| 0da2e79318 | |||
| 2a0060496c | |||
| 103db93efa | |||
| 72d2d850d1 | |||
| 23f983ce00 | |||
| 79fdef791d | |||
| 3d478129f2 | |||
| 832e97ccad | |||
| 5ef38c0b13 | |||
| 56ebdff8ae | |||
| 80c9cda739 | |||
| f2669dd916 | |||
| bd03c44cf4 | |||
| 102d7627b6 | |||
| 0c0c5dc2f1 | |||
| e96635d9ff | |||
| 77f9a86c60 | |||
| e681b9fb11 | |||
| bc4b00aadc | |||
| 05b6a6cfaa | |||
| b1b5550715 | |||
| 1443f5865e | |||
| 31d26f2397 | |||
| 4d433615e7 | |||
| 545356f200 | |||
| 6d1c37ed8f | |||
| 759b5db350 | |||
| 60a0e2bf96 | |||
| 7449e3294d | |||
| 4cd47adfe1 | |||
| 5fa8dad095 | |||
| 6a77217a46 | |||
| b6dfacb528 | |||
| 6123416ead | |||
| a6594f96a3 | |||
| be20394012 | |||
| d1c255c293 | |||
| b371ccd8ea | |||
| 71d7981285 | |||
| e9e9733cb5 | |||
| 8e17ec94b4 | |||
| aae94187c1 | |||
| 36148cccb9 | |||
| a5b959e10d | |||
| d1ac77f26d | |||
| 675af55c60 | |||
| 2b6077152e | |||
| 95fc2f11fb | |||
| 92ab799fe0 | |||
| 369d73b98f | |||
| 97a3705788 | |||
| 281b265245 | |||
| 335f08ccc6 | |||
| 4593dc2f8f | |||
| d4f1b14259 | |||
| 8a884bdb36 | |||
| 129d771399 | |||
| 776fd85f8c | |||
| f654d61146 | |||
| eddf33655d | |||
| 9f77ff18bb | |||
| 0158d05946 | |||
| a05f541a6e | |||
| 5db3a9e947 | |||
| 40f0fa95c4 | |||
| 9bf973324f | |||
| 1175fd9b5d | |||
| 1faad73c9a | |||
| 6b246e4709 | |||
| 0a5b95cdcc | |||
| 77fc89c78d | |||
| bf9bf1c027 | |||
| 24fa947692 | |||
| aaed7b75f9 | |||
| 2a2f4c30a1 | |||
| 6d060bbaa1 | |||
| 28b449d8c7 | |||
| 1721ce7afd | |||
| ff2daa0aba | |||
| b43d146e37 | |||
| 66e08d2b3f | |||
| 9a31859f78 | |||
| ae9cb02459 | |||
| c0b22b827b | |||
| d09af9d5b8 | |||
| e7ec96cee0 | |||
| 41d5a06bfd | |||
| 4ca06280ba | |||
| b895512248 | |||
| 6059d3ceb5 | |||
| bab3951531 | |||
| 93ec0f487d | |||
| a6892dcba5 | |||
| 8eb0202e9d | |||
| dd779fa7d3 | |||
| f05cfae018 | |||
| e1b83ccb74 | |||
| 6a6bd778b6 | |||
| f0f92a1dc8 | |||
| e931a2475a | |||
| 8bfaf96434 | |||
| 8a1cd7656d | |||
| 3b16d31abc | |||
| 40aec383a1 | |||
| 2fce45b8e6 | |||
| d7cfd19fb8 | |||
| 68d73442fa | |||
| f91cab1409 | |||
| 5876a93a5f | |||
| 0ea8490473 | |||
| a85af80f34 | |||
| 47671ab7aa | |||
| 96e6b655c1 | |||
| 57c7bc6885 | |||
| d52917b510 | |||
| b948e562f4 | |||
| c889588a2c | |||
| b77ebbe4d8 | |||
| 9a0fe9e006 | |||
| dd78add36d | |||
| e62a268a73 | |||
| 63b4776d64 | |||
| 6932b1cda2 | |||
| 40aefb0faf | |||
| efe64e03d9 | |||
| 898d46e783 | |||
| 04c1e601ab | |||
| 2f77cd04d4 | |||
| c7e378f003 | |||
| f3663cdc32 | |||
| 0ec47d036c | |||
| 59245fd159 | |||
| 389c8322d5 | |||
| e995ba3522 | |||
| 1e7e52a330 | |||
| 383b86ddcb | |||
| ca32b84657 | |||
| ce97dfe405 | |||
| 003044eb84 | |||
| 5b9d1f4fdf | |||
| f265dd9392 | |||
| 44b66a8064 | |||
| 60ca40ecd4 | |||
| 56d1ccc87a | |||
| e9ce32d807 | |||
| 0f3e632580 | |||
| 4eb247591f | |||
| df4e1992c0 | |||
| d18f3acf74 | |||
| 035c1179af |
@@ -22,7 +22,8 @@ runs:
|
|||||||
MAJOR_VERSION: ${{ inputs.major_version }}
|
MAJOR_VERSION: ${{ inputs.major_version }}
|
||||||
LATEST_TAG: ${{ inputs.latest_tag }}
|
LATEST_TAG: ${{ inputs.latest_tag }}
|
||||||
run: |
|
run: |
|
||||||
python ${{ github.action_path }}/release-branches.py \
|
npm ci
|
||||||
|
npx tsx ./pr-checks/release-branches.ts \
|
||||||
--major-version "$MAJOR_VERSION" \
|
--major-version "$MAJOR_VERSION" \
|
||||||
--latest-tag "$LATEST_TAG"
|
--latest-tag "$LATEST_TAG"
|
||||||
shell: bash
|
shell: bash
|
||||||
|
|||||||
@@ -1,55 +0,0 @@
|
|||||||
import argparse
|
|
||||||
import json
|
|
||||||
import os
|
|
||||||
import configparser
|
|
||||||
|
|
||||||
# Name of the remote
|
|
||||||
ORIGIN = 'origin'
|
|
||||||
|
|
||||||
script_dir = os.path.dirname(os.path.realpath(__file__))
|
|
||||||
grandparent_dir = os.path.dirname(os.path.dirname(script_dir))
|
|
||||||
|
|
||||||
config = configparser.ConfigParser()
|
|
||||||
with open(os.path.join(grandparent_dir, 'releases.ini')) as stream:
|
|
||||||
config.read_string('[default]\n' + stream.read())
|
|
||||||
|
|
||||||
OLDEST_SUPPORTED_MAJOR_VERSION = int(config['default']['OLDEST_SUPPORTED_MAJOR_VERSION'])
|
|
||||||
|
|
||||||
def main():
|
|
||||||
|
|
||||||
parser = argparse.ArgumentParser()
|
|
||||||
parser.add_argument("--major-version", required=True, type=str, help="The major version of the release")
|
|
||||||
parser.add_argument("--latest-tag", required=True, type=str, help="The most recent tag published to the repository")
|
|
||||||
args = parser.parse_args()
|
|
||||||
|
|
||||||
major_version = args.major_version
|
|
||||||
latest_tag = args.latest_tag
|
|
||||||
|
|
||||||
print("major_version: " + major_version)
|
|
||||||
print("latest_tag: " + latest_tag)
|
|
||||||
|
|
||||||
# If this is a primary release, we backport to all supported branches,
|
|
||||||
# so we check whether the major_version taken from the package.json
|
|
||||||
# is greater than or equal to the latest tag pulled from the repo.
|
|
||||||
# For example...
|
|
||||||
# 'v1' >= 'v2' is False # we're operating from an older release branch and should not backport
|
|
||||||
# 'v2' >= 'v2' is True # the normal case where we're updating the current version
|
|
||||||
# 'v3' >= 'v2' is True # in this case we are making the first release of a new major version
|
|
||||||
consider_backports = ( major_version >= latest_tag.split(".")[0] )
|
|
||||||
|
|
||||||
with open(os.environ["GITHUB_OUTPUT"], "a") as f:
|
|
||||||
|
|
||||||
f.write(f"backport_source_branch=releases/{major_version}\n")
|
|
||||||
|
|
||||||
backport_target_branches = []
|
|
||||||
|
|
||||||
if consider_backports:
|
|
||||||
for i in range(int(major_version.strip("v"))-1, 0, -1):
|
|
||||||
branch_name = f"releases/v{i}"
|
|
||||||
if i >= OLDEST_SUPPORTED_MAJOR_VERSION:
|
|
||||||
backport_target_branches.append(branch_name)
|
|
||||||
|
|
||||||
f.write("backport_target_branches="+json.dumps(backport_target_branches)+"\n")
|
|
||||||
|
|
||||||
if __name__ == "__main__":
|
|
||||||
main()
|
|
||||||
@@ -15,6 +15,12 @@ runs:
|
|||||||
run: echo "$GITHUB_CONTEXT"
|
run: echo "$GITHUB_CONTEXT"
|
||||||
shell: bash
|
shell: bash
|
||||||
|
|
||||||
|
- name: Set up Node
|
||||||
|
uses: actions/setup-node@v6
|
||||||
|
with:
|
||||||
|
node-version: 20
|
||||||
|
cache: 'npm'
|
||||||
|
|
||||||
- name: Set up Python
|
- name: Set up Python
|
||||||
uses: actions/setup-python@v6
|
uses: actions/setup-python@v6
|
||||||
with:
|
with:
|
||||||
|
|||||||
@@ -1 +0,0 @@
|
|||||||
OLDEST_SUPPORTED_MAJOR_VERSION=3
|
|
||||||
+21
-22
@@ -25,35 +25,34 @@ on:
|
|||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
workflow_call:
|
workflow_call:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
defaults:
|
defaults:
|
||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: all-platform-bundle-${{github.ref}}-${{inputs.dotnet-version}}-${{inputs.go-version}}
|
||||||
all-platform-bundle-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
all-platform-bundle:
|
all-platform-bundle:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -76,6 +75,15 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v6
|
||||||
|
- name: Install .NET
|
||||||
|
uses: actions/setup-dotnet@v5
|
||||||
|
with:
|
||||||
|
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||||
|
- name: Install Go
|
||||||
|
uses: actions/setup-go@v6
|
||||||
|
with:
|
||||||
|
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||||
|
cache: false
|
||||||
- name: Prepare test
|
- name: Prepare test
|
||||||
id: prepare-test
|
id: prepare-test
|
||||||
uses: ./.github/actions/prepare-test
|
uses: ./.github/actions/prepare-test
|
||||||
@@ -83,19 +91,10 @@ jobs:
|
|||||||
version: ${{ matrix.version }}
|
version: ${{ matrix.version }}
|
||||||
use-all-platform-bundle: 'true'
|
use-all-platform-bundle: 'true'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- name: Install Go
|
|
||||||
uses: actions/setup-go@v6
|
|
||||||
with:
|
|
||||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
|
||||||
cache: false
|
|
||||||
- name: Install .NET
|
|
||||||
uses: actions/setup-dotnet@v5
|
|
||||||
with:
|
|
||||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
|
||||||
- id: init
|
- id: init
|
||||||
uses: ./../action/init
|
uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
# Swift is not supported on Ubuntu so we manually exclude it from the list here
|
# Swift is not supported on Ubuntu so we manually exclude it from the list here
|
||||||
languages: cpp,csharp,go,java,javascript,python,ruby
|
languages: cpp,csharp,go,java,javascript,python,ruby
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
- name: Build code
|
- name: Build code
|
||||||
|
|||||||
Generated
+8
-8
@@ -87,24 +87,24 @@ jobs:
|
|||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
output: ${{ runner.temp }}/results
|
output: '${{ runner.temp }}/results'
|
||||||
upload-database: false
|
upload-database: false
|
||||||
post-processed-sarif-path: ${{ runner.temp }}/post-processed
|
post-processed-sarif-path: '${{ runner.temp }}/post-processed'
|
||||||
|
|
||||||
- name: Upload SARIF files
|
- name: Upload SARIF files
|
||||||
uses: actions/upload-artifact@v6
|
uses: actions/upload-artifact@v7
|
||||||
with:
|
with:
|
||||||
name: |
|
name: |
|
||||||
analysis-kinds-${{ matrix.os }}-${{ matrix.version }}-${{ matrix.analysis-kinds }}
|
analysis-kinds-${{ matrix.os }}-${{ matrix.version }}-${{ matrix.analysis-kinds }}
|
||||||
path: ${{ runner.temp }}/results/*.sarif
|
path: '${{ runner.temp }}/results/*.sarif'
|
||||||
retention-days: 7
|
retention-days: 7
|
||||||
|
|
||||||
- name: Upload post-processed SARIF
|
- name: Upload post-processed SARIF
|
||||||
uses: actions/upload-artifact@v6
|
uses: actions/upload-artifact@v7
|
||||||
with:
|
with:
|
||||||
name: |
|
name: |
|
||||||
post-processed-${{ matrix.os }}-${{ matrix.version }}-${{ matrix.analysis-kinds }}
|
post-processed-${{ matrix.os }}-${{ matrix.version }}-${{ matrix.analysis-kinds }}
|
||||||
path: ${{ runner.temp }}/post-processed
|
path: '${{ runner.temp }}/post-processed'
|
||||||
retention-days: 7
|
retention-days: 7
|
||||||
if-no-files-found: error
|
if-no-files-found: error
|
||||||
|
|
||||||
@@ -112,7 +112,7 @@ jobs:
|
|||||||
if: contains(matrix.analysis-kinds, 'code-scanning')
|
if: contains(matrix.analysis-kinds, 'code-scanning')
|
||||||
uses: actions/github-script@v8
|
uses: actions/github-script@v8
|
||||||
env:
|
env:
|
||||||
SARIF_PATH: ${{ runner.temp }}/results/javascript.sarif
|
SARIF_PATH: '${{ runner.temp }}/results/javascript.sarif'
|
||||||
EXPECT_PRESENT: 'false'
|
EXPECT_PRESENT: 'false'
|
||||||
with:
|
with:
|
||||||
script: ${{ env.CHECK_SCRIPT }}
|
script: ${{ env.CHECK_SCRIPT }}
|
||||||
@@ -120,7 +120,7 @@ jobs:
|
|||||||
if: contains(matrix.analysis-kinds, 'code-quality')
|
if: contains(matrix.analysis-kinds, 'code-quality')
|
||||||
uses: actions/github-script@v8
|
uses: actions/github-script@v8
|
||||||
env:
|
env:
|
||||||
SARIF_PATH: ${{ runner.temp }}/results/javascript.quality.sarif
|
SARIF_PATH: '${{ runner.temp }}/results/javascript.quality.sarif'
|
||||||
EXPECT_PRESENT: 'true'
|
EXPECT_PRESENT: 'true'
|
||||||
with:
|
with:
|
||||||
script: ${{ env.CHECK_SCRIPT }}
|
script: ${{ env.CHECK_SCRIPT }}
|
||||||
|
|||||||
+23
-40
@@ -25,45 +25,34 @@ on:
|
|||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
python-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Python to install
|
|
||||||
required: false
|
|
||||||
default: '3.13'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
workflow_call:
|
workflow_call:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
python-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Python to install
|
|
||||||
required: false
|
|
||||||
default: '3.13'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
defaults:
|
defaults:
|
||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: analyze-ref-input-${{github.ref}}-${{inputs.dotnet-version}}-${{inputs.go-version}}
|
||||||
analyze-ref-input-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
analyze-ref-input:
|
analyze-ref-input:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -82,6 +71,15 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v6
|
||||||
|
- name: Install .NET
|
||||||
|
uses: actions/setup-dotnet@v5
|
||||||
|
with:
|
||||||
|
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||||
|
- name: Install Go
|
||||||
|
uses: actions/setup-go@v6
|
||||||
|
with:
|
||||||
|
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||||
|
cache: false
|
||||||
- name: Prepare test
|
- name: Prepare test
|
||||||
id: prepare-test
|
id: prepare-test
|
||||||
uses: ./.github/actions/prepare-test
|
uses: ./.github/actions/prepare-test
|
||||||
@@ -89,31 +87,16 @@ jobs:
|
|||||||
version: ${{ matrix.version }}
|
version: ${{ matrix.version }}
|
||||||
use-all-platform-bundle: 'false'
|
use-all-platform-bundle: 'false'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- name: Install Go
|
|
||||||
uses: actions/setup-go@v6
|
|
||||||
with:
|
|
||||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
|
||||||
cache: false
|
|
||||||
- name: Install Python
|
|
||||||
if: matrix.version != 'nightly-latest'
|
|
||||||
uses: actions/setup-python@v6
|
|
||||||
with:
|
|
||||||
python-version: ${{ inputs.python-version || '3.13' }}
|
|
||||||
- name: Install .NET
|
|
||||||
uses: actions/setup-dotnet@v5
|
|
||||||
with:
|
|
||||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
languages: cpp,csharp,java,javascript,python
|
languages: cpp,csharp,java,javascript,python
|
||||||
config-file: ${{ github.repository }}/tests/multi-language-repo/.github/codeql/custom-queries.yml@${{
|
config-file: ${{ github.repository }}/tests/multi-language-repo/.github/codeql/custom-queries.yml@${{ github.sha }}
|
||||||
github.sha }}
|
|
||||||
- name: Build code
|
- name: Build code
|
||||||
run: ./build.sh
|
run: ./build.sh
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
ref: refs/heads/main
|
ref: 'refs/heads/main'
|
||||||
sha: 5e235361806c361d4d3f8859e3c897658025a9a2
|
sha: '5e235361806c361d4d3f8859e3c897658025a9a2'
|
||||||
env:
|
env:
|
||||||
CODEQL_ACTION_TEST_MODE: true
|
CODEQL_ACTION_TEST_MODE: true
|
||||||
|
|||||||
Generated
+5
-5
@@ -65,6 +65,10 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v6
|
||||||
|
- name: Install .NET
|
||||||
|
uses: actions/setup-dotnet@v5
|
||||||
|
with:
|
||||||
|
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||||
- name: Prepare test
|
- name: Prepare test
|
||||||
id: prepare-test
|
id: prepare-test
|
||||||
uses: ./.github/actions/prepare-test
|
uses: ./.github/actions/prepare-test
|
||||||
@@ -72,17 +76,13 @@ jobs:
|
|||||||
version: ${{ matrix.version }}
|
version: ${{ matrix.version }}
|
||||||
use-all-platform-bundle: 'false'
|
use-all-platform-bundle: 'false'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- name: Install .NET
|
|
||||||
uses: actions/setup-dotnet@v5
|
|
||||||
with:
|
|
||||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
languages: csharp
|
languages: csharp
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
- uses: ./../action/autobuild
|
- uses: ./../action/autobuild
|
||||||
env:
|
env:
|
||||||
# Explicitly disable the CLR tracer.
|
# Explicitly disable the CLR tracer.
|
||||||
COR_ENABLE_PROFILING: ''
|
COR_ENABLE_PROFILING: ''
|
||||||
COR_PROFILER: ''
|
COR_PROFILER: ''
|
||||||
COR_PROFILER_PATH_64: ''
|
COR_PROFILER_PATH_64: ''
|
||||||
|
|||||||
@@ -42,8 +42,7 @@ defaults:
|
|||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: autobuild-direct-tracing-with-working-dir-${{github.ref}}-${{inputs.java-version}}
|
||||||
autobuild-direct-tracing-with-working-dir-${{github.ref}}-${{inputs.java-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
autobuild-direct-tracing-with-working-dir:
|
autobuild-direct-tracing-with-working-dir:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -68,6 +67,11 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v6
|
||||||
|
- name: Install Java
|
||||||
|
uses: actions/setup-java@v5
|
||||||
|
with:
|
||||||
|
java-version: ${{ inputs.java-version || '17' }}
|
||||||
|
distribution: temurin
|
||||||
- name: Prepare test
|
- name: Prepare test
|
||||||
id: prepare-test
|
id: prepare-test
|
||||||
uses: ./.github/actions/prepare-test
|
uses: ./.github/actions/prepare-test
|
||||||
@@ -75,11 +79,6 @@ jobs:
|
|||||||
version: ${{ matrix.version }}
|
version: ${{ matrix.version }}
|
||||||
use-all-platform-bundle: 'false'
|
use-all-platform-bundle: 'false'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- name: Install Java
|
|
||||||
uses: actions/setup-java@v5
|
|
||||||
with:
|
|
||||||
java-version: ${{ inputs.java-version || '17' }}
|
|
||||||
distribution: temurin
|
|
||||||
- name: Test setup
|
- name: Test setup
|
||||||
run: |
|
run: |
|
||||||
# Make sure that Gradle build succeeds in autobuild-dir ...
|
# Make sure that Gradle build succeeds in autobuild-dir ...
|
||||||
|
|||||||
+8
-8
@@ -67,13 +67,6 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v6
|
||||||
- name: Prepare test
|
|
||||||
id: prepare-test
|
|
||||||
uses: ./.github/actions/prepare-test
|
|
||||||
with:
|
|
||||||
version: ${{ matrix.version }}
|
|
||||||
use-all-platform-bundle: 'false'
|
|
||||||
setup-kotlin: 'true'
|
|
||||||
- name: Install Java
|
- name: Install Java
|
||||||
uses: actions/setup-java@v5
|
uses: actions/setup-java@v5
|
||||||
with:
|
with:
|
||||||
@@ -87,6 +80,13 @@ jobs:
|
|||||||
run: |-
|
run: |-
|
||||||
gh release download --repo mikefarah/yq --pattern "yq_windows_amd64.exe" "$YQ_VERSION" -O "$YQ_PATH/yq.exe"
|
gh release download --repo mikefarah/yq --pattern "yq_windows_amd64.exe" "$YQ_VERSION" -O "$YQ_PATH/yq.exe"
|
||||||
echo "$YQ_PATH" >> "$GITHUB_PATH"
|
echo "$YQ_PATH" >> "$GITHUB_PATH"
|
||||||
|
- name: Prepare test
|
||||||
|
id: prepare-test
|
||||||
|
uses: ./.github/actions/prepare-test
|
||||||
|
with:
|
||||||
|
version: ${{ matrix.version }}
|
||||||
|
use-all-platform-bundle: 'false'
|
||||||
|
setup-kotlin: 'true'
|
||||||
- name: Set up Java test repo configuration
|
- name: Set up Java test repo configuration
|
||||||
run: |
|
run: |
|
||||||
mv * .github ../action/tests/multi-language-repo/
|
mv * .github ../action/tests/multi-language-repo/
|
||||||
@@ -97,7 +97,7 @@ jobs:
|
|||||||
id: init
|
id: init
|
||||||
with:
|
with:
|
||||||
build-mode: autobuild
|
build-mode: autobuild
|
||||||
db-location: ${{ runner.temp }}/customDbLocation
|
db-location: '${{ runner.temp }}/customDbLocation'
|
||||||
languages: java
|
languages: java
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
|
|
||||||
|
|||||||
+21
-22
@@ -25,35 +25,34 @@ on:
|
|||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
workflow_call:
|
workflow_call:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
defaults:
|
defaults:
|
||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: build-mode-manual-${{github.ref}}-${{inputs.dotnet-version}}-${{inputs.go-version}}
|
||||||
build-mode-manual-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
build-mode-manual:
|
build-mode-manual:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -72,6 +71,15 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v6
|
||||||
|
- name: Install .NET
|
||||||
|
uses: actions/setup-dotnet@v5
|
||||||
|
with:
|
||||||
|
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||||
|
- name: Install Go
|
||||||
|
uses: actions/setup-go@v6
|
||||||
|
with:
|
||||||
|
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||||
|
cache: false
|
||||||
- name: Prepare test
|
- name: Prepare test
|
||||||
id: prepare-test
|
id: prepare-test
|
||||||
uses: ./.github/actions/prepare-test
|
uses: ./.github/actions/prepare-test
|
||||||
@@ -79,20 +87,11 @@ jobs:
|
|||||||
version: ${{ matrix.version }}
|
version: ${{ matrix.version }}
|
||||||
use-all-platform-bundle: 'false'
|
use-all-platform-bundle: 'false'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- name: Install Go
|
|
||||||
uses: actions/setup-go@v6
|
|
||||||
with:
|
|
||||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
|
||||||
cache: false
|
|
||||||
- name: Install .NET
|
|
||||||
uses: actions/setup-dotnet@v5
|
|
||||||
with:
|
|
||||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
id: init
|
id: init
|
||||||
with:
|
with:
|
||||||
build-mode: manual
|
build-mode: manual
|
||||||
db-location: ${{ runner.temp }}/customDbLocation
|
db-location: '${{ runner.temp }}/customDbLocation'
|
||||||
languages: java
|
languages: java
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
|
|
||||||
|
|||||||
Generated
+2
-2
@@ -64,7 +64,7 @@ jobs:
|
|||||||
id: init
|
id: init
|
||||||
with:
|
with:
|
||||||
build-mode: none
|
build-mode: none
|
||||||
db-location: ${{ runner.temp }}/customDbLocation
|
db-location: '${{ runner.temp }}/customDbLocation'
|
||||||
languages: java
|
languages: java
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
|
|
||||||
@@ -77,7 +77,7 @@ jobs:
|
|||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# The latest nightly supports omitting the autobuild Action when the build mode is specified.
|
# The latest nightly supports omitting the autobuild Action when the build mode is specified.
|
||||||
- uses: ./../action/autobuild
|
- uses: ./../action/autobuild
|
||||||
if: matrix.version != 'nightly-latest'
|
if: matrix.version != 'nightly-latest'
|
||||||
|
|
||||||
|
|||||||
+1
-1
@@ -68,7 +68,7 @@ jobs:
|
|||||||
id: init
|
id: init
|
||||||
with:
|
with:
|
||||||
build-mode: none
|
build-mode: none
|
||||||
db-location: ${{ runner.temp }}/customDbLocation
|
db-location: '${{ runner.temp }}/customDbLocation'
|
||||||
languages: java
|
languages: java
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
|
|
||||||
|
|||||||
+1
-1
@@ -66,7 +66,7 @@ jobs:
|
|||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
languages: javascript
|
languages: javascript
|
||||||
- name: Fail if the CodeQL version is not a nightly
|
- name: Fail if the CodeQL version is not a nightly
|
||||||
if: "!contains(steps.init.outputs.codeql-version, '+')"
|
if: ${{ !contains(steps.init.outputs.codeql-version, '+') }}
|
||||||
run: exit 1
|
run: exit 1
|
||||||
env:
|
env:
|
||||||
CODEQL_ACTION_TEST_MODE: true
|
CODEQL_ACTION_TEST_MODE: true
|
||||||
|
|||||||
Generated
+2
-2
@@ -39,10 +39,10 @@ jobs:
|
|||||||
fail-fast: false
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
include:
|
include:
|
||||||
- os: macos-latest
|
|
||||||
version: linked
|
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: linked
|
version: linked
|
||||||
|
- os: macos-latest
|
||||||
|
version: linked
|
||||||
- os: windows-latest
|
- os: windows-latest
|
||||||
version: linked
|
version: linked
|
||||||
name: 'Bundle: Caching checks'
|
name: 'Bundle: Caching checks'
|
||||||
|
|||||||
Generated
+3
-3
@@ -39,10 +39,10 @@ jobs:
|
|||||||
fail-fast: false
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
include:
|
include:
|
||||||
- os: macos-latest
|
|
||||||
version: linked
|
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: linked
|
version: linked
|
||||||
|
- os: macos-latest
|
||||||
|
version: linked
|
||||||
- os: windows-latest
|
- os: windows-latest
|
||||||
version: linked
|
version: linked
|
||||||
name: 'Bundle: Zstandard checks'
|
name: 'Bundle: Zstandard checks'
|
||||||
@@ -82,7 +82,7 @@ jobs:
|
|||||||
output: ${{ runner.temp }}/results
|
output: ${{ runner.temp }}/results
|
||||||
upload-database: false
|
upload-database: false
|
||||||
- name: Upload SARIF
|
- name: Upload SARIF
|
||||||
uses: actions/upload-artifact@v6
|
uses: actions/upload-artifact@v7
|
||||||
with:
|
with:
|
||||||
name: ${{ matrix.os }}-zstd-bundle.sarif
|
name: ${{ matrix.os }}-zstd-bundle.sarif
|
||||||
path: ${{ runner.temp }}/results/javascript.sarif
|
path: ${{ runner.temp }}/results/javascript.sarif
|
||||||
|
|||||||
+1
-1
@@ -67,7 +67,7 @@ jobs:
|
|||||||
id: init
|
id: init
|
||||||
with:
|
with:
|
||||||
build-mode: none
|
build-mode: none
|
||||||
db-location: ${{ runner.temp }}/customDbLocation
|
db-location: '${{ runner.temp }}/customDbLocation'
|
||||||
languages: javascript
|
languages: javascript
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
|
|
||||||
|
|||||||
Generated
+4
-4
@@ -67,18 +67,18 @@ jobs:
|
|||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
output: ${{ runner.temp }}/results
|
output: '${{ runner.temp }}/results'
|
||||||
upload-database: false
|
upload-database: false
|
||||||
- name: Upload SARIF
|
- name: Upload SARIF
|
||||||
uses: actions/upload-artifact@v6
|
uses: actions/upload-artifact@v7
|
||||||
with:
|
with:
|
||||||
name: config-export-${{ matrix.os }}-${{ matrix.version }}.sarif.json
|
name: config-export-${{ matrix.os }}-${{ matrix.version }}.sarif.json
|
||||||
path: ${{ runner.temp }}/results/javascript.sarif
|
path: '${{ runner.temp }}/results/javascript.sarif'
|
||||||
retention-days: 7
|
retention-days: 7
|
||||||
- name: Check config properties appear in SARIF
|
- name: Check config properties appear in SARIF
|
||||||
uses: actions/github-script@v8
|
uses: actions/github-script@v8
|
||||||
env:
|
env:
|
||||||
SARIF_PATH: ${{ runner.temp }}/results/javascript.sarif
|
SARIF_PATH: '${{ runner.temp }}/results/javascript.sarif'
|
||||||
with:
|
with:
|
||||||
script: |
|
script: |
|
||||||
const fs = require('fs');
|
const fs = require('fs');
|
||||||
|
|||||||
+4
-4
@@ -78,18 +78,18 @@ jobs:
|
|||||||
--ready-for-status-page
|
--ready-for-status-page
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
output: ${{ runner.temp }}/results
|
output: '${{ runner.temp }}/results'
|
||||||
upload-database: false
|
upload-database: false
|
||||||
- name: Upload SARIF
|
- name: Upload SARIF
|
||||||
uses: actions/upload-artifact@v6
|
uses: actions/upload-artifact@v7
|
||||||
with:
|
with:
|
||||||
name: diagnostics-export-${{ matrix.os }}-${{ matrix.version }}.sarif.json
|
name: diagnostics-export-${{ matrix.os }}-${{ matrix.version }}.sarif.json
|
||||||
path: ${{ runner.temp }}/results/javascript.sarif
|
path: '${{ runner.temp }}/results/javascript.sarif'
|
||||||
retention-days: 7
|
retention-days: 7
|
||||||
- name: Check diagnostics appear in SARIF
|
- name: Check diagnostics appear in SARIF
|
||||||
uses: actions/github-script@v8
|
uses: actions/github-script@v8
|
||||||
env:
|
env:
|
||||||
SARIF_PATH: ${{ runner.temp }}/results/javascript.sarif
|
SARIF_PATH: '${{ runner.temp }}/results/javascript.sarif'
|
||||||
with:
|
with:
|
||||||
script: |
|
script: |
|
||||||
const fs = require('fs');
|
const fs = require('fs');
|
||||||
|
|||||||
+23
-24
@@ -25,35 +25,34 @@ on:
|
|||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
workflow_call:
|
workflow_call:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
defaults:
|
defaults:
|
||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: export-file-baseline-information-${{github.ref}}-${{inputs.dotnet-version}}-${{inputs.go-version}}
|
||||||
export-file-baseline-information-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
export-file-baseline-information:
|
export-file-baseline-information:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -76,6 +75,15 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v6
|
||||||
|
- name: Install .NET
|
||||||
|
uses: actions/setup-dotnet@v5
|
||||||
|
with:
|
||||||
|
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||||
|
- name: Install Go
|
||||||
|
uses: actions/setup-go@v6
|
||||||
|
with:
|
||||||
|
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||||
|
cache: false
|
||||||
- name: Prepare test
|
- name: Prepare test
|
||||||
id: prepare-test
|
id: prepare-test
|
||||||
uses: ./.github/actions/prepare-test
|
uses: ./.github/actions/prepare-test
|
||||||
@@ -83,15 +91,6 @@ jobs:
|
|||||||
version: ${{ matrix.version }}
|
version: ${{ matrix.version }}
|
||||||
use-all-platform-bundle: 'false'
|
use-all-platform-bundle: 'false'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- name: Install Go
|
|
||||||
uses: actions/setup-go@v6
|
|
||||||
with:
|
|
||||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
|
||||||
cache: false
|
|
||||||
- name: Install .NET
|
|
||||||
uses: actions/setup-dotnet@v5
|
|
||||||
with:
|
|
||||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
id: init
|
id: init
|
||||||
with:
|
with:
|
||||||
@@ -101,12 +100,12 @@ jobs:
|
|||||||
run: ./build.sh
|
run: ./build.sh
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
output: ${{ runner.temp }}/results
|
output: '${{ runner.temp }}/results'
|
||||||
- name: Upload SARIF
|
- name: Upload SARIF
|
||||||
uses: actions/upload-artifact@v6
|
uses: actions/upload-artifact@v7
|
||||||
with:
|
with:
|
||||||
name: with-baseline-information-${{ matrix.os }}-${{ matrix.version }}.sarif.json
|
name: with-baseline-information-${{ matrix.os }}-${{ matrix.version }}.sarif.json
|
||||||
path: ${{ runner.temp }}/results/javascript.sarif
|
path: '${{ runner.temp }}/results/javascript.sarif'
|
||||||
retention-days: 7
|
retention-days: 7
|
||||||
- name: Check results
|
- name: Check results
|
||||||
run: |
|
run: |
|
||||||
|
|||||||
+20
-21
@@ -25,35 +25,34 @@ on:
|
|||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
workflow_call:
|
workflow_call:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
defaults:
|
defaults:
|
||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: go-custom-queries-${{github.ref}}-${{inputs.dotnet-version}}-${{inputs.go-version}}
|
||||||
go-custom-queries-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
go-custom-queries:
|
go-custom-queries:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -74,6 +73,15 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v6
|
||||||
|
- name: Install .NET
|
||||||
|
uses: actions/setup-dotnet@v5
|
||||||
|
with:
|
||||||
|
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||||
|
- name: Install Go
|
||||||
|
uses: actions/setup-go@v6
|
||||||
|
with:
|
||||||
|
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||||
|
cache: false
|
||||||
- name: Prepare test
|
- name: Prepare test
|
||||||
id: prepare-test
|
id: prepare-test
|
||||||
uses: ./.github/actions/prepare-test
|
uses: ./.github/actions/prepare-test
|
||||||
@@ -81,15 +89,6 @@ jobs:
|
|||||||
version: ${{ matrix.version }}
|
version: ${{ matrix.version }}
|
||||||
use-all-platform-bundle: 'false'
|
use-all-platform-bundle: 'false'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- name: Install Go
|
|
||||||
uses: actions/setup-go@v6
|
|
||||||
with:
|
|
||||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
|
||||||
cache: false
|
|
||||||
- name: Install .NET
|
|
||||||
uses: actions/setup-dotnet@v5
|
|
||||||
with:
|
|
||||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
languages: go
|
languages: go
|
||||||
|
|||||||
@@ -61,6 +61,11 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v6
|
||||||
|
- name: Install Go
|
||||||
|
uses: actions/setup-go@v6
|
||||||
|
with:
|
||||||
|
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||||
|
cache: false
|
||||||
- name: Prepare test
|
- name: Prepare test
|
||||||
id: prepare-test
|
id: prepare-test
|
||||||
uses: ./.github/actions/prepare-test
|
uses: ./.github/actions/prepare-test
|
||||||
@@ -68,16 +73,11 @@ jobs:
|
|||||||
version: ${{ matrix.version }}
|
version: ${{ matrix.version }}
|
||||||
use-all-platform-bundle: 'false'
|
use-all-platform-bundle: 'false'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- name: Install Go
|
|
||||||
uses: actions/setup-go@v6
|
|
||||||
with:
|
|
||||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
|
||||||
cache: false
|
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
languages: go
|
languages: go
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
# Deliberately change Go after the `init` step
|
# Deliberately change Go after the `init` step
|
||||||
- uses: actions/setup-go@v6
|
- uses: actions/setup-go@v6
|
||||||
with:
|
with:
|
||||||
go-version: '1.20'
|
go-version: '1.20'
|
||||||
@@ -85,12 +85,12 @@ jobs:
|
|||||||
run: go build main.go
|
run: go build main.go
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
output: ${{ runner.temp }}/results
|
output: '${{ runner.temp }}/results'
|
||||||
upload-database: false
|
upload-database: false
|
||||||
- name: Check diagnostic appears in SARIF
|
- name: Check diagnostic appears in SARIF
|
||||||
uses: actions/github-script@v8
|
uses: actions/github-script@v8
|
||||||
env:
|
env:
|
||||||
SARIF_PATH: ${{ runner.temp }}/results/go.sarif
|
SARIF_PATH: '${{ runner.temp }}/results/go.sarif'
|
||||||
with:
|
with:
|
||||||
script: |
|
script: |
|
||||||
const fs = require('fs');
|
const fs = require('fs');
|
||||||
|
|||||||
@@ -42,8 +42,7 @@ defaults:
|
|||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: go-indirect-tracing-workaround-no-file-program-${{github.ref}}-${{inputs.go-version}}
|
||||||
go-indirect-tracing-workaround-no-file-program-${{github.ref}}-${{inputs.go-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
go-indirect-tracing-workaround-no-file-program:
|
go-indirect-tracing-workaround-no-file-program:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -62,6 +61,11 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v6
|
||||||
|
- name: Install Go
|
||||||
|
uses: actions/setup-go@v6
|
||||||
|
with:
|
||||||
|
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||||
|
cache: false
|
||||||
- name: Prepare test
|
- name: Prepare test
|
||||||
id: prepare-test
|
id: prepare-test
|
||||||
uses: ./.github/actions/prepare-test
|
uses: ./.github/actions/prepare-test
|
||||||
@@ -69,11 +73,6 @@ jobs:
|
|||||||
version: ${{ matrix.version }}
|
version: ${{ matrix.version }}
|
||||||
use-all-platform-bundle: 'false'
|
use-all-platform-bundle: 'false'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- name: Install Go
|
|
||||||
uses: actions/setup-go@v6
|
|
||||||
with:
|
|
||||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
|
||||||
cache: false
|
|
||||||
- name: Remove `file` program
|
- name: Remove `file` program
|
||||||
run: |
|
run: |
|
||||||
echo $(which file)
|
echo $(which file)
|
||||||
@@ -87,12 +86,12 @@ jobs:
|
|||||||
run: go build main.go
|
run: go build main.go
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
output: ${{ runner.temp }}/results
|
output: '${{ runner.temp }}/results'
|
||||||
upload-database: false
|
upload-database: false
|
||||||
- name: Check diagnostic appears in SARIF
|
- name: Check diagnostic appears in SARIF
|
||||||
uses: actions/github-script@v8
|
uses: actions/github-script@v8
|
||||||
env:
|
env:
|
||||||
SARIF_PATH: ${{ runner.temp }}/results/go.sarif
|
SARIF_PATH: '${{ runner.temp }}/results/go.sarif'
|
||||||
with:
|
with:
|
||||||
script: |
|
script: |
|
||||||
const fs = require('fs');
|
const fs = require('fs');
|
||||||
|
|||||||
+5
-5
@@ -61,6 +61,11 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v6
|
||||||
|
- name: Install Go
|
||||||
|
uses: actions/setup-go@v6
|
||||||
|
with:
|
||||||
|
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||||
|
cache: false
|
||||||
- name: Prepare test
|
- name: Prepare test
|
||||||
id: prepare-test
|
id: prepare-test
|
||||||
uses: ./.github/actions/prepare-test
|
uses: ./.github/actions/prepare-test
|
||||||
@@ -68,11 +73,6 @@ jobs:
|
|||||||
version: ${{ matrix.version }}
|
version: ${{ matrix.version }}
|
||||||
use-all-platform-bundle: 'false'
|
use-all-platform-bundle: 'false'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- name: Install Go
|
|
||||||
uses: actions/setup-go@v6
|
|
||||||
with:
|
|
||||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
|
||||||
cache: false
|
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
languages: go
|
languages: go
|
||||||
|
|||||||
+5
-19
@@ -51,32 +51,18 @@ jobs:
|
|||||||
include:
|
include:
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: stable-v2.17.6
|
version: stable-v2.17.6
|
||||||
- os: macos-latest
|
|
||||||
version: stable-v2.17.6
|
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: stable-v2.18.4
|
version: stable-v2.18.4
|
||||||
- os: macos-latest
|
|
||||||
version: stable-v2.18.4
|
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: stable-v2.19.4
|
version: stable-v2.19.4
|
||||||
- os: macos-latest
|
|
||||||
version: stable-v2.19.4
|
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: stable-v2.20.7
|
version: stable-v2.20.7
|
||||||
- os: macos-latest
|
|
||||||
version: stable-v2.20.7
|
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: stable-v2.21.4
|
version: stable-v2.21.4
|
||||||
- os: macos-latest
|
|
||||||
version: stable-v2.21.4
|
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: stable-v2.22.4
|
version: stable-v2.22.4
|
||||||
- os: macos-latest
|
|
||||||
version: stable-v2.22.4
|
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: default
|
version: default
|
||||||
- os: macos-latest
|
|
||||||
version: default
|
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: linked
|
version: linked
|
||||||
- os: macos-latest
|
- os: macos-latest
|
||||||
@@ -95,6 +81,11 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v6
|
||||||
|
- name: Install Go
|
||||||
|
uses: actions/setup-go@v6
|
||||||
|
with:
|
||||||
|
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||||
|
cache: false
|
||||||
- name: Prepare test
|
- name: Prepare test
|
||||||
id: prepare-test
|
id: prepare-test
|
||||||
uses: ./.github/actions/prepare-test
|
uses: ./.github/actions/prepare-test
|
||||||
@@ -102,11 +93,6 @@ jobs:
|
|||||||
version: ${{ matrix.version }}
|
version: ${{ matrix.version }}
|
||||||
use-all-platform-bundle: 'false'
|
use-all-platform-bundle: 'false'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- name: Install Go
|
|
||||||
uses: actions/setup-go@v6
|
|
||||||
with:
|
|
||||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
|
||||||
cache: false
|
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
languages: go
|
languages: go
|
||||||
|
|||||||
+5
-19
@@ -51,32 +51,18 @@ jobs:
|
|||||||
include:
|
include:
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: stable-v2.17.6
|
version: stable-v2.17.6
|
||||||
- os: macos-latest
|
|
||||||
version: stable-v2.17.6
|
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: stable-v2.18.4
|
version: stable-v2.18.4
|
||||||
- os: macos-latest
|
|
||||||
version: stable-v2.18.4
|
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: stable-v2.19.4
|
version: stable-v2.19.4
|
||||||
- os: macos-latest
|
|
||||||
version: stable-v2.19.4
|
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: stable-v2.20.7
|
version: stable-v2.20.7
|
||||||
- os: macos-latest
|
|
||||||
version: stable-v2.20.7
|
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: stable-v2.21.4
|
version: stable-v2.21.4
|
||||||
- os: macos-latest
|
|
||||||
version: stable-v2.21.4
|
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: stable-v2.22.4
|
version: stable-v2.22.4
|
||||||
- os: macos-latest
|
|
||||||
version: stable-v2.22.4
|
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: default
|
version: default
|
||||||
- os: macos-latest
|
|
||||||
version: default
|
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: linked
|
version: linked
|
||||||
- os: macos-latest
|
- os: macos-latest
|
||||||
@@ -95,6 +81,11 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v6
|
||||||
|
- name: Install Go
|
||||||
|
uses: actions/setup-go@v6
|
||||||
|
with:
|
||||||
|
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||||
|
cache: false
|
||||||
- name: Prepare test
|
- name: Prepare test
|
||||||
id: prepare-test
|
id: prepare-test
|
||||||
uses: ./.github/actions/prepare-test
|
uses: ./.github/actions/prepare-test
|
||||||
@@ -102,11 +93,6 @@ jobs:
|
|||||||
version: ${{ matrix.version }}
|
version: ${{ matrix.version }}
|
||||||
use-all-platform-bundle: 'false'
|
use-all-platform-bundle: 'false'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- name: Install Go
|
|
||||||
uses: actions/setup-go@v6
|
|
||||||
with:
|
|
||||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
|
||||||
cache: false
|
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
languages: go
|
languages: go
|
||||||
|
|||||||
+5
-19
@@ -51,32 +51,18 @@ jobs:
|
|||||||
include:
|
include:
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: stable-v2.17.6
|
version: stable-v2.17.6
|
||||||
- os: macos-latest
|
|
||||||
version: stable-v2.17.6
|
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: stable-v2.18.4
|
version: stable-v2.18.4
|
||||||
- os: macos-latest
|
|
||||||
version: stable-v2.18.4
|
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: stable-v2.19.4
|
version: stable-v2.19.4
|
||||||
- os: macos-latest
|
|
||||||
version: stable-v2.19.4
|
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: stable-v2.20.7
|
version: stable-v2.20.7
|
||||||
- os: macos-latest
|
|
||||||
version: stable-v2.20.7
|
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: stable-v2.21.4
|
version: stable-v2.21.4
|
||||||
- os: macos-latest
|
|
||||||
version: stable-v2.21.4
|
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: stable-v2.22.4
|
version: stable-v2.22.4
|
||||||
- os: macos-latest
|
|
||||||
version: stable-v2.22.4
|
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: default
|
version: default
|
||||||
- os: macos-latest
|
|
||||||
version: default
|
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: linked
|
version: linked
|
||||||
- os: macos-latest
|
- os: macos-latest
|
||||||
@@ -95,6 +81,11 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v6
|
||||||
|
- name: Install Go
|
||||||
|
uses: actions/setup-go@v6
|
||||||
|
with:
|
||||||
|
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||||
|
cache: false
|
||||||
- name: Prepare test
|
- name: Prepare test
|
||||||
id: prepare-test
|
id: prepare-test
|
||||||
uses: ./.github/actions/prepare-test
|
uses: ./.github/actions/prepare-test
|
||||||
@@ -102,11 +93,6 @@ jobs:
|
|||||||
version: ${{ matrix.version }}
|
version: ${{ matrix.version }}
|
||||||
use-all-platform-bundle: 'false'
|
use-all-platform-bundle: 'false'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- name: Install Go
|
|
||||||
uses: actions/setup-go@v6
|
|
||||||
with:
|
|
||||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
|
||||||
cache: false
|
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
languages: go
|
languages: go
|
||||||
|
|||||||
Generated
+6
-6
@@ -10,16 +10,16 @@ env:
|
|||||||
on:
|
on:
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
jobs:
|
jobs:
|
||||||
go-custom-queries:
|
go-custom-queries:
|
||||||
name: 'Go: Custom queries'
|
name: 'Go: Custom queries'
|
||||||
@@ -28,8 +28,8 @@ jobs:
|
|||||||
security-events: read
|
security-events: read
|
||||||
uses: ./.github/workflows/__go-custom-queries.yml
|
uses: ./.github/workflows/__go-custom-queries.yml
|
||||||
with:
|
with:
|
||||||
go-version: ${{ inputs.go-version }}
|
|
||||||
dotnet-version: ${{ inputs.dotnet-version }}
|
dotnet-version: ${{ inputs.dotnet-version }}
|
||||||
|
go-version: ${{ inputs.go-version }}
|
||||||
go-indirect-tracing-workaround-diagnostic:
|
go-indirect-tracing-workaround-diagnostic:
|
||||||
name: 'Go: diagnostic when Go is changed after init step'
|
name: 'Go: diagnostic when Go is changed after init step'
|
||||||
permissions:
|
permissions:
|
||||||
|
|||||||
+1
-2
@@ -50,7 +50,6 @@ jobs:
|
|||||||
permissions:
|
permissions:
|
||||||
contents: read
|
contents: read
|
||||||
packages: read
|
packages: read
|
||||||
|
|
||||||
timeout-minutes: 45
|
timeout-minutes: 45
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
@@ -66,7 +65,7 @@ jobs:
|
|||||||
- name: Init with registries
|
- name: Init with registries
|
||||||
uses: ./../action/init
|
uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
db-location: ${{ runner.temp }}/customDbLocation
|
db-location: '${{ runner.temp }}/customDbLocation'
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
config-file: ./.github/codeql/codeql-config-registries.yml
|
config-file: ./.github/codeql/codeql-config-registries.yml
|
||||||
languages: javascript
|
languages: javascript
|
||||||
|
|||||||
+3
-3
@@ -65,12 +65,12 @@ jobs:
|
|||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
output: ${{ runner.temp }}/results
|
output: '${{ runner.temp }}/results'
|
||||||
- name: Upload SARIF
|
- name: Upload SARIF
|
||||||
uses: actions/upload-artifact@v6
|
uses: actions/upload-artifact@v7
|
||||||
with:
|
with:
|
||||||
name: ${{ matrix.os }}-${{ matrix.version }}.sarif.json
|
name: ${{ matrix.os }}-${{ matrix.version }}.sarif.json
|
||||||
path: ${{ runner.temp }}/results/javascript.sarif
|
path: '${{ runner.temp }}/results/javascript.sarif'
|
||||||
retention-days: 7
|
retention-days: 7
|
||||||
- name: Check results
|
- name: Check results
|
||||||
run: |
|
run: |
|
||||||
|
|||||||
Generated
+1
-1
@@ -63,7 +63,7 @@ jobs:
|
|||||||
languages: C#,java-kotlin,swift,typescript
|
languages: C#,java-kotlin,swift,typescript
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
|
|
||||||
- name: Check languages
|
- name: 'Check languages'
|
||||||
run: |
|
run: |
|
||||||
expected_languages="csharp,java,swift,javascript"
|
expected_languages="csharp,java,swift,javascript"
|
||||||
actual_languages=$(jq -r '.languages | join(",")' "$RUNNER_TEMP"/config)
|
actual_languages=$(jq -r '.languages | join(",")' "$RUNNER_TEMP"/config)
|
||||||
|
|||||||
Generated
+21
-37
@@ -25,45 +25,34 @@ on:
|
|||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
python-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Python to install
|
|
||||||
required: false
|
|
||||||
default: '3.13'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
workflow_call:
|
workflow_call:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
python-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Python to install
|
|
||||||
required: false
|
|
||||||
default: '3.13'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
defaults:
|
defaults:
|
||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: local-bundle-${{github.ref}}-${{inputs.dotnet-version}}-${{inputs.go-version}}
|
||||||
local-bundle-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
local-bundle:
|
local-bundle:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -82,6 +71,15 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v6
|
||||||
|
- name: Install .NET
|
||||||
|
uses: actions/setup-dotnet@v5
|
||||||
|
with:
|
||||||
|
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||||
|
- name: Install Go
|
||||||
|
uses: actions/setup-go@v6
|
||||||
|
with:
|
||||||
|
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||||
|
cache: false
|
||||||
- name: Prepare test
|
- name: Prepare test
|
||||||
id: prepare-test
|
id: prepare-test
|
||||||
uses: ./.github/actions/prepare-test
|
uses: ./.github/actions/prepare-test
|
||||||
@@ -89,27 +87,13 @@ jobs:
|
|||||||
version: ${{ matrix.version }}
|
version: ${{ matrix.version }}
|
||||||
use-all-platform-bundle: 'false'
|
use-all-platform-bundle: 'false'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- name: Install Go
|
|
||||||
uses: actions/setup-go@v6
|
|
||||||
with:
|
|
||||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
|
||||||
cache: false
|
|
||||||
- name: Install Python
|
|
||||||
if: matrix.version != 'nightly-latest'
|
|
||||||
uses: actions/setup-python@v6
|
|
||||||
with:
|
|
||||||
python-version: ${{ inputs.python-version || '3.13' }}
|
|
||||||
- name: Install .NET
|
|
||||||
uses: actions/setup-dotnet@v5
|
|
||||||
with:
|
|
||||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
|
||||||
- name: Fetch latest CodeQL bundle
|
- name: Fetch latest CodeQL bundle
|
||||||
run: |
|
run: |
|
||||||
wget https://github.com/github/codeql-action/releases/latest/download/codeql-bundle-linux64.tar.zst
|
wget https://github.com/github/codeql-action/releases/latest/download/codeql-bundle-linux64.tar.zst
|
||||||
- id: init
|
- id: init
|
||||||
uses: ./../action/init
|
uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
# Swift is not supported on Ubuntu so we manually exclude it from the list here
|
# Swift is not supported on Ubuntu so we manually exclude it from the list here
|
||||||
languages: cpp,csharp,go,java,javascript,python,ruby
|
languages: cpp,csharp,go,java,javascript,python,ruby
|
||||||
tools: ./codeql-bundle-linux64.tar.zst
|
tools: ./codeql-bundle-linux64.tar.zst
|
||||||
- name: Build code
|
- name: Build code
|
||||||
|
|||||||
+38
-47
@@ -25,86 +25,75 @@ on:
|
|||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
python-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Python to install
|
|
||||||
required: false
|
|
||||||
default: '3.13'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
workflow_call:
|
workflow_call:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
python-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Python to install
|
|
||||||
required: false
|
|
||||||
default: '3.13'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
defaults:
|
defaults:
|
||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: multi-language-autodetect-${{github.ref}}-${{inputs.dotnet-version}}-${{inputs.go-version}}
|
||||||
multi-language-autodetect-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
multi-language-autodetect:
|
multi-language-autodetect:
|
||||||
strategy:
|
strategy:
|
||||||
fail-fast: false
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
include:
|
include:
|
||||||
- os: macos-latest
|
|
||||||
version: stable-v2.17.6
|
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: stable-v2.17.6
|
version: stable-v2.17.6
|
||||||
- os: macos-latest
|
- os: macos-latest
|
||||||
version: stable-v2.18.4
|
version: stable-v2.17.6
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: stable-v2.18.4
|
version: stable-v2.18.4
|
||||||
- os: macos-latest
|
- os: macos-latest
|
||||||
version: stable-v2.19.4
|
version: stable-v2.18.4
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: stable-v2.19.4
|
version: stable-v2.19.4
|
||||||
- os: macos-latest
|
- os: macos-latest
|
||||||
version: stable-v2.20.7
|
version: stable-v2.19.4
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: stable-v2.20.7
|
version: stable-v2.20.7
|
||||||
- os: macos-latest
|
- os: macos-latest
|
||||||
version: stable-v2.21.4
|
version: stable-v2.20.7
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: stable-v2.21.4
|
version: stable-v2.21.4
|
||||||
- os: macos-latest
|
- os: macos-latest
|
||||||
version: stable-v2.22.4
|
version: stable-v2.21.4
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: stable-v2.22.4
|
version: stable-v2.22.4
|
||||||
- os: macos-latest
|
- os: macos-latest
|
||||||
version: default
|
version: stable-v2.22.4
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: default
|
version: default
|
||||||
- os: macos-latest
|
- os: macos-latest
|
||||||
version: linked
|
version: default
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: linked
|
version: linked
|
||||||
- os: macos-latest
|
- os: macos-latest
|
||||||
|
version: linked
|
||||||
|
- os: ubuntu-latest
|
||||||
version: nightly-latest
|
version: nightly-latest
|
||||||
- os: ubuntu-latest
|
- os: macos-latest
|
||||||
version: nightly-latest
|
version: nightly-latest
|
||||||
name: Multi-language repository
|
name: Multi-language repository
|
||||||
if: github.triggering_actor != 'dependabot[bot]'
|
if: github.triggering_actor != 'dependabot[bot]'
|
||||||
@@ -116,6 +105,15 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v6
|
||||||
|
- name: Install .NET
|
||||||
|
uses: actions/setup-dotnet@v5
|
||||||
|
with:
|
||||||
|
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||||
|
- name: Install Go
|
||||||
|
uses: actions/setup-go@v6
|
||||||
|
with:
|
||||||
|
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||||
|
cache: false
|
||||||
- name: Prepare test
|
- name: Prepare test
|
||||||
id: prepare-test
|
id: prepare-test
|
||||||
uses: ./.github/actions/prepare-test
|
uses: ./.github/actions/prepare-test
|
||||||
@@ -123,20 +121,14 @@ jobs:
|
|||||||
version: ${{ matrix.version }}
|
version: ${{ matrix.version }}
|
||||||
use-all-platform-bundle: 'false'
|
use-all-platform-bundle: 'false'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- name: Install Go
|
- name: Install Python 3.13 for older CLI versions
|
||||||
uses: actions/setup-go@v6
|
# We need Python 3.13 for older CLI versions because they are not compatible with Python 3.14 or newer.
|
||||||
with:
|
# See https://github.com/github/codeql-action/pull/3212
|
||||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
if: matrix.version != 'nightly-latest' && matrix.version != 'linked'
|
||||||
cache: false
|
|
||||||
- name: Install Python
|
|
||||||
if: matrix.version != 'nightly-latest'
|
|
||||||
uses: actions/setup-python@v6
|
uses: actions/setup-python@v6
|
||||||
with:
|
with:
|
||||||
python-version: ${{ inputs.python-version || '3.13' }}
|
python-version: '3.13'
|
||||||
- name: Install .NET
|
|
||||||
uses: actions/setup-dotnet@v5
|
|
||||||
with:
|
|
||||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
|
||||||
- name: Use Xcode 16
|
- name: Use Xcode 16
|
||||||
if: runner.os == 'macOS' && matrix.version != 'nightly-latest'
|
if: runner.os == 'macOS' && matrix.version != 'nightly-latest'
|
||||||
run: sudo xcode-select -s "/Applications/Xcode_16.app"
|
run: sudo xcode-select -s "/Applications/Xcode_16.app"
|
||||||
@@ -144,9 +136,8 @@ jobs:
|
|||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
id: init
|
id: init
|
||||||
with:
|
with:
|
||||||
db-location: ${{ runner.temp }}/customDbLocation
|
db-location: '${{ runner.temp }}/customDbLocation'
|
||||||
languages: ${{ runner.os == 'Linux' && 'cpp,csharp,go,java,javascript,python,ruby'
|
languages: ${{ runner.os == 'Linux' && 'cpp,csharp,go,java,javascript,python,ruby' || '' }}
|
||||||
|| '' }}
|
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
|
|
||||||
- name: Build code
|
- name: Build code
|
||||||
|
|||||||
+23
-40
@@ -25,45 +25,34 @@ on:
|
|||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
python-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Python to install
|
|
||||||
required: false
|
|
||||||
default: '3.13'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
workflow_call:
|
workflow_call:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
python-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Python to install
|
|
||||||
required: false
|
|
||||||
default: '3.13'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
defaults:
|
defaults:
|
||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: packaging-codescanning-config-inputs-js-${{github.ref}}-${{inputs.dotnet-version}}-${{inputs.go-version}}
|
||||||
packaging-codescanning-config-inputs-js-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
packaging-codescanning-config-inputs-js:
|
packaging-codescanning-config-inputs-js:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -86,6 +75,15 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v6
|
||||||
|
- name: Install .NET
|
||||||
|
uses: actions/setup-dotnet@v5
|
||||||
|
with:
|
||||||
|
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||||
|
- name: Install Go
|
||||||
|
uses: actions/setup-go@v6
|
||||||
|
with:
|
||||||
|
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||||
|
cache: false
|
||||||
- name: Install Node.js
|
- name: Install Node.js
|
||||||
uses: actions/setup-node@v6
|
uses: actions/setup-node@v6
|
||||||
with:
|
with:
|
||||||
@@ -100,23 +98,9 @@ jobs:
|
|||||||
version: ${{ matrix.version }}
|
version: ${{ matrix.version }}
|
||||||
use-all-platform-bundle: 'false'
|
use-all-platform-bundle: 'false'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- name: Install Go
|
|
||||||
uses: actions/setup-go@v6
|
|
||||||
with:
|
|
||||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
|
||||||
cache: false
|
|
||||||
- name: Install Python
|
|
||||||
if: matrix.version != 'nightly-latest'
|
|
||||||
uses: actions/setup-python@v6
|
|
||||||
with:
|
|
||||||
python-version: ${{ inputs.python-version || '3.13' }}
|
|
||||||
- name: Install .NET
|
|
||||||
uses: actions/setup-dotnet@v5
|
|
||||||
with:
|
|
||||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
config-file: .github/codeql/codeql-config-packaging3.yml
|
config-file: '.github/codeql/codeql-config-packaging3.yml'
|
||||||
packs: +codeql-testing/codeql-pack1@1.0.0
|
packs: +codeql-testing/codeql-pack1@1.0.0
|
||||||
languages: javascript
|
languages: javascript
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
@@ -124,15 +108,14 @@ jobs:
|
|||||||
run: ./build.sh
|
run: ./build.sh
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
output: ${{ runner.temp }}/results
|
output: '${{ runner.temp }}/results'
|
||||||
upload-database: false
|
upload-database: false
|
||||||
|
|
||||||
- name: Check results
|
- name: Check results
|
||||||
uses: ./../action/.github/actions/check-sarif
|
uses: ./../action/.github/actions/check-sarif
|
||||||
with:
|
with:
|
||||||
sarif-file: ${{ runner.temp }}/results/javascript.sarif
|
sarif-file: ${{ runner.temp }}/results/javascript.sarif
|
||||||
queries-run:
|
queries-run: javascript/example/empty-or-one-block,javascript/example/empty-or-one-block,javascript/example/other-query-block,javascript/example/two-block
|
||||||
javascript/example/empty-or-one-block,javascript/example/empty-or-one-block,javascript/example/other-query-block,javascript/example/two-block
|
|
||||||
queries-not-run: foo,bar
|
queries-not-run: foo,bar
|
||||||
|
|
||||||
- name: Assert Results
|
- name: Assert Results
|
||||||
|
|||||||
+23
-25
@@ -25,35 +25,34 @@ on:
|
|||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
workflow_call:
|
workflow_call:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
defaults:
|
defaults:
|
||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: packaging-config-inputs-js-${{github.ref}}-${{inputs.dotnet-version}}-${{inputs.go-version}}
|
||||||
packaging-config-inputs-js-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
packaging-config-inputs-js:
|
packaging-config-inputs-js:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -76,6 +75,15 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v6
|
||||||
|
- name: Install .NET
|
||||||
|
uses: actions/setup-dotnet@v5
|
||||||
|
with:
|
||||||
|
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||||
|
- name: Install Go
|
||||||
|
uses: actions/setup-go@v6
|
||||||
|
with:
|
||||||
|
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||||
|
cache: false
|
||||||
- name: Install Node.js
|
- name: Install Node.js
|
||||||
uses: actions/setup-node@v6
|
uses: actions/setup-node@v6
|
||||||
with:
|
with:
|
||||||
@@ -90,18 +98,9 @@ jobs:
|
|||||||
version: ${{ matrix.version }}
|
version: ${{ matrix.version }}
|
||||||
use-all-platform-bundle: 'false'
|
use-all-platform-bundle: 'false'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- name: Install Go
|
|
||||||
uses: actions/setup-go@v6
|
|
||||||
with:
|
|
||||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
|
||||||
cache: false
|
|
||||||
- name: Install .NET
|
|
||||||
uses: actions/setup-dotnet@v5
|
|
||||||
with:
|
|
||||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
config-file: .github/codeql/codeql-config-packaging3.yml
|
config-file: '.github/codeql/codeql-config-packaging3.yml'
|
||||||
packs: +codeql-testing/codeql-pack1@1.0.0
|
packs: +codeql-testing/codeql-pack1@1.0.0
|
||||||
languages: javascript
|
languages: javascript
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
@@ -109,15 +108,14 @@ jobs:
|
|||||||
run: ./build.sh
|
run: ./build.sh
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
output: ${{ runner.temp }}/results
|
output: '${{ runner.temp }}/results'
|
||||||
upload-database: false
|
upload-database: false
|
||||||
|
|
||||||
- name: Check results
|
- name: Check results
|
||||||
uses: ./../action/.github/actions/check-sarif
|
uses: ./../action/.github/actions/check-sarif
|
||||||
with:
|
with:
|
||||||
sarif-file: ${{ runner.temp }}/results/javascript.sarif
|
sarif-file: ${{ runner.temp }}/results/javascript.sarif
|
||||||
queries-run:
|
queries-run: javascript/example/empty-or-one-block,javascript/example/empty-or-one-block,javascript/example/other-query-block,javascript/example/two-block
|
||||||
javascript/example/empty-or-one-block,javascript/example/empty-or-one-block,javascript/example/other-query-block,javascript/example/two-block
|
|
||||||
queries-not-run: foo,bar
|
queries-not-run: foo,bar
|
||||||
|
|
||||||
- name: Assert Results
|
- name: Assert Results
|
||||||
|
|||||||
+23
-25
@@ -25,35 +25,34 @@ on:
|
|||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
workflow_call:
|
workflow_call:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
defaults:
|
defaults:
|
||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: packaging-config-js-${{github.ref}}-${{inputs.dotnet-version}}-${{inputs.go-version}}
|
||||||
packaging-config-js-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
packaging-config-js:
|
packaging-config-js:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -76,6 +75,15 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v6
|
||||||
|
- name: Install .NET
|
||||||
|
uses: actions/setup-dotnet@v5
|
||||||
|
with:
|
||||||
|
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||||
|
- name: Install Go
|
||||||
|
uses: actions/setup-go@v6
|
||||||
|
with:
|
||||||
|
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||||
|
cache: false
|
||||||
- name: Install Node.js
|
- name: Install Node.js
|
||||||
uses: actions/setup-node@v6
|
uses: actions/setup-node@v6
|
||||||
with:
|
with:
|
||||||
@@ -90,33 +98,23 @@ jobs:
|
|||||||
version: ${{ matrix.version }}
|
version: ${{ matrix.version }}
|
||||||
use-all-platform-bundle: 'false'
|
use-all-platform-bundle: 'false'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- name: Install Go
|
|
||||||
uses: actions/setup-go@v6
|
|
||||||
with:
|
|
||||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
|
||||||
cache: false
|
|
||||||
- name: Install .NET
|
|
||||||
uses: actions/setup-dotnet@v5
|
|
||||||
with:
|
|
||||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
config-file: .github/codeql/codeql-config-packaging.yml
|
config-file: '.github/codeql/codeql-config-packaging.yml'
|
||||||
languages: javascript
|
languages: javascript
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
- name: Build code
|
- name: Build code
|
||||||
run: ./build.sh
|
run: ./build.sh
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
output: ${{ runner.temp }}/results
|
output: '${{ runner.temp }}/results'
|
||||||
upload-database: false
|
upload-database: false
|
||||||
|
|
||||||
- name: Check results
|
- name: Check results
|
||||||
uses: ./../action/.github/actions/check-sarif
|
uses: ./../action/.github/actions/check-sarif
|
||||||
with:
|
with:
|
||||||
sarif-file: ${{ runner.temp }}/results/javascript.sarif
|
sarif-file: ${{ runner.temp }}/results/javascript.sarif
|
||||||
queries-run:
|
queries-run: javascript/example/empty-or-one-block,javascript/example/empty-or-one-block,javascript/example/other-query-block,javascript/example/two-block
|
||||||
javascript/example/empty-or-one-block,javascript/example/empty-or-one-block,javascript/example/other-query-block,javascript/example/two-block
|
|
||||||
queries-not-run: foo,bar
|
queries-not-run: foo,bar
|
||||||
|
|
||||||
- name: Assert Results
|
- name: Assert Results
|
||||||
|
|||||||
+23
-25
@@ -25,35 +25,34 @@ on:
|
|||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
workflow_call:
|
workflow_call:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
defaults:
|
defaults:
|
||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: packaging-inputs-js-${{github.ref}}-${{inputs.dotnet-version}}-${{inputs.go-version}}
|
||||||
packaging-inputs-js-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
packaging-inputs-js:
|
packaging-inputs-js:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -76,6 +75,15 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v6
|
||||||
|
- name: Install .NET
|
||||||
|
uses: actions/setup-dotnet@v5
|
||||||
|
with:
|
||||||
|
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||||
|
- name: Install Go
|
||||||
|
uses: actions/setup-go@v6
|
||||||
|
with:
|
||||||
|
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||||
|
cache: false
|
||||||
- name: Install Node.js
|
- name: Install Node.js
|
||||||
uses: actions/setup-node@v6
|
uses: actions/setup-node@v6
|
||||||
with:
|
with:
|
||||||
@@ -90,18 +98,9 @@ jobs:
|
|||||||
version: ${{ matrix.version }}
|
version: ${{ matrix.version }}
|
||||||
use-all-platform-bundle: 'false'
|
use-all-platform-bundle: 'false'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- name: Install Go
|
|
||||||
uses: actions/setup-go@v6
|
|
||||||
with:
|
|
||||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
|
||||||
cache: false
|
|
||||||
- name: Install .NET
|
|
||||||
uses: actions/setup-dotnet@v5
|
|
||||||
with:
|
|
||||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
config-file: .github/codeql/codeql-config-packaging2.yml
|
config-file: '.github/codeql/codeql-config-packaging2.yml'
|
||||||
languages: javascript
|
languages: javascript
|
||||||
packs: codeql-testing/codeql-pack1@1.0.0, codeql-testing/codeql-pack2, codeql-testing/codeql-pack3:other-query.ql
|
packs: codeql-testing/codeql-pack1@1.0.0, codeql-testing/codeql-pack2, codeql-testing/codeql-pack3:other-query.ql
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
@@ -109,14 +108,13 @@ jobs:
|
|||||||
run: ./build.sh
|
run: ./build.sh
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
output: ${{ runner.temp }}/results
|
output: '${{ runner.temp }}/results'
|
||||||
|
|
||||||
- name: Check results
|
- name: Check results
|
||||||
uses: ./../action/.github/actions/check-sarif
|
uses: ./../action/.github/actions/check-sarif
|
||||||
with:
|
with:
|
||||||
sarif-file: ${{ runner.temp }}/results/javascript.sarif
|
sarif-file: ${{ runner.temp }}/results/javascript.sarif
|
||||||
queries-run:
|
queries-run: javascript/example/empty-or-one-block,javascript/example/empty-or-one-block,javascript/example/other-query-block,javascript/example/two-block
|
||||||
javascript/example/empty-or-one-block,javascript/example/empty-or-one-block,javascript/example/other-query-block,javascript/example/two-block
|
|
||||||
queries-not-run: foo,bar
|
queries-not-run: foo,bar
|
||||||
|
|
||||||
- name: Assert Results
|
- name: Assert Results
|
||||||
|
|||||||
Generated
+21
-38
@@ -25,45 +25,34 @@ on:
|
|||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
python-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Python to install
|
|
||||||
required: false
|
|
||||||
default: '3.13'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
workflow_call:
|
workflow_call:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
python-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Python to install
|
|
||||||
required: false
|
|
||||||
default: '3.13'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
defaults:
|
defaults:
|
||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: remote-config-${{github.ref}}-${{inputs.dotnet-version}}-${{inputs.go-version}}
|
||||||
remote-config-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
remote-config:
|
remote-config:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -84,6 +73,15 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v6
|
||||||
|
- name: Install .NET
|
||||||
|
uses: actions/setup-dotnet@v5
|
||||||
|
with:
|
||||||
|
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||||
|
- name: Install Go
|
||||||
|
uses: actions/setup-go@v6
|
||||||
|
with:
|
||||||
|
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||||
|
cache: false
|
||||||
- name: Prepare test
|
- name: Prepare test
|
||||||
id: prepare-test
|
id: prepare-test
|
||||||
uses: ./.github/actions/prepare-test
|
uses: ./.github/actions/prepare-test
|
||||||
@@ -91,26 +89,11 @@ jobs:
|
|||||||
version: ${{ matrix.version }}
|
version: ${{ matrix.version }}
|
||||||
use-all-platform-bundle: 'false'
|
use-all-platform-bundle: 'false'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- name: Install Go
|
|
||||||
uses: actions/setup-go@v6
|
|
||||||
with:
|
|
||||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
|
||||||
cache: false
|
|
||||||
- name: Install Python
|
|
||||||
if: matrix.version != 'nightly-latest'
|
|
||||||
uses: actions/setup-python@v6
|
|
||||||
with:
|
|
||||||
python-version: ${{ inputs.python-version || '3.13' }}
|
|
||||||
- name: Install .NET
|
|
||||||
uses: actions/setup-dotnet@v5
|
|
||||||
with:
|
|
||||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
languages: cpp,csharp,java,javascript,python
|
languages: cpp,csharp,java,javascript,python
|
||||||
config-file: ${{ github.repository }}/tests/multi-language-repo/.github/codeql/custom-queries.yml@${{
|
config-file: ${{ github.repository }}/tests/multi-language-repo/.github/codeql/custom-queries.yml@${{ github.sha }}
|
||||||
github.sha }}
|
|
||||||
- name: Build code
|
- name: Build code
|
||||||
run: ./build.sh
|
run: ./build.sh
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
|
|||||||
+3
-4
@@ -39,10 +39,10 @@ jobs:
|
|||||||
fail-fast: false
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
include:
|
include:
|
||||||
- os: ubuntu-latest
|
|
||||||
version: default
|
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: linked
|
version: linked
|
||||||
|
- os: ubuntu-latest
|
||||||
|
version: default
|
||||||
- os: ubuntu-latest
|
- os: ubuntu-latest
|
||||||
version: nightly-latest
|
version: nightly-latest
|
||||||
name: Resolve environment
|
name: Resolve environment
|
||||||
@@ -84,8 +84,7 @@ jobs:
|
|||||||
language: javascript-typescript
|
language: javascript-typescript
|
||||||
|
|
||||||
- name: Fail if JavaScript/TypeScript configuration present
|
- name: Fail if JavaScript/TypeScript configuration present
|
||||||
if:
|
if: fromJSON(steps.resolve-environment-js.outputs.environment).configuration.javascript
|
||||||
fromJSON(steps.resolve-environment-js.outputs.environment).configuration.javascript
|
|
||||||
run: exit 1
|
run: exit 1
|
||||||
env:
|
env:
|
||||||
CODEQL_ACTION_TEST_MODE: true
|
CODEQL_ACTION_TEST_MODE: true
|
||||||
|
|||||||
+1
-1
@@ -59,7 +59,7 @@ jobs:
|
|||||||
use-all-platform-bundle: 'false'
|
use-all-platform-bundle: 'false'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- name: Set up Ruby
|
- name: Set up Ruby
|
||||||
uses: ruby/setup-ruby@09a7688d3b55cf0e976497ff046b70949eeaccfd # v1.288.0
|
uses: ruby/setup-ruby@319994f95fa847cf3fb3cd3dbe89f6dcde9f178f # v1.295.0
|
||||||
with:
|
with:
|
||||||
ruby-version: 2.6
|
ruby-version: 2.6
|
||||||
- name: Install Code Scanning integration
|
- name: Install Code Scanning integration
|
||||||
|
|||||||
Generated
+23
-23
@@ -25,34 +25,34 @@ on:
|
|||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
workflow_call:
|
workflow_call:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
defaults:
|
defaults:
|
||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group: split-workflow-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
group: split-workflow-${{github.ref}}-${{inputs.dotnet-version}}-${{inputs.go-version}}
|
||||||
jobs:
|
jobs:
|
||||||
split-workflow:
|
split-workflow:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -81,6 +81,15 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v6
|
||||||
|
- name: Install .NET
|
||||||
|
uses: actions/setup-dotnet@v5
|
||||||
|
with:
|
||||||
|
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||||
|
- name: Install Go
|
||||||
|
uses: actions/setup-go@v6
|
||||||
|
with:
|
||||||
|
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||||
|
cache: false
|
||||||
- name: Prepare test
|
- name: Prepare test
|
||||||
id: prepare-test
|
id: prepare-test
|
||||||
uses: ./.github/actions/prepare-test
|
uses: ./.github/actions/prepare-test
|
||||||
@@ -88,18 +97,9 @@ jobs:
|
|||||||
version: ${{ matrix.version }}
|
version: ${{ matrix.version }}
|
||||||
use-all-platform-bundle: 'false'
|
use-all-platform-bundle: 'false'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- name: Install Go
|
|
||||||
uses: actions/setup-go@v6
|
|
||||||
with:
|
|
||||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
|
||||||
cache: false
|
|
||||||
- name: Install .NET
|
|
||||||
uses: actions/setup-dotnet@v5
|
|
||||||
with:
|
|
||||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
config-file: .github/codeql/codeql-config-packaging3.yml
|
config-file: '.github/codeql/codeql-config-packaging3.yml'
|
||||||
packs: +codeql-testing/codeql-pack1@1.0.0
|
packs: +codeql-testing/codeql-pack1@1.0.0
|
||||||
languages: javascript
|
languages: javascript
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
@@ -108,7 +108,7 @@ jobs:
|
|||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
skip-queries: true
|
skip-queries: true
|
||||||
output: ${{ runner.temp }}/results
|
output: '${{ runner.temp }}/results'
|
||||||
upload-database: false
|
upload-database: false
|
||||||
|
|
||||||
- name: Assert No Results
|
- name: Assert No Results
|
||||||
@@ -119,7 +119,7 @@ jobs:
|
|||||||
fi
|
fi
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
output: ${{ runner.temp }}/results
|
output: '${{ runner.temp }}/results'
|
||||||
upload-database: false
|
upload-database: false
|
||||||
- name: Assert Results
|
- name: Assert Results
|
||||||
run: |
|
run: |
|
||||||
|
|||||||
Generated
+2
-4
@@ -71,8 +71,7 @@ jobs:
|
|||||||
id: proxy
|
id: proxy
|
||||||
uses: ./../action/start-proxy
|
uses: ./../action/start-proxy
|
||||||
with:
|
with:
|
||||||
registry_secrets: '[{ "type": "nuget_feed", "url": "https://api.nuget.org/v3/index.json"
|
registry_secrets: '[{ "type": "nuget_feed", "url": "https://api.nuget.org/v3/index.json" }]'
|
||||||
}]'
|
|
||||||
|
|
||||||
- name: Print proxy outputs
|
- name: Print proxy outputs
|
||||||
run: |
|
run: |
|
||||||
@@ -81,8 +80,7 @@ jobs:
|
|||||||
echo "${{ steps.proxy.outputs.proxy_urls }}"
|
echo "${{ steps.proxy.outputs.proxy_urls }}"
|
||||||
|
|
||||||
- name: Fail if proxy outputs are not set
|
- name: Fail if proxy outputs are not set
|
||||||
if: (!steps.proxy.outputs.proxy_host) || (!steps.proxy.outputs.proxy_port)
|
if: (!steps.proxy.outputs.proxy_host) || (!steps.proxy.outputs.proxy_port) || (!steps.proxy.outputs.proxy_ca_certificate) || (!steps.proxy.outputs.proxy_urls)
|
||||||
|| (!steps.proxy.outputs.proxy_ca_certificate) || (!steps.proxy.outputs.proxy_urls)
|
|
||||||
run: exit 1
|
run: exit 1
|
||||||
env:
|
env:
|
||||||
CODEQL_ACTION_TEST_MODE: true
|
CODEQL_ACTION_TEST_MODE: true
|
||||||
|
|||||||
+8
-15
@@ -49,8 +49,7 @@ jobs:
|
|||||||
if: github.triggering_actor != 'dependabot[bot]'
|
if: github.triggering_actor != 'dependabot[bot]'
|
||||||
permissions:
|
permissions:
|
||||||
contents: read
|
contents: read
|
||||||
security-events: write # needed to upload the SARIF file
|
security-events: write
|
||||||
|
|
||||||
timeout-minutes: 45
|
timeout-minutes: 45
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
@@ -69,26 +68,20 @@ jobs:
|
|||||||
languages: javascript
|
languages: javascript
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
- name: Fail
|
- name: Fail
|
||||||
# We want this job to pass if the Action correctly uploads the SARIF file for
|
# We want this job to pass if the Action correctly uploads the SARIF file for
|
||||||
# the failed run.
|
# the failed run.
|
||||||
# Setting this step to continue on error means that it is marked as completing
|
# Setting this step to continue on error means that it is marked as completing
|
||||||
# successfully, so will not fail the job.
|
# successfully, so will not fail the job.
|
||||||
continue-on-error: true
|
continue-on-error: true
|
||||||
run: exit 1
|
run: exit 1
|
||||||
- uses: ./analyze
|
- uses: ./analyze
|
||||||
# In a real workflow, this step wouldn't run. Since we used `continue-on-error`
|
# In a real workflow, this step wouldn't run. Since we used `continue-on-error`
|
||||||
# above, we manually disable it with an `if` condition.
|
# above, we manually disable it with an `if` condition.
|
||||||
if: false
|
if: false
|
||||||
with:
|
with:
|
||||||
category: /test-codeql-version:${{ matrix.version }}
|
category: '/test-codeql-version:${{ matrix.version }}'
|
||||||
env:
|
env:
|
||||||
# Internal-only environment variable used to indicate that the post-init Action
|
|
||||||
# should expect to upload a SARIF file for the failed run.
|
|
||||||
CODEQL_ACTION_EXPECT_UPLOAD_FAILED_SARIF: true
|
CODEQL_ACTION_EXPECT_UPLOAD_FAILED_SARIF: true
|
||||||
# Make sure the uploading SARIF files feature is enabled.
|
|
||||||
CODEQL_ACTION_UPLOAD_FAILED_SARIF: true
|
CODEQL_ACTION_UPLOAD_FAILED_SARIF: true
|
||||||
# Upload the failed SARIF file as an integration test of the API endpoint.
|
|
||||||
CODEQL_ACTION_TEST_MODE: false
|
CODEQL_ACTION_TEST_MODE: false
|
||||||
# Mark telemetry for this workflow so it can be treated separately.
|
|
||||||
CODEQL_ACTION_TESTING_ENVIRONMENT: codeql-action-pr-checks
|
CODEQL_ACTION_TESTING_ENVIRONMENT: codeql-action-pr-checks
|
||||||
|
|
||||||
|
|||||||
+20
-21
@@ -25,35 +25,34 @@ on:
|
|||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
workflow_call:
|
workflow_call:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
defaults:
|
defaults:
|
||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: swift-custom-build-${{github.ref}}-${{inputs.dotnet-version}}-${{inputs.go-version}}
|
||||||
swift-custom-build-${{github.ref}}-${{inputs.go-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
swift-custom-build:
|
swift-custom-build:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -76,6 +75,15 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v6
|
||||||
|
- name: Install .NET
|
||||||
|
uses: actions/setup-dotnet@v5
|
||||||
|
with:
|
||||||
|
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||||
|
- name: Install Go
|
||||||
|
uses: actions/setup-go@v6
|
||||||
|
with:
|
||||||
|
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||||
|
cache: false
|
||||||
- name: Prepare test
|
- name: Prepare test
|
||||||
id: prepare-test
|
id: prepare-test
|
||||||
uses: ./.github/actions/prepare-test
|
uses: ./.github/actions/prepare-test
|
||||||
@@ -83,15 +91,6 @@ jobs:
|
|||||||
version: ${{ matrix.version }}
|
version: ${{ matrix.version }}
|
||||||
use-all-platform-bundle: 'false'
|
use-all-platform-bundle: 'false'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- name: Install Go
|
|
||||||
uses: actions/setup-go@v6
|
|
||||||
with:
|
|
||||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
|
||||||
cache: false
|
|
||||||
- name: Install .NET
|
|
||||||
uses: actions/setup-dotnet@v5
|
|
||||||
with:
|
|
||||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
|
||||||
- name: Use Xcode 16
|
- name: Use Xcode 16
|
||||||
if: runner.os == 'macOS' && matrix.version != 'nightly-latest'
|
if: runner.os == 'macOS' && matrix.version != 'nightly-latest'
|
||||||
run: sudo xcode-select -s "/Applications/Xcode_16.app"
|
run: sudo xcode-select -s "/Applications/Xcode_16.app"
|
||||||
|
|||||||
+21
-37
@@ -25,45 +25,34 @@ on:
|
|||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
python-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Python to install
|
|
||||||
required: false
|
|
||||||
default: '3.13'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
workflow_call:
|
workflow_call:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
python-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Python to install
|
|
||||||
required: false
|
|
||||||
default: '3.13'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
defaults:
|
defaults:
|
||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: unset-environment-${{github.ref}}-${{inputs.dotnet-version}}-${{inputs.go-version}}
|
||||||
unset-environment-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
unset-environment:
|
unset-environment:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -84,6 +73,15 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v6
|
||||||
|
- name: Install .NET
|
||||||
|
uses: actions/setup-dotnet@v5
|
||||||
|
with:
|
||||||
|
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||||
|
- name: Install Go
|
||||||
|
uses: actions/setup-go@v6
|
||||||
|
with:
|
||||||
|
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||||
|
cache: false
|
||||||
- name: Prepare test
|
- name: Prepare test
|
||||||
id: prepare-test
|
id: prepare-test
|
||||||
uses: ./.github/actions/prepare-test
|
uses: ./.github/actions/prepare-test
|
||||||
@@ -91,25 +89,11 @@ jobs:
|
|||||||
version: ${{ matrix.version }}
|
version: ${{ matrix.version }}
|
||||||
use-all-platform-bundle: 'false'
|
use-all-platform-bundle: 'false'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- name: Install Go
|
|
||||||
uses: actions/setup-go@v6
|
|
||||||
with:
|
|
||||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
|
||||||
cache: false
|
|
||||||
- name: Install Python
|
|
||||||
if: matrix.version != 'nightly-latest'
|
|
||||||
uses: actions/setup-python@v6
|
|
||||||
with:
|
|
||||||
python-version: ${{ inputs.python-version || '3.13' }}
|
|
||||||
- name: Install .NET
|
|
||||||
uses: actions/setup-dotnet@v5
|
|
||||||
with:
|
|
||||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
id: init
|
id: init
|
||||||
with:
|
with:
|
||||||
db-location: ${{ runner.temp }}/customDbLocation
|
db-location: ${{ runner.temp }}/customDbLocation
|
||||||
# Swift is not supported on Ubuntu so we manually exclude it from the list here
|
# Swift is not supported on Ubuntu so we manually exclude it from the list here
|
||||||
languages: cpp,csharp,go,java,javascript,python,ruby
|
languages: cpp,csharp,go,java,javascript,python,ruby
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
- name: Build code
|
- name: Build code
|
||||||
|
|||||||
+26
-43
@@ -25,45 +25,34 @@ on:
|
|||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
python-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Python to install
|
|
||||||
required: false
|
|
||||||
default: '3.13'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
workflow_call:
|
workflow_call:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
python-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Python to install
|
|
||||||
required: false
|
|
||||||
default: '3.13'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
defaults:
|
defaults:
|
||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: upload-ref-sha-input-${{github.ref}}-${{inputs.dotnet-version}}-${{inputs.go-version}}
|
||||||
upload-ref-sha-input-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
upload-ref-sha-input:
|
upload-ref-sha-input:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -82,6 +71,15 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v6
|
||||||
|
- name: Install .NET
|
||||||
|
uses: actions/setup-dotnet@v5
|
||||||
|
with:
|
||||||
|
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||||
|
- name: Install Go
|
||||||
|
uses: actions/setup-go@v6
|
||||||
|
with:
|
||||||
|
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||||
|
cache: false
|
||||||
- name: Prepare test
|
- name: Prepare test
|
||||||
id: prepare-test
|
id: prepare-test
|
||||||
uses: ./.github/actions/prepare-test
|
uses: ./.github/actions/prepare-test
|
||||||
@@ -89,37 +87,22 @@ jobs:
|
|||||||
version: ${{ matrix.version }}
|
version: ${{ matrix.version }}
|
||||||
use-all-platform-bundle: 'false'
|
use-all-platform-bundle: 'false'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- name: Install Go
|
|
||||||
uses: actions/setup-go@v6
|
|
||||||
with:
|
|
||||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
|
||||||
cache: false
|
|
||||||
- name: Install Python
|
|
||||||
if: matrix.version != 'nightly-latest'
|
|
||||||
uses: actions/setup-python@v6
|
|
||||||
with:
|
|
||||||
python-version: ${{ inputs.python-version || '3.13' }}
|
|
||||||
- name: Install .NET
|
|
||||||
uses: actions/setup-dotnet@v5
|
|
||||||
with:
|
|
||||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
languages: cpp,csharp,java,javascript,python
|
languages: cpp,csharp,java,javascript,python
|
||||||
config-file: ${{ github.repository }}/tests/multi-language-repo/.github/codeql/custom-queries.yml@${{
|
config-file: ${{ github.repository }}/tests/multi-language-repo/.github/codeql/custom-queries.yml@${{ github.sha }}
|
||||||
github.sha }}
|
|
||||||
- name: Build code
|
- name: Build code
|
||||||
run: ./build.sh
|
run: ./build.sh
|
||||||
# Generate some SARIF we can upload with the upload-sarif step
|
# Generate some SARIF we can upload with the upload-sarif step
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
ref: refs/heads/main
|
ref: 'refs/heads/main'
|
||||||
sha: 5e235361806c361d4d3f8859e3c897658025a9a2
|
sha: '5e235361806c361d4d3f8859e3c897658025a9a2'
|
||||||
upload: never
|
upload: never
|
||||||
- uses: ./../action/upload-sarif
|
- uses: ./../action/upload-sarif
|
||||||
with:
|
with:
|
||||||
ref: refs/heads/main
|
ref: 'refs/heads/main'
|
||||||
sha: 5e235361806c361d4d3f8859e3c897658025a9a2
|
sha: '5e235361806c361d4d3f8859e3c897658025a9a2'
|
||||||
env:
|
env:
|
||||||
CODEQL_ACTION_TEST_MODE: true
|
CODEQL_ACTION_TEST_MODE: true
|
||||||
|
|||||||
Generated
+38
-56
@@ -25,45 +25,34 @@ on:
|
|||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
python-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Python to install
|
|
||||||
required: false
|
|
||||||
default: '3.13'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
workflow_call:
|
workflow_call:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
python-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Python to install
|
|
||||||
required: false
|
|
||||||
default: '3.13'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
defaults:
|
defaults:
|
||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: upload-sarif-${{github.ref}}-${{inputs.dotnet-version}}-${{inputs.go-version}}
|
||||||
upload-sarif-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
upload-sarif:
|
upload-sarif:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -89,6 +78,15 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v6
|
||||||
|
- name: Install .NET
|
||||||
|
uses: actions/setup-dotnet@v5
|
||||||
|
with:
|
||||||
|
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||||
|
- name: Install Go
|
||||||
|
uses: actions/setup-go@v6
|
||||||
|
with:
|
||||||
|
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||||
|
cache: false
|
||||||
- name: Prepare test
|
- name: Prepare test
|
||||||
id: prepare-test
|
id: prepare-test
|
||||||
uses: ./.github/actions/prepare-test
|
uses: ./.github/actions/prepare-test
|
||||||
@@ -96,20 +94,6 @@ jobs:
|
|||||||
version: ${{ matrix.version }}
|
version: ${{ matrix.version }}
|
||||||
use-all-platform-bundle: 'false'
|
use-all-platform-bundle: 'false'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- name: Install Go
|
|
||||||
uses: actions/setup-go@v6
|
|
||||||
with:
|
|
||||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
|
||||||
cache: false
|
|
||||||
- name: Install Python
|
|
||||||
if: matrix.version != 'nightly-latest'
|
|
||||||
uses: actions/setup-python@v6
|
|
||||||
with:
|
|
||||||
python-version: ${{ inputs.python-version || '3.13' }}
|
|
||||||
- name: Install .NET
|
|
||||||
uses: actions/setup-dotnet@v5
|
|
||||||
with:
|
|
||||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
@@ -117,11 +101,11 @@ jobs:
|
|||||||
analysis-kinds: ${{ matrix.analysis-kinds }}
|
analysis-kinds: ${{ matrix.analysis-kinds }}
|
||||||
- name: Build code
|
- name: Build code
|
||||||
run: ./build.sh
|
run: ./build.sh
|
||||||
# Generate some SARIF we can upload with the upload-sarif step
|
# Generate some SARIF we can upload with the upload-sarif step
|
||||||
- uses: ./../action/analyze
|
- uses: ./../action/analyze
|
||||||
with:
|
with:
|
||||||
ref: refs/heads/main
|
ref: 'refs/heads/main'
|
||||||
sha: 5e235361806c361d4d3f8859e3c897658025a9a2
|
sha: '5e235361806c361d4d3f8859e3c897658025a9a2'
|
||||||
upload: never
|
upload: never
|
||||||
output: ${{ runner.temp }}/results
|
output: ${{ runner.temp }}/results
|
||||||
|
|
||||||
@@ -130,15 +114,15 @@ jobs:
|
|||||||
uses: ./../action/upload-sarif
|
uses: ./../action/upload-sarif
|
||||||
id: upload-sarif
|
id: upload-sarif
|
||||||
with:
|
with:
|
||||||
ref: refs/heads/main
|
ref: 'refs/heads/main'
|
||||||
sha: 5e235361806c361d4d3f8859e3c897658025a9a2
|
sha: '5e235361806c361d4d3f8859e3c897658025a9a2'
|
||||||
sarif_file: ${{ runner.temp }}/results
|
sarif_file: ${{ runner.temp }}/results
|
||||||
category: |
|
category: |
|
||||||
${{ github.workflow }}:upload-sarif/analysis-kinds:${{ matrix.analysis-kinds }}/os:${{ matrix.os }}/version:${{ matrix.version }}/test:all-files/
|
${{ github.workflow }}:upload-sarif/analysis-kinds:${{ matrix.analysis-kinds }}/os:${{ matrix.os }}/version:${{ matrix.version }}/test:all-files/
|
||||||
- name: Fail for missing output from `upload-sarif` step for `code-scanning`
|
- name: 'Fail for missing output from `upload-sarif` step for `code-scanning`'
|
||||||
if: contains(matrix.analysis-kinds, 'code-scanning') && !(fromJSON(steps.upload-sarif.outputs.sarif-ids).code-scanning)
|
if: contains(matrix.analysis-kinds, 'code-scanning') && !(fromJSON(steps.upload-sarif.outputs.sarif-ids).code-scanning)
|
||||||
run: exit 1
|
run: exit 1
|
||||||
- name: Fail for missing output from `upload-sarif` step for `code-quality`
|
- name: 'Fail for missing output from `upload-sarif` step for `code-quality`'
|
||||||
if: contains(matrix.analysis-kinds, 'code-quality') && !(fromJSON(steps.upload-sarif.outputs.sarif-ids).code-quality)
|
if: contains(matrix.analysis-kinds, 'code-quality') && !(fromJSON(steps.upload-sarif.outputs.sarif-ids).code-quality)
|
||||||
run: exit 1
|
run: exit 1
|
||||||
|
|
||||||
@@ -147,28 +131,26 @@ jobs:
|
|||||||
id: upload-single-sarif-code-scanning
|
id: upload-single-sarif-code-scanning
|
||||||
if: contains(matrix.analysis-kinds, 'code-scanning')
|
if: contains(matrix.analysis-kinds, 'code-scanning')
|
||||||
with:
|
with:
|
||||||
ref: refs/heads/main
|
ref: 'refs/heads/main'
|
||||||
sha: 5e235361806c361d4d3f8859e3c897658025a9a2
|
sha: '5e235361806c361d4d3f8859e3c897658025a9a2'
|
||||||
sarif_file: ${{ runner.temp }}/results/javascript.sarif
|
sarif_file: ${{ runner.temp }}/results/javascript.sarif
|
||||||
category: |
|
category: |
|
||||||
${{ github.workflow }}:upload-sarif/analysis-kinds:${{ matrix.analysis-kinds }}/os:${{ matrix.os }}/version:${{ matrix.version }}/test:single-code-scanning/
|
${{ github.workflow }}:upload-sarif/analysis-kinds:${{ matrix.analysis-kinds }}/os:${{ matrix.os }}/version:${{ matrix.version }}/test:single-code-scanning/
|
||||||
- name: Fail for missing output from `upload-single-sarif-code-scanning` step
|
- name: 'Fail for missing output from `upload-single-sarif-code-scanning` step'
|
||||||
if: contains(matrix.analysis-kinds, 'code-scanning') &&
|
if: contains(matrix.analysis-kinds, 'code-scanning') && !(fromJSON(steps.upload-single-sarif-code-scanning.outputs.sarif-ids).code-scanning)
|
||||||
!(fromJSON(steps.upload-single-sarif-code-scanning.outputs.sarif-ids).code-scanning)
|
|
||||||
run: exit 1
|
run: exit 1
|
||||||
- name: Upload single SARIF file for Code Quality
|
- name: Upload single SARIF file for Code Quality
|
||||||
uses: ./../action/upload-sarif
|
uses: ./../action/upload-sarif
|
||||||
id: upload-single-sarif-code-quality
|
id: upload-single-sarif-code-quality
|
||||||
if: contains(matrix.analysis-kinds, 'code-quality')
|
if: contains(matrix.analysis-kinds, 'code-quality')
|
||||||
with:
|
with:
|
||||||
ref: refs/heads/main
|
ref: 'refs/heads/main'
|
||||||
sha: 5e235361806c361d4d3f8859e3c897658025a9a2
|
sha: '5e235361806c361d4d3f8859e3c897658025a9a2'
|
||||||
sarif_file: ${{ runner.temp }}/results/javascript.quality.sarif
|
sarif_file: ${{ runner.temp }}/results/javascript.quality.sarif
|
||||||
category: |
|
category: |
|
||||||
${{ github.workflow }}:upload-sarif/analysis-kinds:${{ matrix.analysis-kinds }}/os:${{ matrix.os }}/version:${{ matrix.version }}/test:single-code-quality/
|
${{ github.workflow }}:upload-sarif/analysis-kinds:${{ matrix.analysis-kinds }}/os:${{ matrix.os }}/version:${{ matrix.version }}/test:single-code-quality/
|
||||||
- name: Fail for missing output from `upload-single-sarif-code-quality` step
|
- name: 'Fail for missing output from `upload-single-sarif-code-quality` step'
|
||||||
if: contains(matrix.analysis-kinds, 'code-quality') &&
|
if: contains(matrix.analysis-kinds, 'code-quality') && !(fromJSON(steps.upload-single-sarif-code-quality.outputs.sarif-ids).code-quality)
|
||||||
!(fromJSON(steps.upload-single-sarif-code-quality.outputs.sarif-ids).code-quality)
|
|
||||||
run: exit 1
|
run: exit 1
|
||||||
|
|
||||||
- name: Change SARIF file extension
|
- name: Change SARIF file extension
|
||||||
@@ -179,12 +161,12 @@ jobs:
|
|||||||
id: upload-single-non-sarif
|
id: upload-single-non-sarif
|
||||||
if: contains(matrix.analysis-kinds, 'code-scanning')
|
if: contains(matrix.analysis-kinds, 'code-scanning')
|
||||||
with:
|
with:
|
||||||
ref: refs/heads/main
|
ref: 'refs/heads/main'
|
||||||
sha: 5e235361806c361d4d3f8859e3c897658025a9a2
|
sha: '5e235361806c361d4d3f8859e3c897658025a9a2'
|
||||||
sarif_file: ${{ runner.temp }}/results/javascript.sarif.json
|
sarif_file: ${{ runner.temp }}/results/javascript.sarif.json
|
||||||
category: |
|
category: |
|
||||||
${{ github.workflow }}:upload-sarif/analysis-kinds:${{ matrix.analysis-kinds }}/os:${{ matrix.os }}/version:${{ matrix.version }}/test:non-sarif/
|
${{ github.workflow }}:upload-sarif/analysis-kinds:${{ matrix.analysis-kinds }}/os:${{ matrix.os }}/version:${{ matrix.version }}/test:non-sarif/
|
||||||
- name: Fail for missing output from `upload-single-non-sarif` step
|
- name: 'Fail for missing output from `upload-single-non-sarif` step'
|
||||||
if: contains(matrix.analysis-kinds, 'code-scanning') && !(fromJSON(steps.upload-single-non-sarif.outputs.sarif-ids).code-scanning)
|
if: contains(matrix.analysis-kinds, 'code-scanning') && !(fromJSON(steps.upload-single-non-sarif.outputs.sarif-ids).code-scanning)
|
||||||
run: exit 1
|
run: exit 1
|
||||||
env:
|
env:
|
||||||
|
|||||||
+24
-39
@@ -25,45 +25,34 @@ on:
|
|||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
python-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Python to install
|
|
||||||
required: false
|
|
||||||
default: '3.13'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
workflow_call:
|
workflow_call:
|
||||||
inputs:
|
inputs:
|
||||||
go-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Go to install
|
|
||||||
required: false
|
|
||||||
default: '>=1.21.0'
|
|
||||||
python-version:
|
|
||||||
type: string
|
|
||||||
description: The version of Python to install
|
|
||||||
required: false
|
|
||||||
default: '3.13'
|
|
||||||
dotnet-version:
|
dotnet-version:
|
||||||
type: string
|
type: string
|
||||||
description: The version of .NET to install
|
description: The version of .NET to install
|
||||||
required: false
|
required: false
|
||||||
default: 9.x
|
default: 9.x
|
||||||
|
go-version:
|
||||||
|
type: string
|
||||||
|
description: The version of Go to install
|
||||||
|
required: false
|
||||||
|
default: '>=1.21.0'
|
||||||
defaults:
|
defaults:
|
||||||
run:
|
run:
|
||||||
shell: bash
|
shell: bash
|
||||||
concurrency:
|
concurrency:
|
||||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||||
group:
|
group: with-checkout-path-${{github.ref}}-${{inputs.dotnet-version}}-${{inputs.go-version}}
|
||||||
with-checkout-path-${{github.ref}}-${{inputs.go-version}}-${{inputs.python-version}}-${{inputs.dotnet-version}}
|
|
||||||
jobs:
|
jobs:
|
||||||
with-checkout-path:
|
with-checkout-path:
|
||||||
strategy:
|
strategy:
|
||||||
@@ -80,8 +69,18 @@ jobs:
|
|||||||
timeout-minutes: 45
|
timeout-minutes: 45
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
|
# This ensures we don't accidentally use the original checkout for any part of the test.
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v6
|
||||||
|
- name: Install .NET
|
||||||
|
uses: actions/setup-dotnet@v5
|
||||||
|
with:
|
||||||
|
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||||
|
- name: Install Go
|
||||||
|
uses: actions/setup-go@v6
|
||||||
|
with:
|
||||||
|
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||||
|
cache: false
|
||||||
- name: Prepare test
|
- name: Prepare test
|
||||||
id: prepare-test
|
id: prepare-test
|
||||||
uses: ./.github/actions/prepare-test
|
uses: ./.github/actions/prepare-test
|
||||||
@@ -89,28 +88,14 @@ jobs:
|
|||||||
version: ${{ matrix.version }}
|
version: ${{ matrix.version }}
|
||||||
use-all-platform-bundle: 'false'
|
use-all-platform-bundle: 'false'
|
||||||
setup-kotlin: 'true'
|
setup-kotlin: 'true'
|
||||||
- name: Install Go
|
|
||||||
uses: actions/setup-go@v6
|
|
||||||
with:
|
|
||||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
|
||||||
cache: false
|
|
||||||
- name: Install Python
|
|
||||||
if: matrix.version != 'nightly-latest'
|
|
||||||
uses: actions/setup-python@v6
|
|
||||||
with:
|
|
||||||
python-version: ${{ inputs.python-version || '3.13' }}
|
|
||||||
- name: Install .NET
|
|
||||||
uses: actions/setup-dotnet@v5
|
|
||||||
with:
|
|
||||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
|
||||||
- name: Delete original checkout
|
- name: Delete original checkout
|
||||||
run: |
|
run: |
|
||||||
# delete the original checkout so we don't accidentally use it.
|
# delete the original checkout so we don't accidentally use it.
|
||||||
# Actions does not support deleting the current working directory, so we
|
# Actions does not support deleting the current working directory, so we
|
||||||
# delete the contents of the directory instead.
|
# delete the contents of the directory instead.
|
||||||
rm -rf ./* .github .git
|
rm -rf ./* .github .git
|
||||||
# Check out the actions repo again, but at a different location.
|
# Check out the actions repo again, but at a different location.
|
||||||
# choose an arbitrary SHA so that we can later test that the commit_oid is not from main
|
# choose an arbitrary SHA so that we can later test that the commit_oid is not from main
|
||||||
- uses: actions/checkout@v6
|
- uses: actions/checkout@v6
|
||||||
with:
|
with:
|
||||||
ref: 474bbf07f9247ffe1856c6a0f94aeeb10e7afee6
|
ref: 474bbf07f9247ffe1856c6a0f94aeeb10e7afee6
|
||||||
@@ -119,7 +104,7 @@ jobs:
|
|||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
with:
|
with:
|
||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
# it's enough to test one compiled language and one interpreted language
|
# it's enough to test one compiled language and one interpreted language
|
||||||
languages: csharp,javascript
|
languages: csharp,javascript
|
||||||
source-root: x/y/z/some-path/tests/multi-language-repo
|
source-root: x/y/z/some-path/tests/multi-language-repo
|
||||||
|
|
||||||
|
|||||||
@@ -31,34 +31,29 @@ jobs:
|
|||||||
|
|
||||||
permissions:
|
permissions:
|
||||||
contents: read
|
contents: read
|
||||||
|
# We currently need `security-events: read` to access feature flags.
|
||||||
|
security-events: read
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v6
|
- uses: actions/checkout@v6
|
||||||
- name: Init with default CodeQL bundle from the VM image
|
- name: Set up default CodeQL bundle
|
||||||
id: init-default
|
id: setup-default
|
||||||
uses: ./init
|
uses: ./setup-codeql
|
||||||
with:
|
- name: Set up linked CodeQL bundle
|
||||||
languages: javascript
|
id: setup-linked
|
||||||
- name: Remove empty database
|
uses: ./setup-codeql
|
||||||
# allows us to run init a second time
|
|
||||||
run: |
|
|
||||||
rm -rf "$RUNNER_TEMP/codeql_databases"
|
|
||||||
- name: Init with latest CodeQL bundle
|
|
||||||
id: init-latest
|
|
||||||
uses: ./init
|
|
||||||
with:
|
with:
|
||||||
tools: linked
|
tools: linked
|
||||||
languages: javascript
|
- name: Compare default and linked CodeQL bundle versions
|
||||||
- name: Compare default and latest CodeQL bundle versions
|
|
||||||
id: compare
|
id: compare
|
||||||
env:
|
env:
|
||||||
CODEQL_DEFAULT: ${{ steps.init-default.outputs.codeql-path }}
|
CODEQL_DEFAULT: ${{ steps.setup-default.outputs.codeql-path }}
|
||||||
CODEQL_LATEST: ${{ steps.init-latest.outputs.codeql-path }}
|
CODEQL_LINKED: ${{ steps.setup-linked.outputs.codeql-path }}
|
||||||
run: |
|
run: |
|
||||||
CODEQL_VERSION_DEFAULT="$("$CODEQL_DEFAULT" version --format terse)"
|
CODEQL_VERSION_DEFAULT="$("$CODEQL_DEFAULT" version --format terse)"
|
||||||
CODEQL_VERSION_LATEST="$("$CODEQL_LATEST" version --format terse)"
|
CODEQL_VERSION_LINKED="$("$CODEQL_LINKED" version --format terse)"
|
||||||
echo "Default CodeQL bundle version is $CODEQL_VERSION_DEFAULT"
|
echo "Default CodeQL bundle version is $CODEQL_VERSION_DEFAULT"
|
||||||
echo "Latest CodeQL bundle version is $CODEQL_VERSION_LATEST"
|
echo "Linked CodeQL bundle version is $CODEQL_VERSION_LINKED"
|
||||||
|
|
||||||
# If we're running on a pull request, run with both bundles, even if `tools: linked` would
|
# If we're running on a pull request, run with both bundles, even if `tools: linked` would
|
||||||
# be the same as `tools: null`. This allows us to make the job for each of the bundles a
|
# be the same as `tools: null`. This allows us to make the job for each of the bundles a
|
||||||
@@ -66,7 +61,7 @@ jobs:
|
|||||||
#
|
#
|
||||||
# If we're running on push or schedule, then we can skip running with `tools: linked` when it would be
|
# If we're running on push or schedule, then we can skip running with `tools: linked` when it would be
|
||||||
# the same as running with `tools: null`.
|
# the same as running with `tools: null`.
|
||||||
if [[ "$GITHUB_EVENT_NAME" != "pull_request" && "$GITHUB_EVENT_NAME" != "merge_group" && "$CODEQL_VERSION_DEFAULT" == "$CODEQL_VERSION_LATEST" ]]; then
|
if [[ "$GITHUB_EVENT_NAME" != "pull_request" && "$GITHUB_EVENT_NAME" != "merge_group" && "$CODEQL_VERSION_DEFAULT" == "$CODEQL_VERSION_LINKED" ]]; then
|
||||||
VERSIONS_JSON='[null]'
|
VERSIONS_JSON='[null]'
|
||||||
else
|
else
|
||||||
VERSIONS_JSON='[null, "linked"]'
|
VERSIONS_JSON='[null, "linked"]'
|
||||||
|
|||||||
@@ -11,6 +11,8 @@ env:
|
|||||||
CODEQL_ACTION_OVERLAY_ANALYSIS: true
|
CODEQL_ACTION_OVERLAY_ANALYSIS: true
|
||||||
CODEQL_ACTION_OVERLAY_ANALYSIS_JAVASCRIPT: false
|
CODEQL_ACTION_OVERLAY_ANALYSIS_JAVASCRIPT: false
|
||||||
CODEQL_ACTION_OVERLAY_ANALYSIS_CODE_SCANNING_JAVASCRIPT: true
|
CODEQL_ACTION_OVERLAY_ANALYSIS_CODE_SCANNING_JAVASCRIPT: true
|
||||||
|
CODEQL_ACTION_OVERLAY_ANALYSIS_STATUS_CHECK: false
|
||||||
|
CODEQL_ACTION_OVERLAY_ANALYSIS_SKIP_RESOURCE_CHECKS: true
|
||||||
|
|
||||||
on:
|
on:
|
||||||
push:
|
push:
|
||||||
|
|||||||
@@ -41,6 +41,8 @@ jobs:
|
|||||||
CODEQL_ACTION_TEST_MODE: true
|
CODEQL_ACTION_TEST_MODE: true
|
||||||
permissions:
|
permissions:
|
||||||
contents: read
|
contents: read
|
||||||
|
# We currently need `security-events: read` to access feature flags.
|
||||||
|
security-events: read
|
||||||
timeout-minutes: 45
|
timeout-minutes: 45
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
@@ -87,7 +89,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Download all artifacts
|
- name: Download all artifacts
|
||||||
uses: actions/download-artifact@v7
|
uses: actions/download-artifact@v8
|
||||||
- name: Check expected artifacts exist
|
- name: Check expected artifacts exist
|
||||||
run: |
|
run: |
|
||||||
LANGUAGES="cpp csharp go java javascript python"
|
LANGUAGES="cpp csharp go java javascript python"
|
||||||
|
|||||||
@@ -40,6 +40,8 @@ jobs:
|
|||||||
timeout-minutes: 45
|
timeout-minutes: 45
|
||||||
permissions:
|
permissions:
|
||||||
contents: read
|
contents: read
|
||||||
|
# We currently need `security-events: read` to access feature flags.
|
||||||
|
security-events: read
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out repository
|
- name: Check out repository
|
||||||
@@ -81,7 +83,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Download all artifacts
|
- name: Download all artifacts
|
||||||
uses: actions/download-artifact@v7
|
uses: actions/download-artifact@v8
|
||||||
- name: Check expected artifacts exist
|
- name: Check expected artifacts exist
|
||||||
run: |
|
run: |
|
||||||
VERSIONS="stable-v2.20.3 default linked nightly-latest"
|
VERSIONS="stable-v2.20.3 default linked nightly-latest"
|
||||||
|
|||||||
@@ -24,7 +24,7 @@ defaults:
|
|||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
merge-back:
|
merge-back:
|
||||||
runs-on: ubuntu-slim
|
runs-on: ubuntu-latest
|
||||||
environment: Automation
|
environment: Automation
|
||||||
if: github.repository == 'github/codeql-action'
|
if: github.repository == 'github/codeql-action'
|
||||||
env:
|
env:
|
||||||
@@ -131,7 +131,7 @@ jobs:
|
|||||||
echo "::endgroup::"
|
echo "::endgroup::"
|
||||||
|
|
||||||
- name: Generate token
|
- name: Generate token
|
||||||
uses: actions/create-github-app-token@v2.2.1
|
uses: actions/create-github-app-token@v3.0.0
|
||||||
id: app-token
|
id: app-token
|
||||||
with:
|
with:
|
||||||
app-id: ${{ vars.AUTOMATION_APP_ID }}
|
app-id: ${{ vars.AUTOMATION_APP_ID }}
|
||||||
|
|||||||
@@ -42,11 +42,6 @@ jobs:
|
|||||||
node-version: ${{ matrix.node-version }}
|
node-version: ${{ matrix.node-version }}
|
||||||
cache: 'npm'
|
cache: 'npm'
|
||||||
|
|
||||||
- name: Set up Python
|
|
||||||
uses: actions/setup-python@v6
|
|
||||||
with:
|
|
||||||
python-version: 3.11
|
|
||||||
|
|
||||||
- name: Install dependencies
|
- name: Install dependencies
|
||||||
run: |
|
run: |
|
||||||
# Use the system Bash shell to ensure we can run commands like `npm ci`
|
# Use the system Bash shell to ensure we can run commands like `npm ci`
|
||||||
@@ -57,18 +52,13 @@ jobs:
|
|||||||
- name: Verify compiled JS up to date
|
- name: Verify compiled JS up to date
|
||||||
run: .github/workflows/script/check-js.sh
|
run: .github/workflows/script/check-js.sh
|
||||||
|
|
||||||
- name: Verify PR checks up to date
|
|
||||||
if: always()
|
|
||||||
run: .github/workflows/script/verify-pr-checks.sh
|
|
||||||
|
|
||||||
- name: Run unit tests
|
- name: Run unit tests
|
||||||
if: always()
|
if: always()
|
||||||
run: npm test
|
run: npm run test-coverage
|
||||||
|
|
||||||
- name: Run pr-checks tests
|
- name: Check code coverage
|
||||||
if: always()
|
if: always()
|
||||||
working-directory: pr-checks
|
run: npm run coverage
|
||||||
run: python -m unittest discover
|
|
||||||
|
|
||||||
- name: Lint
|
- name: Lint
|
||||||
if: always() && matrix.os != 'windows-latest'
|
if: always() && matrix.os != 'windows-latest'
|
||||||
@@ -81,6 +71,43 @@ jobs:
|
|||||||
sarif_file: eslint.sarif
|
sarif_file: eslint.sarif
|
||||||
category: eslint
|
category: eslint
|
||||||
|
|
||||||
|
# Verifying the PR checks are up-to-date requires Node 24. The PR checks are not dependent
|
||||||
|
# on the main codebase and therefore do not need to be run as part of the same matrix that
|
||||||
|
# we use for the `unit-tests` job.
|
||||||
|
verify-pr-checks:
|
||||||
|
name: Verify PR checks
|
||||||
|
if: github.triggering_actor != 'dependabot[bot]'
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
runs-on: ubuntu-slim
|
||||||
|
timeout-minutes: 10
|
||||||
|
|
||||||
|
steps:
|
||||||
|
- name: Prepare git (Windows)
|
||||||
|
if: runner.os == 'Windows'
|
||||||
|
run: git config --global core.autocrlf false
|
||||||
|
|
||||||
|
- name: Checkout repository
|
||||||
|
uses: actions/checkout@v6
|
||||||
|
|
||||||
|
- name: Set up Node.js
|
||||||
|
uses: actions/setup-node@v6
|
||||||
|
with:
|
||||||
|
node-version: 24
|
||||||
|
cache: 'npm'
|
||||||
|
|
||||||
|
- name: Install dependencies
|
||||||
|
run: npm ci
|
||||||
|
|
||||||
|
- name: Verify PR checks up to date
|
||||||
|
if: always()
|
||||||
|
run: .github/workflows/script/verify-pr-checks.sh
|
||||||
|
|
||||||
|
- name: Run pr-checks tests
|
||||||
|
if: always()
|
||||||
|
working-directory: pr-checks
|
||||||
|
run: npx tsx --test
|
||||||
|
|
||||||
check-node-version:
|
check-node-version:
|
||||||
if: github.triggering_actor != 'dependabot[bot]'
|
if: github.triggering_actor != 'dependabot[bot]'
|
||||||
name: Check Action Node versions
|
name: Check Action Node versions
|
||||||
|
|||||||
@@ -29,7 +29,7 @@ defaults:
|
|||||||
jobs:
|
jobs:
|
||||||
prepare:
|
prepare:
|
||||||
name: "Prepare release"
|
name: "Prepare release"
|
||||||
runs-on: ubuntu-slim
|
runs-on: ubuntu-latest
|
||||||
if: github.repository == 'github/codeql-action'
|
if: github.repository == 'github/codeql-action'
|
||||||
|
|
||||||
permissions:
|
permissions:
|
||||||
|
|||||||
@@ -26,6 +26,8 @@ jobs:
|
|||||||
timeout-minutes: 45
|
timeout-minutes: 45
|
||||||
permissions:
|
permissions:
|
||||||
contents: read
|
contents: read
|
||||||
|
# We currently need `security-events: read` to access feature flags.
|
||||||
|
security-events: read
|
||||||
runs-on: windows-latest
|
runs-on: windows-latest
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
|
|||||||
@@ -29,6 +29,12 @@ jobs:
|
|||||||
fetch-depth: 0
|
fetch-depth: 0
|
||||||
ref: ${{ env.HEAD_REF }}
|
ref: ${{ env.HEAD_REF }}
|
||||||
|
|
||||||
|
- name: Set up Node.js
|
||||||
|
uses: actions/setup-node@v6
|
||||||
|
with:
|
||||||
|
node-version: 24
|
||||||
|
cache: 'npm'
|
||||||
|
|
||||||
- name: Remove label
|
- name: Remove label
|
||||||
if: github.event_name == 'pull_request'
|
if: github.event_name == 'pull_request'
|
||||||
env:
|
env:
|
||||||
@@ -49,9 +55,18 @@ jobs:
|
|||||||
git fetch origin "$BASE_BRANCH"
|
git fetch origin "$BASE_BRANCH"
|
||||||
|
|
||||||
# Allow merge conflicts in `lib`, since rebuilding should resolve them.
|
# Allow merge conflicts in `lib`, since rebuilding should resolve them.
|
||||||
git merge "origin/$BASE_BRANCH" || echo "Merge conflicts detected, continuing."
|
git merge "origin/$BASE_BRANCH"
|
||||||
MERGE_RESULT=$?
|
MERGE_RESULT=$?
|
||||||
|
|
||||||
|
if [ "$MERGE_RESULT" -eq 0 ]; then
|
||||||
|
echo "Merge succeeded cleanly."
|
||||||
|
elif [ "$MERGE_RESULT" -eq 1 ]; then
|
||||||
|
echo "Merge conflicts detected (exit code $MERGE_RESULT), continuing."
|
||||||
|
else
|
||||||
|
echo "git merge failed with unexpected exit code $MERGE_RESULT."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
if [ "$MERGE_RESULT" -ne 0 ]; then
|
if [ "$MERGE_RESULT" -ne 0 ]; then
|
||||||
echo "merge-in-progress=true" >> $GITHUB_OUTPUT
|
echo "merge-in-progress=true" >> $GITHUB_OUTPUT
|
||||||
|
|
||||||
@@ -73,24 +88,17 @@ jobs:
|
|||||||
npm run lint -- --fix
|
npm run lint -- --fix
|
||||||
npm run build
|
npm run build
|
||||||
|
|
||||||
- name: Set up Python
|
|
||||||
uses: actions/setup-python@v6
|
|
||||||
with:
|
|
||||||
python-version: 3.11
|
|
||||||
|
|
||||||
- name: Sync back version updates to generated workflows
|
- name: Sync back version updates to generated workflows
|
||||||
# Only sync back versions on Dependabot update PRs
|
# Only sync back versions on Dependabot update PRs
|
||||||
if: startsWith(env.HEAD_REF, 'dependabot/')
|
if: startsWith(env.HEAD_REF, 'dependabot/')
|
||||||
working-directory: pr-checks
|
working-directory: pr-checks
|
||||||
run: |
|
run: |
|
||||||
python3 sync_back.py -v
|
npm ci
|
||||||
|
npx tsx sync-back.ts --verbose
|
||||||
|
|
||||||
- name: Generate workflows
|
- name: Generate workflows
|
||||||
working-directory: pr-checks
|
working-directory: pr-checks
|
||||||
run: |
|
run: ./sync.sh
|
||||||
python -m pip install --upgrade pip
|
|
||||||
pip install ruamel.yaml==0.17.31
|
|
||||||
python3 sync.py
|
|
||||||
|
|
||||||
- name: "Merge in progress: Finish merge and push"
|
- name: "Merge in progress: Finish merge and push"
|
||||||
if: steps.merge.outputs.merge-in-progress == 'true'
|
if: steps.merge.outputs.merge-in-progress == 'true'
|
||||||
@@ -111,7 +119,7 @@ jobs:
|
|||||||
# Otherwise, just commit the changes.
|
# Otherwise, just commit the changes.
|
||||||
if git rev-parse --verify MERGE_HEAD >/dev/null 2>&1; then
|
if git rev-parse --verify MERGE_HEAD >/dev/null 2>&1; then
|
||||||
echo "In progress merge detected, finishing it up."
|
echo "In progress merge detected, finishing it up."
|
||||||
git merge --continue --no-edit
|
git commit --no-edit
|
||||||
else
|
else
|
||||||
echo "No in-progress merge detected, committing changes."
|
echo "No in-progress merge detected, committing changes."
|
||||||
git commit -m "Rebuild"
|
git commit -m "Rebuild"
|
||||||
|
|||||||
@@ -136,7 +136,7 @@ jobs:
|
|||||||
|
|
||||||
- name: Generate token
|
- name: Generate token
|
||||||
if: github.event_name == 'workflow_dispatch'
|
if: github.event_name == 'workflow_dispatch'
|
||||||
uses: actions/create-github-app-token@v2.2.1
|
uses: actions/create-github-app-token@v3.0.0
|
||||||
id: app-token
|
id: app-token
|
||||||
with:
|
with:
|
||||||
app-id: ${{ vars.AUTOMATION_APP_ID }}
|
app-id: ${{ vars.AUTOMATION_APP_ID }}
|
||||||
|
|||||||
@@ -1,64 +0,0 @@
|
|||||||
#!/usr/bin/env bash
|
|
||||||
# Update the required checks based on the current branch.
|
|
||||||
|
|
||||||
set -euo pipefail
|
|
||||||
|
|
||||||
SCRIPT_DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" >/dev/null 2>&1 && pwd )"
|
|
||||||
REPO_DIR="$(dirname "$SCRIPT_DIR")"
|
|
||||||
GRANDPARENT_DIR="$(dirname "$REPO_DIR")"
|
|
||||||
source "$GRANDPARENT_DIR/releases.ini"
|
|
||||||
|
|
||||||
if ! gh auth status 2>/dev/null; then
|
|
||||||
gh auth status
|
|
||||||
echo "Failed: Not authorized. This script requires admin access to github/codeql-action through the gh CLI."
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [ "$#" -eq 1 ]; then
|
|
||||||
# If we were passed an argument, use that as the SHA
|
|
||||||
GITHUB_SHA="$1"
|
|
||||||
elif [ "$#" -gt 1 ]; then
|
|
||||||
echo "Usage: $0 [SHA]"
|
|
||||||
echo "Update the required checks based on the SHA, or main."
|
|
||||||
exit 1
|
|
||||||
elif [ -z "$GITHUB_SHA" ]; then
|
|
||||||
# If we don't have a SHA, use main
|
|
||||||
GITHUB_SHA="$(git rev-parse main)"
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo "Getting checks for $GITHUB_SHA"
|
|
||||||
|
|
||||||
# Ignore any checks with "https://", CodeQL, LGTM, Update, and ESLint checks.
|
|
||||||
CHECKS="$(gh api repos/github/codeql-action/commits/"${GITHUB_SHA}"/check-runs --paginate | jq --slurp --compact-output --raw-output '[.[].check_runs.[] | select(.conclusion != "skipped") | .name | select(contains("https://") or . == "CodeQL" or . == "Dependabot" or . == "check-expected-release-files" or contains("Update") or contains("ESLint") or contains("update") or contains("test-setup-python-scripts") or . == "Agent" or . == "Cleanup artifacts" or . == "Prepare" or . == "Upload results" or . == "Label PR with size" | not)] | unique | sort')"
|
|
||||||
|
|
||||||
echo "$CHECKS" | jq
|
|
||||||
|
|
||||||
# Fail if there are no checks
|
|
||||||
if [ -z "$CHECKS" ] || [ "$(echo "$CHECKS" | jq '. | length')" -eq 0 ]; then
|
|
||||||
echo "No checks found for $GITHUB_SHA"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo "{\"contexts\": ${CHECKS}}" > checks.json
|
|
||||||
|
|
||||||
echo "Updating main"
|
|
||||||
gh api --silent -X "PATCH" "repos/github/codeql-action/branches/main/protection/required_status_checks" --input checks.json
|
|
||||||
|
|
||||||
# list all branchs on origin remote matching releases/v*
|
|
||||||
BRANCHES="$(git ls-remote --heads origin 'releases/v*' | sed 's?.*refs/heads/??' | sort -V)"
|
|
||||||
|
|
||||||
for BRANCH in $BRANCHES; do
|
|
||||||
|
|
||||||
# strip exact 'releases/v' prefix from $BRANCH using count of characters
|
|
||||||
VERSION="${BRANCH:10}"
|
|
||||||
|
|
||||||
if [ "$VERSION" -lt "$OLDEST_SUPPORTED_MAJOR_VERSION" ]; then
|
|
||||||
echo "Skipping $BRANCH"
|
|
||||||
continue
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo "Updating $BRANCH"
|
|
||||||
gh api --silent -X "PATCH" "repos/github/codeql-action/branches/$BRANCH/protection/required_status_checks" --input checks.json
|
|
||||||
done
|
|
||||||
|
|
||||||
rm checks.json
|
|
||||||
@@ -19,7 +19,7 @@ if [ ! -z "$(git status --porcelain)" ]; then
|
|||||||
# If we get a fail here then the PR needs attention
|
# If we get a fail here then the PR needs attention
|
||||||
git diff
|
git diff
|
||||||
git status
|
git status
|
||||||
>&2 echo "Failed: PR checks are not up to date. Run 'cd pr-checks && python3 sync.py' to update"
|
>&2 echo "Failed: PR checks are not up to date. Run 'cd pr-checks && ./sync.sh' to update"
|
||||||
|
|
||||||
echo "### Generated workflows diff" >> $GITHUB_STEP_SUMMARY
|
echo "### Generated workflows diff" >> $GITHUB_STEP_SUMMARY
|
||||||
echo "" >> $GITHUB_STEP_SUMMARY
|
echo "" >> $GITHUB_STEP_SUMMARY
|
||||||
|
|||||||
@@ -20,7 +20,7 @@ defaults:
|
|||||||
jobs:
|
jobs:
|
||||||
update-bundle:
|
update-bundle:
|
||||||
if: github.event.release.prerelease && startsWith(github.event.release.tag_name, 'codeql-bundle-')
|
if: github.event.release.prerelease && startsWith(github.event.release.tag_name, 'codeql-bundle-')
|
||||||
runs-on: ubuntu-slim
|
runs-on: ubuntu-latest
|
||||||
permissions:
|
permissions:
|
||||||
contents: write # needed to push commits
|
contents: write # needed to push commits
|
||||||
pull-requests: write # needed to create pull requests
|
pull-requests: write # needed to create pull requests
|
||||||
|
|||||||
@@ -26,7 +26,7 @@ jobs:
|
|||||||
|
|
||||||
update:
|
update:
|
||||||
timeout-minutes: 45
|
timeout-minutes: 45
|
||||||
runs-on: ubuntu-slim
|
runs-on: ubuntu-latest
|
||||||
if: github.event_name == 'workflow_dispatch'
|
if: github.event_name == 'workflow_dispatch'
|
||||||
needs: [prepare]
|
needs: [prepare]
|
||||||
env:
|
env:
|
||||||
@@ -77,7 +77,7 @@ jobs:
|
|||||||
|
|
||||||
backport:
|
backport:
|
||||||
timeout-minutes: 45
|
timeout-minutes: 45
|
||||||
runs-on: ubuntu-slim
|
runs-on: ubuntu-latest
|
||||||
environment: Automation
|
environment: Automation
|
||||||
needs: [prepare]
|
needs: [prepare]
|
||||||
if: ${{ (github.event_name == 'push') && needs.prepare.outputs.backport_target_branches != '[]' }}
|
if: ${{ (github.event_name == 'push') && needs.prepare.outputs.backport_target_branches != '[]' }}
|
||||||
@@ -93,7 +93,7 @@ jobs:
|
|||||||
pull-requests: write # needed to create pull request
|
pull-requests: write # needed to create pull request
|
||||||
steps:
|
steps:
|
||||||
- name: Generate token
|
- name: Generate token
|
||||||
uses: actions/create-github-app-token@v2.2.1
|
uses: actions/create-github-app-token@v3.0.0
|
||||||
id: app-token
|
id: app-token
|
||||||
with:
|
with:
|
||||||
app-id: ${{ vars.AUTOMATION_APP_ID }}
|
app-id: ${{ vars.AUTOMATION_APP_ID }}
|
||||||
|
|||||||
@@ -2,6 +2,8 @@
|
|||||||
node_modules/
|
node_modules/
|
||||||
# Build output for tests
|
# Build output for tests
|
||||||
build/
|
build/
|
||||||
|
# Code coverage information
|
||||||
|
coverage/
|
||||||
# Java build files
|
# Java build files
|
||||||
.gradle/
|
.gradle/
|
||||||
*.class
|
*.class
|
||||||
|
|||||||
Vendored
+30
@@ -0,0 +1,30 @@
|
|||||||
|
{
|
||||||
|
// Place your codeql-action workspace snippets here. Each snippet is defined under a snippet name and has a scope, prefix, body and
|
||||||
|
// description. Add comma separated ids of the languages where the snippet is applicable in the scope field. If scope
|
||||||
|
// is left empty or omitted, the snippet gets applied to all languages. The prefix is what is
|
||||||
|
// used to trigger the snippet and the body will be expanded and inserted. Possible variables are:
|
||||||
|
// $1, $2 for tab stops, $0 for the final cursor position, and ${1:label}, ${2:another} for placeholders.
|
||||||
|
// Placeholders with the same ids are connected.
|
||||||
|
// Example:
|
||||||
|
// "Print to console": {
|
||||||
|
// "scope": "javascript,typescript",
|
||||||
|
// "prefix": "log",
|
||||||
|
// "body": [
|
||||||
|
// "console.log('$1');",
|
||||||
|
// "$2"
|
||||||
|
// ],
|
||||||
|
// "description": "Log output to console"
|
||||||
|
// }
|
||||||
|
"Test Macro": {
|
||||||
|
"scope": "javascript, typescript",
|
||||||
|
"prefix": "testMacro",
|
||||||
|
"body": [
|
||||||
|
"const ${1:nameMacro} = test.macro({",
|
||||||
|
" exec: async (t: ExecutionContext<unknown>) => {},",
|
||||||
|
"",
|
||||||
|
" title: (providedTitle = \"\") => `${2:common title} - \\${providedTitle}`,",
|
||||||
|
"});",
|
||||||
|
],
|
||||||
|
"description": "An Ava test macro",
|
||||||
|
},
|
||||||
|
}
|
||||||
@@ -2,6 +2,47 @@
|
|||||||
|
|
||||||
See the [releases page](https://github.com/github/codeql-action/releases) for the relevant changes to the CodeQL CLI and language packs.
|
See the [releases page](https://github.com/github/codeql-action/releases) for the relevant changes to the CodeQL CLI and language packs.
|
||||||
|
|
||||||
|
## [UNRELEASED]
|
||||||
|
|
||||||
|
No user facing changes.
|
||||||
|
|
||||||
|
## 4.35.1 - 27 Mar 2026
|
||||||
|
|
||||||
|
- Fix incorrect minimum required Git version for [improved incremental analysis](https://github.com/github/roadmap/issues/1158): it should have been 2.36.0, not 2.11.0. [#3781](https://github.com/github/codeql-action/pull/3781)
|
||||||
|
|
||||||
|
## 4.35.0 - 27 Mar 2026
|
||||||
|
|
||||||
|
- Reduced the minimum Git version required for [improved incremental analysis](https://github.com/github/roadmap/issues/1158) from 2.38.0 to 2.11.0. [#3767](https://github.com/github/codeql-action/pull/3767)
|
||||||
|
- Update default CodeQL bundle version to [2.25.1](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.1). [#3773](https://github.com/github/codeql-action/pull/3773)
|
||||||
|
|
||||||
|
## 4.34.1 - 20 Mar 2026
|
||||||
|
|
||||||
|
- Downgrade default CodeQL bundle version to [2.24.3](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.3) due to issues with a small percentage of Actions and JavaScript analyses. [#3762](https://github.com/github/codeql-action/pull/3762)
|
||||||
|
|
||||||
|
## 4.34.0 - 20 Mar 2026
|
||||||
|
|
||||||
|
- Added an experimental change which disables TRAP caching when [improved incremental analysis](https://github.com/github/roadmap/issues/1158) is enabled, since improved incremental analysis supersedes TRAP caching. This will improve performance and reduce Actions cache usage. We expect to roll this change out to everyone in March. [#3569](https://github.com/github/codeql-action/pull/3569)
|
||||||
|
- We are rolling out improved incremental analysis to C/C++ analyses that use build mode `none`. We expect this rollout to be complete by the end of April 2026. [#3584](https://github.com/github/codeql-action/pull/3584)
|
||||||
|
- Update default CodeQL bundle version to [2.25.0](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.0). [#3585](https://github.com/github/codeql-action/pull/3585)
|
||||||
|
|
||||||
|
## 4.33.0 - 16 Mar 2026
|
||||||
|
|
||||||
|
- Upcoming change: Starting April 2026, the CodeQL Action will skip collecting file coverage information on pull requests to improve analysis performance. File coverage information will still be computed on non-PR analyses. Pull request analyses will log a warning about this upcoming change. [#3562](https://github.com/github/codeql-action/pull/3562)
|
||||||
|
|
||||||
|
To opt out of this change:
|
||||||
|
- **Repositories owned by an organization:** Create a custom repository property with the name `github-codeql-file-coverage-on-prs` and the type "True/false", then set this property to `true` in the repository's settings. For more information, see [Managing custom properties for repositories in your organization](https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization). Alternatively, if you are using an advanced setup workflow, you can set the `CODEQL_ACTION_FILE_COVERAGE_ON_PRS` environment variable to `true` in your workflow.
|
||||||
|
- **User-owned repositories using default setup:** Switch to an advanced setup workflow and set the `CODEQL_ACTION_FILE_COVERAGE_ON_PRS` environment variable to `true` in your workflow.
|
||||||
|
- **User-owned repositories using advanced setup:** Set the `CODEQL_ACTION_FILE_COVERAGE_ON_PRS` environment variable to `true` in your workflow.
|
||||||
|
- Fixed [a bug](https://github.com/github/codeql-action/issues/3555) which caused the CodeQL Action to fail loading repository properties if a "Multi select" repository property was configured for the repository. [#3557](https://github.com/github/codeql-action/pull/3557)
|
||||||
|
- The CodeQL Action now loads [custom repository properties](https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization) on GitHub Enterprise Server, enabling the customization of features such as `github-codeql-disable-overlay` that was previously only available on GitHub.com. [#3559](https://github.com/github/codeql-action/pull/3559)
|
||||||
|
- Once [private package registries](https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries) can be configured with OIDC-based authentication for organizations, the CodeQL Action will now be able to accept such configurations. [#3563](https://github.com/github/codeql-action/pull/3563)
|
||||||
|
- Fixed the retry mechanism for database uploads. Previously this would fail with the error "Response body object should not be disturbed or locked". [#3564](https://github.com/github/codeql-action/pull/3564)
|
||||||
|
- A warning is now emitted if the CodeQL Action detects a repository property whose name suggests that it relates to the CodeQL Action, but which is not one of the properties recognised by the current version of the CodeQL Action. [#3570](https://github.com/github/codeql-action/pull/3570)
|
||||||
|
|
||||||
|
## 4.32.6 - 05 Mar 2026
|
||||||
|
|
||||||
|
- Update default CodeQL bundle version to [2.24.3](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.3). [#3548](https://github.com/github/codeql-action/pull/3548)
|
||||||
|
|
||||||
## 4.32.5 - 02 Mar 2026
|
## 4.32.5 - 02 Mar 2026
|
||||||
|
|
||||||
- Repositories owned by an organization can now set up the `github-codeql-disable-overlay` custom repository property to disable [improved incremental analysis for CodeQL](https://github.com/github/roadmap/issues/1158). First, create a custom repository property with the name `github-codeql-disable-overlay` and the type "True/false" in the organization's settings. Then in the repository's settings, set this property to `true` to disable improved incremental analysis. For more information, see [Managing custom properties for repositories in your organization](https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization). This feature is not yet available on GitHub Enterprise Server. [#3507](https://github.com/github/codeql-action/pull/3507)
|
- Repositories owned by an organization can now set up the `github-codeql-disable-overlay` custom repository property to disable [improved incremental analysis for CodeQL](https://github.com/github/roadmap/issues/1158). First, create a custom repository property with the name `github-codeql-disable-overlay` and the type "True/false" in the organization's settings. Then in the repository's settings, set this property to `true` to disable improved incremental analysis. For more information, see [Managing custom properties for repositories in your organization](https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization). This feature is not yet available on GitHub Enterprise Server. [#3507](https://github.com/github/codeql-action/pull/3507)
|
||||||
|
|||||||
+8
-6
@@ -69,12 +69,14 @@ Once the mergeback and backport pull request have been merged, the release is co
|
|||||||
|
|
||||||
## Keeping the PR checks up to date (admin access required)
|
## Keeping the PR checks up to date (admin access required)
|
||||||
|
|
||||||
Since the `codeql-action` runs most of its testing through individual Actions workflows, there are over two hundred required jobs that need to pass in order for a PR to turn green. It would be too tedious to maintain that list manually. You can regenerate the set of required checks automatically by running the [update-required-checks.sh](.github/workflows/script/update-required-checks.sh) script:
|
Since the `codeql-action` runs most of its testing through individual Actions workflows, there are over two hundred required jobs that need to pass in order for a PR to turn green. It would be too tedious to maintain that list manually. You can regenerate the set of required checks automatically by running the [sync-checks.ts](pr-checks/sync-checks.ts) script:
|
||||||
|
|
||||||
- If you run the script without an argument, it will retrieve the set of workflows that ran for the latest commit on `main`. Make sure that your local `main` branch is up to date before running the script.
|
- At a minimum, you must provide an argument for the `--token` input. For example, `--token "$(gh auth token)"` to use the same token that `gh` uses. If no token is provided or the token has insufficient permissions, the script will fail.
|
||||||
- You can specify a commit SHA as argument to retrieve the set of workflows for that commit instead. You will likely want to use this if you have a PR that removes or adds PR checks.
|
- By default, the script performs a dry run and outputs information about the changes it would make to the branch protection rules. To actually apply the changes, specify the `--apply` flag.
|
||||||
|
- If you run the script without any other arguments, it will retrieve the set of workflows that ran for the latest commit on `main`.
|
||||||
|
- You can specify a different git ref with the `--ref` input. You will likely want to use this if you have a PR that removes or adds PR checks. For example, `--ref "some/branch/name"` to use the HEAD of the `some/branch/name` branch.
|
||||||
|
|
||||||
After running, go to the [branch protection rules settings page](https://github.com/github/codeql-action/settings/branches) and validate that the rules for `main`, `v3`, and any other currently supported major versions have been updated.
|
After running, go to the [branch protection rules settings page](https://github.com/github/codeql-action/settings/branches) and validate that the rules for `main`, `v4`, and any other currently supported major versions have been updated.
|
||||||
|
|
||||||
Note that any updates to checks on `main` need to be backported to all currently supported major version branches, in order to maintain the same set of names for required checks.
|
Note that any updates to checks on `main` need to be backported to all currently supported major version branches, in order to maintain the same set of names for required checks.
|
||||||
|
|
||||||
@@ -92,7 +94,7 @@ We typically deprecate a version of CodeQL when the GitHub Enterprise Server (GH
|
|||||||
1. Remove support for the old version of CodeQL.
|
1. Remove support for the old version of CodeQL.
|
||||||
- Bump `CODEQL_MINIMUM_VERSION` in `src/codeql.ts` to the new minimum version of CodeQL.
|
- Bump `CODEQL_MINIMUM_VERSION` in `src/codeql.ts` to the new minimum version of CodeQL.
|
||||||
- Remove any code that is only needed to support the old version of CodeQL. This is often behind a version guard, so look for instances of version numbers between the old minimum version and the new minimum version in the codebase. A good place to start is the list of version numbers in `src/codeql.ts`.
|
- Remove any code that is only needed to support the old version of CodeQL. This is often behind a version guard, so look for instances of version numbers between the old minimum version and the new minimum version in the codebase. A good place to start is the list of version numbers in `src/codeql.ts`.
|
||||||
- Update the default set of CodeQL test versions in `pr-checks/sync.py`.
|
- Update the default set of CodeQL test versions in `pr-checks/sync.ts`.
|
||||||
- Remove the old minimum version of CodeQL.
|
- Remove the old minimum version of CodeQL.
|
||||||
- Add the latest patch release for any new CodeQL minor version series that have shipped in GHES.
|
- Add the latest patch release for any new CodeQL minor version series that have shipped in GHES.
|
||||||
- Run the script to update the generated PR checks.
|
- Run the script to update the generated PR checks.
|
||||||
@@ -122,7 +124,7 @@ To deprecate an older version of the Action:
|
|||||||
- Implement an Actions warning for customers using the deprecated version.
|
- Implement an Actions warning for customers using the deprecated version.
|
||||||
1. Wait for the deprecation period to pass.
|
1. Wait for the deprecation period to pass.
|
||||||
1. Upgrade the Actions warning for customers using the deprecated version to a non-fatal error, and mention that this version of the Action is no longer supported.
|
1. Upgrade the Actions warning for customers using the deprecated version to a non-fatal error, and mention that this version of the Action is no longer supported.
|
||||||
1. Make a PR to bump the `OLDEST_SUPPORTED_MAJOR_VERSION` in [releases.ini](.github/releases.ini). Once this PR is merged, the release process will no longer backport changes to the deprecated release version.
|
1. Make a PR to bump the `OLDEST_SUPPORTED_MAJOR_VERSION` in [config.ts](pr-checks/config.ts). Once this PR is merged, the release process will no longer backport changes to the deprecated release version.
|
||||||
|
|
||||||
## Resources
|
## Resources
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,9 @@
|
|||||||
|
export default {
|
||||||
|
typescript: {
|
||||||
|
rewritePaths: {
|
||||||
|
"src/": "build/",
|
||||||
|
},
|
||||||
|
compile: false,
|
||||||
|
},
|
||||||
|
require: ["./ava.setup.mjs"],
|
||||||
|
};
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
import pkg from "./package.json" with { type: "json" };
|
||||||
|
|
||||||
|
globalThis.__CODEQL_ACTION_VERSION__ = pkg.version;
|
||||||
@@ -5,6 +5,8 @@ import { fileURLToPath } from "node:url";
|
|||||||
import * as esbuild from "esbuild";
|
import * as esbuild from "esbuild";
|
||||||
import { globSync } from "glob";
|
import { globSync } from "glob";
|
||||||
|
|
||||||
|
import pkg from "./package.json" with { type: "json" };
|
||||||
|
|
||||||
const __filename = fileURLToPath(import.meta.url);
|
const __filename = fileURLToPath(import.meta.url);
|
||||||
const __dirname = dirname(__filename);
|
const __dirname = dirname(__filename);
|
||||||
|
|
||||||
@@ -13,7 +15,7 @@ const OUT_DIR = join(__dirname, "lib");
|
|||||||
|
|
||||||
/**
|
/**
|
||||||
* Clean the output directory before building.
|
* Clean the output directory before building.
|
||||||
*
|
*
|
||||||
* @type {esbuild.Plugin}
|
* @type {esbuild.Plugin}
|
||||||
*/
|
*/
|
||||||
const cleanPlugin = {
|
const cleanPlugin = {
|
||||||
@@ -27,7 +29,7 @@ const cleanPlugin = {
|
|||||||
|
|
||||||
/**
|
/**
|
||||||
* Copy defaults.json to the output directory since other projects depend on it.
|
* Copy defaults.json to the output directory since other projects depend on it.
|
||||||
*
|
*
|
||||||
* @type {esbuild.Plugin}
|
* @type {esbuild.Plugin}
|
||||||
*/
|
*/
|
||||||
const copyDefaultsPlugin = {
|
const copyDefaultsPlugin = {
|
||||||
@@ -69,6 +71,9 @@ const context = await esbuild.context({
|
|||||||
platform: "node",
|
platform: "node",
|
||||||
plugins: [cleanPlugin, copyDefaultsPlugin, onEndPlugin],
|
plugins: [cleanPlugin, copyDefaultsPlugin, onEndPlugin],
|
||||||
target: ["node20"],
|
target: ["node20"],
|
||||||
|
define: {
|
||||||
|
__CODEQL_ACTION_VERSION__: JSON.stringify(pkg.version),
|
||||||
|
},
|
||||||
});
|
});
|
||||||
|
|
||||||
await context.rebuild();
|
await context.rebuild();
|
||||||
|
|||||||
+48
-5
@@ -7,7 +7,11 @@ import noAsyncForeach from "eslint-plugin-no-async-foreach";
|
|||||||
import jsdoc from "eslint-plugin-jsdoc";
|
import jsdoc from "eslint-plugin-jsdoc";
|
||||||
import tseslint from "typescript-eslint";
|
import tseslint from "typescript-eslint";
|
||||||
import globals from "globals";
|
import globals from "globals";
|
||||||
|
import path from "path";
|
||||||
|
import { fileURLToPath } from "url";
|
||||||
|
|
||||||
|
const __filename = fileURLToPath(import.meta.url);
|
||||||
|
const __dirname = path.dirname(__filename);
|
||||||
const githubFlatConfigs = github.getFlatConfigs();
|
const githubFlatConfigs = github.getFlatConfigs();
|
||||||
|
|
||||||
export default [
|
export default [
|
||||||
@@ -19,6 +23,8 @@ export default [
|
|||||||
"src/testdata/**/*",
|
"src/testdata/**/*",
|
||||||
"tests/**/*",
|
"tests/**/*",
|
||||||
"build.mjs",
|
"build.mjs",
|
||||||
|
"ava.config.mjs",
|
||||||
|
"ava.setup.mjs",
|
||||||
"eslint.config.mjs",
|
"eslint.config.mjs",
|
||||||
".github/**/*",
|
".github/**/*",
|
||||||
],
|
],
|
||||||
@@ -41,7 +47,7 @@ export default [
|
|||||||
plugins: {
|
plugins: {
|
||||||
"import-x": importX,
|
"import-x": importX,
|
||||||
"no-async-foreach": fixupPluginRules(noAsyncForeach),
|
"no-async-foreach": fixupPluginRules(noAsyncForeach),
|
||||||
"jsdoc": jsdoc,
|
jsdoc: jsdoc,
|
||||||
},
|
},
|
||||||
|
|
||||||
languageOptions: {
|
languageOptions: {
|
||||||
@@ -65,7 +71,13 @@ export default [
|
|||||||
|
|
||||||
typescript: {},
|
typescript: {},
|
||||||
},
|
},
|
||||||
"import/ignore": ["sinon", "uuid", "@octokit/plugin-retry", "del", "get-folder-size"],
|
"import/ignore": [
|
||||||
|
"sinon",
|
||||||
|
"uuid",
|
||||||
|
"@octokit/plugin-retry",
|
||||||
|
"del",
|
||||||
|
"get-folder-size",
|
||||||
|
],
|
||||||
"import-x/resolver-next": [
|
"import-x/resolver-next": [
|
||||||
createTypeScriptImportResolver(),
|
createTypeScriptImportResolver(),
|
||||||
createNodeResolver({
|
createNodeResolver({
|
||||||
@@ -141,7 +153,7 @@ export default [
|
|||||||
// We don't currently require full JSDoc coverage, so this rule
|
// We don't currently require full JSDoc coverage, so this rule
|
||||||
// should not error on missing @param annotations.
|
// should not error on missing @param annotations.
|
||||||
disableMissingParamChecks: true,
|
disableMissingParamChecks: true,
|
||||||
}
|
},
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
@@ -160,10 +172,41 @@ export default [
|
|||||||
"@typescript-eslint/no-unused-vars": [
|
"@typescript-eslint/no-unused-vars": [
|
||||||
"error",
|
"error",
|
||||||
{
|
{
|
||||||
"argsIgnorePattern": "^_",
|
args: "all",
|
||||||
}
|
argsIgnorePattern: "^_",
|
||||||
|
},
|
||||||
],
|
],
|
||||||
"func-style": "off",
|
"func-style": "off",
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
files: ["pr-checks/**/*.ts"],
|
||||||
|
|
||||||
|
languageOptions: {
|
||||||
|
parserOptions: {
|
||||||
|
// Use the correct `tsconfig.json` for `pr-checks`.
|
||||||
|
project: "./pr-checks/tsconfig.json",
|
||||||
|
},
|
||||||
|
},
|
||||||
|
|
||||||
|
rules: {
|
||||||
|
// The scripts in `pr-checks` are expected to output to the console.
|
||||||
|
"no-console": "off",
|
||||||
|
|
||||||
|
"import/no-extraneous-dependencies": [
|
||||||
|
"error",
|
||||||
|
{ packageDir: [__dirname, path.resolve(__dirname, "pr-checks")] },
|
||||||
|
],
|
||||||
|
|
||||||
|
"@typescript-eslint/no-floating-promises": [
|
||||||
|
"error",
|
||||||
|
{
|
||||||
|
allowForKnownSafeCalls: [
|
||||||
|
// Avoid needing explicit `void` in front of `describe` calls in test files.
|
||||||
|
{ from: "package", name: ["describe"], package: "node:test" },
|
||||||
|
],
|
||||||
|
},
|
||||||
|
],
|
||||||
|
},
|
||||||
|
},
|
||||||
];
|
];
|
||||||
|
|||||||
@@ -159,6 +159,11 @@ inputs:
|
|||||||
description: >-
|
description: >-
|
||||||
Explicitly enable or disable caching of project build dependencies.
|
Explicitly enable or disable caching of project build dependencies.
|
||||||
required: false
|
required: false
|
||||||
|
check-run-id:
|
||||||
|
description: >-
|
||||||
|
[Internal] The ID of the check run, as provided by the Actions runtime environment. Do not set this value manually.
|
||||||
|
default: ${{ job.check_run_id }}
|
||||||
|
required: false
|
||||||
outputs:
|
outputs:
|
||||||
codeql-path:
|
codeql-path:
|
||||||
description: The path of the CodeQL binary used for analysis
|
description: The path of the CodeQL binary used for analysis
|
||||||
|
|||||||
Generated
+2488
-2150
File diff suppressed because it is too large
Load Diff
Generated
+1889
-1660
File diff suppressed because it is too large
Load Diff
Generated
+1830
-1489
File diff suppressed because it is too large
Load Diff
+4
-4
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"bundleVersion": "codeql-bundle-v2.24.2",
|
"bundleVersion": "codeql-bundle-v2.25.1",
|
||||||
"cliVersion": "2.24.2",
|
"cliVersion": "2.25.1",
|
||||||
"priorBundleVersion": "codeql-bundle-v2.24.1",
|
"priorBundleVersion": "codeql-bundle-v2.24.3",
|
||||||
"priorCliVersion": "2.24.1"
|
"priorCliVersion": "2.24.3"
|
||||||
}
|
}
|
||||||
|
|||||||
Generated
+2162
-1698
File diff suppressed because it is too large
Load Diff
Generated
+1895
-1306
File diff suppressed because it is too large
Load Diff
Generated
+1822
-1481
File diff suppressed because it is too large
Load Diff
Generated
+1356
-1012
File diff suppressed because it is too large
Load Diff
Generated
+1318
-1040
File diff suppressed because it is too large
Load Diff
Generated
+1431
-961
File diff suppressed because it is too large
Load Diff
Generated
+1750
-1403
File diff suppressed because it is too large
Load Diff
Generated
+1320
-1040
File diff suppressed because it is too large
Load Diff
Generated
+1810
-1463
File diff suppressed because it is too large
Load Diff
Generated
+1162
-572
File diff suppressed because it is too large
Load Diff
+24
-21
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "codeql",
|
"name": "codeql",
|
||||||
"version": "4.32.5",
|
"version": "4.35.2",
|
||||||
"private": true,
|
"private": true,
|
||||||
"description": "CodeQL action",
|
"description": "CodeQL action",
|
||||||
"scripts": {
|
"scripts": {
|
||||||
@@ -9,20 +9,17 @@
|
|||||||
"lint": "eslint --report-unused-disable-directives --max-warnings=0 .",
|
"lint": "eslint --report-unused-disable-directives --max-warnings=0 .",
|
||||||
"lint-ci": "SARIF_ESLINT_IGNORE_SUPPRESSED=true eslint --report-unused-disable-directives --max-warnings=0 . --format @microsoft/eslint-formatter-sarif --output-file=eslint.sarif",
|
"lint-ci": "SARIF_ESLINT_IGNORE_SUPPRESSED=true eslint --report-unused-disable-directives --max-warnings=0 . --format @microsoft/eslint-formatter-sarif --output-file=eslint.sarif",
|
||||||
"lint-fix": "eslint --report-unused-disable-directives --max-warnings=0 . --fix",
|
"lint-fix": "eslint --report-unused-disable-directives --max-warnings=0 . --fix",
|
||||||
"ava": "npm run transpile && ava --serial --verbose",
|
"ava": "npm run transpile && ava --verbose",
|
||||||
"test": "npm run ava -- src/",
|
"test": "npm run ava -- src/",
|
||||||
"test-debug": "npm run test -- --timeout=20m",
|
"test-debug": "npm run test -- --timeout=20m",
|
||||||
"transpile": "tsc --build --verbose"
|
"test-coverage": "c8 npm run test",
|
||||||
},
|
"transpile": "tsc --build --verbose",
|
||||||
"ava": {
|
"coverage": "c8 report --check-coverage"
|
||||||
"typescript": {
|
|
||||||
"rewritePaths": {
|
|
||||||
"src/": "build/"
|
|
||||||
},
|
|
||||||
"compile": false
|
|
||||||
}
|
|
||||||
},
|
},
|
||||||
"license": "MIT",
|
"license": "MIT",
|
||||||
|
"workspaces": [
|
||||||
|
"pr-checks"
|
||||||
|
],
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@actions/artifact": "^5.0.3",
|
"@actions/artifact": "^5.0.3",
|
||||||
"@actions/artifact-legacy": "npm:@actions/artifact@^1.1.2",
|
"@actions/artifact-legacy": "npm:@actions/artifact@^1.1.2",
|
||||||
@@ -35,7 +32,6 @@
|
|||||||
"@actions/io": "^2.0.0",
|
"@actions/io": "^2.0.0",
|
||||||
"@actions/tool-cache": "^3.0.1",
|
"@actions/tool-cache": "^3.0.1",
|
||||||
"@octokit/plugin-retry": "^8.0.0",
|
"@octokit/plugin-retry": "^8.0.0",
|
||||||
"@schemastore/package": "0.0.10",
|
|
||||||
"archiver": "^7.0.1",
|
"archiver": "^7.0.1",
|
||||||
"fast-deep-equal": "^3.1.3",
|
"fast-deep-equal": "^3.1.3",
|
||||||
"follow-redirects": "^1.15.11",
|
"follow-redirects": "^1.15.11",
|
||||||
@@ -44,13 +40,13 @@
|
|||||||
"js-yaml": "^4.1.1",
|
"js-yaml": "^4.1.1",
|
||||||
"jsonschema": "1.4.1",
|
"jsonschema": "1.4.1",
|
||||||
"long": "^5.3.2",
|
"long": "^5.3.2",
|
||||||
"node-forge": "^1.3.3",
|
"node-forge": "^1.4.0",
|
||||||
"semver": "^7.7.4",
|
"semver": "^7.7.4",
|
||||||
"uuid": "^13.0.0"
|
"uuid": "^13.0.0"
|
||||||
},
|
},
|
||||||
"devDependencies": {
|
"devDependencies": {
|
||||||
"@ava/typescript": "6.0.0",
|
"@ava/typescript": "6.0.0",
|
||||||
"@eslint/compat": "^2.0.2",
|
"@eslint/compat": "^2.0.3",
|
||||||
"@microsoft/eslint-formatter-sarif": "^3.1.0",
|
"@microsoft/eslint-formatter-sarif": "^3.1.0",
|
||||||
"@octokit/types": "^16.0.0",
|
"@octokit/types": "^16.0.0",
|
||||||
"@types/archiver": "^7.0.0",
|
"@types/archiver": "^7.0.0",
|
||||||
@@ -58,22 +54,24 @@
|
|||||||
"@types/js-yaml": "^4.0.9",
|
"@types/js-yaml": "^4.0.9",
|
||||||
"@types/node": "^20.19.9",
|
"@types/node": "^20.19.9",
|
||||||
"@types/node-forge": "^1.3.14",
|
"@types/node-forge": "^1.3.14",
|
||||||
|
"@types/sarif": "^2.1.7",
|
||||||
"@types/semver": "^7.7.1",
|
"@types/semver": "^7.7.1",
|
||||||
"@types/sinon": "^21.0.0",
|
"@types/sinon": "^21.0.0",
|
||||||
"ava": "^6.4.1",
|
"ava": "^7.0.0",
|
||||||
"esbuild": "^0.27.3",
|
"c8": "^11.0.0",
|
||||||
|
"esbuild": "^0.27.4",
|
||||||
"eslint": "^9.39.2",
|
"eslint": "^9.39.2",
|
||||||
"eslint-import-resolver-typescript": "^3.8.7",
|
"eslint-import-resolver-typescript": "^3.8.7",
|
||||||
"eslint-plugin-github": "^6.0.0",
|
"eslint-plugin-github": "^6.0.0",
|
||||||
"eslint-plugin-import-x": "^4.16.1",
|
"eslint-plugin-import-x": "^4.16.2",
|
||||||
"eslint-plugin-jsdoc": "^62.6.0",
|
"eslint-plugin-jsdoc": "^62.8.0",
|
||||||
"eslint-plugin-no-async-foreach": "^0.1.1",
|
"eslint-plugin-no-async-foreach": "^0.1.1",
|
||||||
"glob": "^11.1.0",
|
"glob": "^11.1.0",
|
||||||
"globals": "^17.3.0",
|
"globals": "^17.4.0",
|
||||||
"nock": "^14.0.11",
|
"nock": "^14.0.11",
|
||||||
"sinon": "^21.0.1",
|
"sinon": "^21.0.3",
|
||||||
"typescript": "^5.9.3",
|
"typescript": "^5.9.3",
|
||||||
"typescript-eslint": "^8.56.0"
|
"typescript-eslint": "^8.57.1"
|
||||||
},
|
},
|
||||||
"overrides": {
|
"overrides": {
|
||||||
"@actions/tool-cache": {
|
"@actions/tool-cache": {
|
||||||
@@ -96,5 +94,10 @@
|
|||||||
},
|
},
|
||||||
"brace-expansion@2.0.1": "2.0.2",
|
"brace-expansion@2.0.1": "2.0.2",
|
||||||
"glob": "^11.1.0"
|
"glob": "^11.1.0"
|
||||||
|
},
|
||||||
|
"c8": {
|
||||||
|
"functions": 80,
|
||||||
|
"lines": 80,
|
||||||
|
"branches": 80
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,3 +1 @@
|
|||||||
env
|
node_modules/
|
||||||
__pycache__/
|
|
||||||
*.pyc
|
|
||||||
|
|||||||
@@ -1,7 +1,11 @@
|
|||||||
name: "All-platform bundle"
|
name: "All-platform bundle"
|
||||||
description: "Tests using an all-platform CodeQL Bundle"
|
description: "Tests using an all-platform CodeQL Bundle"
|
||||||
operatingSystems: ["ubuntu", "macos", "windows"]
|
operatingSystems:
|
||||||
versions: ["nightly-latest"]
|
- ubuntu
|
||||||
|
- macos
|
||||||
|
- windows
|
||||||
|
versions:
|
||||||
|
- nightly-latest
|
||||||
useAllPlatformBundle: "true"
|
useAllPlatformBundle: "true"
|
||||||
installGo: true
|
installGo: true
|
||||||
installDotNet: true
|
installDotNet: true
|
||||||
|
|||||||
@@ -1,7 +1,13 @@
|
|||||||
name: "Analysis kinds"
|
name: "Analysis kinds"
|
||||||
description: "Tests basic functionality for different `analysis-kinds` inputs."
|
description: "Tests basic functionality for different `analysis-kinds` inputs."
|
||||||
versions: ["linked", "nightly-latest"]
|
versions:
|
||||||
analysisKinds: ["code-scanning", "code-quality", "code-scanning,code-quality", "risk-assessment"]
|
- linked
|
||||||
|
- nightly-latest
|
||||||
|
analysisKinds:
|
||||||
|
- code-scanning
|
||||||
|
- code-quality
|
||||||
|
- code-scanning,code-quality
|
||||||
|
- risk-assessment
|
||||||
env:
|
env:
|
||||||
CODEQL_ACTION_RISK_ASSESSMENT_ID: 1
|
CODEQL_ACTION_RISK_ASSESSMENT_ID: 1
|
||||||
CHECK_SCRIPT: |
|
CHECK_SCRIPT: |
|
||||||
@@ -40,7 +46,7 @@ steps:
|
|||||||
post-processed-sarif-path: "${{ runner.temp }}/post-processed"
|
post-processed-sarif-path: "${{ runner.temp }}/post-processed"
|
||||||
|
|
||||||
- name: Upload SARIF files
|
- name: Upload SARIF files
|
||||||
uses: actions/upload-artifact@v6
|
uses: actions/upload-artifact@v7
|
||||||
with:
|
with:
|
||||||
name: |
|
name: |
|
||||||
analysis-kinds-${{ matrix.os }}-${{ matrix.version }}-${{ matrix.analysis-kinds }}
|
analysis-kinds-${{ matrix.os }}-${{ matrix.version }}-${{ matrix.analysis-kinds }}
|
||||||
@@ -48,7 +54,7 @@ steps:
|
|||||||
retention-days: 7
|
retention-days: 7
|
||||||
|
|
||||||
- name: Upload post-processed SARIF
|
- name: Upload post-processed SARIF
|
||||||
uses: actions/upload-artifact@v6
|
uses: actions/upload-artifact@v7
|
||||||
with:
|
with:
|
||||||
name: |
|
name: |
|
||||||
post-processed-${{ matrix.os }}-${{ matrix.version }}-${{ matrix.analysis-kinds }}
|
post-processed-${{ matrix.os }}-${{ matrix.version }}-${{ matrix.analysis-kinds }}
|
||||||
|
|||||||
@@ -1,8 +1,8 @@
|
|||||||
name: "Analyze: 'ref' and 'sha' from inputs"
|
name: "Analyze: 'ref' and 'sha' from inputs"
|
||||||
description: "Checks that specifying 'ref' and 'sha' as inputs works"
|
description: "Checks that specifying 'ref' and 'sha' as inputs works"
|
||||||
versions: ["default"]
|
versions:
|
||||||
|
- default
|
||||||
installGo: true
|
installGo: true
|
||||||
installPython: true
|
|
||||||
installDotNet: true
|
installDotNet: true
|
||||||
steps:
|
steps:
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
|
|||||||
@@ -1,7 +1,11 @@
|
|||||||
name: "autobuild-action"
|
name: "autobuild-action"
|
||||||
description: "Tests that the C# autobuild action works"
|
description: "Tests that the C# autobuild action works"
|
||||||
operatingSystems: ["ubuntu", "macos", "windows"]
|
operatingSystems:
|
||||||
versions: ["linked"]
|
- ubuntu
|
||||||
|
- macos
|
||||||
|
- windows
|
||||||
|
versions:
|
||||||
|
- linked
|
||||||
installDotNet: true
|
installDotNet: true
|
||||||
steps:
|
steps:
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
|
|||||||
@@ -3,9 +3,13 @@ description: >
|
|||||||
An end-to-end integration test of a Java repository built using 'build-mode: autobuild',
|
An end-to-end integration test of a Java repository built using 'build-mode: autobuild',
|
||||||
with direct tracing enabled and a custom working directory specified as the input to the
|
with direct tracing enabled and a custom working directory specified as the input to the
|
||||||
autobuild Action.
|
autobuild Action.
|
||||||
operatingSystems: ["ubuntu", "windows"]
|
operatingSystems:
|
||||||
versions: ["linked", "nightly-latest"]
|
- ubuntu
|
||||||
installJava: "true"
|
- windows
|
||||||
|
versions:
|
||||||
|
- linked
|
||||||
|
- nightly-latest
|
||||||
|
installJava: true
|
||||||
env:
|
env:
|
||||||
CODEQL_ACTION_AUTOBUILD_BUILD_MODE_DIRECT_TRACING: true
|
CODEQL_ACTION_AUTOBUILD_BUILD_MODE_DIRECT_TRACING: true
|
||||||
steps:
|
steps:
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
name: "Autobuild working directory"
|
name: "Autobuild working directory"
|
||||||
description: "Tests working-directory input of autobuild action"
|
description: "Tests working-directory input of autobuild action"
|
||||||
versions: ["linked"]
|
versions:
|
||||||
|
- linked
|
||||||
steps:
|
steps:
|
||||||
- name: Test setup
|
- name: Test setup
|
||||||
run: |
|
run: |
|
||||||
|
|||||||
@@ -1,9 +1,13 @@
|
|||||||
name: "Build mode autobuild"
|
name: "Build mode autobuild"
|
||||||
description: "An end-to-end integration test of a Java repository built using 'build-mode: autobuild'"
|
description: "An end-to-end integration test of a Java repository built using 'build-mode: autobuild'"
|
||||||
operatingSystems: ["ubuntu", "windows"]
|
operatingSystems:
|
||||||
versions: ["linked", "nightly-latest"]
|
- ubuntu
|
||||||
installJava: "true"
|
- windows
|
||||||
installYq: "true"
|
versions:
|
||||||
|
- linked
|
||||||
|
- nightly-latest
|
||||||
|
installJava: true
|
||||||
|
installYq: true
|
||||||
steps:
|
steps:
|
||||||
- name: Set up Java test repo configuration
|
- name: Set up Java test repo configuration
|
||||||
run: |
|
run: |
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
name: "Build mode manual"
|
name: "Build mode manual"
|
||||||
description: "An end-to-end integration test of a Java repository built using 'build-mode: manual'"
|
description: "An end-to-end integration test of a Java repository built using 'build-mode: manual'"
|
||||||
versions: ["nightly-latest"]
|
versions:
|
||||||
|
- nightly-latest
|
||||||
installGo: true
|
installGo: true
|
||||||
installDotNet: true
|
installDotNet: true
|
||||||
steps:
|
steps:
|
||||||
|
|||||||
@@ -1,6 +1,8 @@
|
|||||||
name: "Build mode none"
|
name: "Build mode none"
|
||||||
description: "An end-to-end integration test of a Java repository built using 'build-mode: none'"
|
description: "An end-to-end integration test of a Java repository built using 'build-mode: none'"
|
||||||
versions: ["linked", "nightly-latest"]
|
versions:
|
||||||
|
- linked
|
||||||
|
- nightly-latest
|
||||||
steps:
|
steps:
|
||||||
- uses: ./../action/init
|
- uses: ./../action/init
|
||||||
id: init
|
id: init
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
name: "Build mode rollback"
|
name: "Build mode rollback"
|
||||||
description: "The build mode is rolled back from none to autobuild when the relevant feature flag is enabled."
|
description: "The build mode is rolled back from none to autobuild when the relevant feature flag is enabled."
|
||||||
versions: ["nightly-latest"]
|
versions:
|
||||||
|
- nightly-latest
|
||||||
env:
|
env:
|
||||||
CODEQL_ACTION_DISABLE_JAVA_BUILDLESS: true
|
CODEQL_ACTION_DISABLE_JAVA_BUILDLESS: true
|
||||||
steps:
|
steps:
|
||||||
|
|||||||
@@ -11,5 +11,5 @@ steps:
|
|||||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||||
languages: javascript
|
languages: javascript
|
||||||
- name: Fail if the CodeQL version is not a nightly
|
- name: Fail if the CodeQL version is not a nightly
|
||||||
if: "!contains(steps.init.outputs.codeql-version, '+')"
|
if: ${{ !contains(steps.init.outputs.codeql-version, '+') }}
|
||||||
run: exit 1
|
run: exit 1
|
||||||
|
|||||||
@@ -3,8 +3,8 @@ description: "The CodeQL bundle should be cached within the toolcache"
|
|||||||
versions:
|
versions:
|
||||||
- linked
|
- linked
|
||||||
operatingSystems:
|
operatingSystems:
|
||||||
- macos
|
|
||||||
- ubuntu
|
- ubuntu
|
||||||
|
- macos
|
||||||
- windows
|
- windows
|
||||||
steps:
|
steps:
|
||||||
- name: Remove CodeQL from toolcache
|
- name: Remove CodeQL from toolcache
|
||||||
|
|||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user