Add wrapper around JSON.parse to sarif module

This commit is contained in:
Michael B. Gale
2026-03-01 13:52:45 +00:00
parent d7cfd19fb8
commit 2fce45b8e6
6 changed files with 680 additions and 679 deletions

204
lib/upload-lib.js generated
View File

@@ -204,7 +204,7 @@ var require_file_command = __commonJS({
exports2.issueFileCommand = issueFileCommand;
exports2.prepareKeyValueMessage = prepareKeyValueMessage;
var crypto2 = __importStar2(require("crypto"));
var fs12 = __importStar2(require("fs"));
var fs13 = __importStar2(require("fs"));
var os2 = __importStar2(require("os"));
var utils_1 = require_utils();
function issueFileCommand(command, message) {
@@ -212,10 +212,10 @@ var require_file_command = __commonJS({
if (!filePath) {
throw new Error(`Unable to find environment variable for file command ${command}`);
}
if (!fs12.existsSync(filePath)) {
if (!fs13.existsSync(filePath)) {
throw new Error(`Missing file at path: ${filePath}`);
}
fs12.appendFileSync(filePath, `${(0, utils_1.toCommandValue)(message)}${os2.EOL}`, {
fs13.appendFileSync(filePath, `${(0, utils_1.toCommandValue)(message)}${os2.EOL}`, {
encoding: "utf8"
});
}
@@ -20123,13 +20123,13 @@ var require_io_util = __commonJS({
exports2.isRooted = isRooted;
exports2.tryGetExecutablePath = tryGetExecutablePath;
exports2.getCmdPath = getCmdPath;
var fs12 = __importStar2(require("fs"));
var fs13 = __importStar2(require("fs"));
var path12 = __importStar2(require("path"));
_a = fs12.promises, exports2.chmod = _a.chmod, exports2.copyFile = _a.copyFile, exports2.lstat = _a.lstat, exports2.mkdir = _a.mkdir, exports2.open = _a.open, exports2.readdir = _a.readdir, exports2.rename = _a.rename, exports2.rm = _a.rm, exports2.rmdir = _a.rmdir, exports2.stat = _a.stat, exports2.symlink = _a.symlink, exports2.unlink = _a.unlink;
_a = fs13.promises, exports2.chmod = _a.chmod, exports2.copyFile = _a.copyFile, exports2.lstat = _a.lstat, exports2.mkdir = _a.mkdir, exports2.open = _a.open, exports2.readdir = _a.readdir, exports2.rename = _a.rename, exports2.rm = _a.rm, exports2.rmdir = _a.rmdir, exports2.stat = _a.stat, exports2.symlink = _a.symlink, exports2.unlink = _a.unlink;
exports2.IS_WINDOWS = process.platform === "win32";
function readlink(fsPath) {
return __awaiter2(this, void 0, void 0, function* () {
const result = yield fs12.promises.readlink(fsPath);
const result = yield fs13.promises.readlink(fsPath);
if (exports2.IS_WINDOWS && !result.endsWith("\\")) {
return `${result}\\`;
}
@@ -20137,7 +20137,7 @@ var require_io_util = __commonJS({
});
}
exports2.UV_FS_O_EXLOCK = 268435456;
exports2.READONLY = fs12.constants.O_RDONLY;
exports2.READONLY = fs13.constants.O_RDONLY;
function exists(fsPath) {
return __awaiter2(this, void 0, void 0, function* () {
try {
@@ -50403,7 +50403,7 @@ var require_internal_globber = __commonJS({
Object.defineProperty(exports2, "__esModule", { value: true });
exports2.DefaultGlobber = void 0;
var core12 = __importStar2(require_core());
var fs12 = __importStar2(require("fs"));
var fs13 = __importStar2(require("fs"));
var globOptionsHelper = __importStar2(require_internal_glob_options_helper());
var path12 = __importStar2(require("path"));
var patternHelper = __importStar2(require_internal_pattern_helper());
@@ -50457,7 +50457,7 @@ var require_internal_globber = __commonJS({
for (const searchPath of patternHelper.getSearchPaths(patterns)) {
core12.debug(`Search path '${searchPath}'`);
try {
yield __await2(fs12.promises.lstat(searchPath));
yield __await2(fs13.promises.lstat(searchPath));
} catch (err) {
if (err.code === "ENOENT") {
continue;
@@ -50491,7 +50491,7 @@ var require_internal_globber = __commonJS({
continue;
}
const childLevel = item.level + 1;
const childItems = (yield __await2(fs12.promises.readdir(item.path))).map((x) => new internal_search_state_1.SearchState(path12.join(item.path, x), childLevel));
const childItems = (yield __await2(fs13.promises.readdir(item.path))).map((x) => new internal_search_state_1.SearchState(path12.join(item.path, x), childLevel));
stack.push(...childItems.reverse());
} else if (match & internal_match_kind_1.MatchKind.File) {
yield yield __await2(item.path);
@@ -50526,7 +50526,7 @@ var require_internal_globber = __commonJS({
let stats;
if (options.followSymbolicLinks) {
try {
stats = yield fs12.promises.stat(item.path);
stats = yield fs13.promises.stat(item.path);
} catch (err) {
if (err.code === "ENOENT") {
if (options.omitBrokenSymbolicLinks) {
@@ -50538,10 +50538,10 @@ var require_internal_globber = __commonJS({
throw err;
}
} else {
stats = yield fs12.promises.lstat(item.path);
stats = yield fs13.promises.lstat(item.path);
}
if (stats.isDirectory() && options.followSymbolicLinks) {
const realPath = yield fs12.promises.realpath(item.path);
const realPath = yield fs13.promises.realpath(item.path);
while (traversalChain.length >= item.level) {
traversalChain.pop();
}
@@ -50650,7 +50650,7 @@ var require_internal_hash_files = __commonJS({
exports2.hashFiles = hashFiles;
var crypto2 = __importStar2(require("crypto"));
var core12 = __importStar2(require_core());
var fs12 = __importStar2(require("fs"));
var fs13 = __importStar2(require("fs"));
var stream2 = __importStar2(require("stream"));
var util = __importStar2(require("util"));
var path12 = __importStar2(require("path"));
@@ -50673,13 +50673,13 @@ var require_internal_hash_files = __commonJS({
writeDelegate(`Ignore '${file}' since it is not under GITHUB_WORKSPACE.`);
continue;
}
if (fs12.statSync(file).isDirectory()) {
if (fs13.statSync(file).isDirectory()) {
writeDelegate(`Skip directory '${file}'.`);
continue;
}
const hash2 = crypto2.createHash("sha256");
const pipeline = util.promisify(stream2.pipeline);
yield pipeline(fs12.createReadStream(file), hash2);
yield pipeline(fs13.createReadStream(file), hash2);
result.write(hash2.digest());
count++;
if (!hasMatch) {
@@ -52054,7 +52054,7 @@ var require_cacheUtils = __commonJS({
var glob = __importStar2(require_glob());
var io6 = __importStar2(require_io());
var crypto2 = __importStar2(require("crypto"));
var fs12 = __importStar2(require("fs"));
var fs13 = __importStar2(require("fs"));
var path12 = __importStar2(require("path"));
var semver9 = __importStar2(require_semver3());
var util = __importStar2(require("util"));
@@ -52083,7 +52083,7 @@ var require_cacheUtils = __commonJS({
});
}
function getArchiveFileSizeInBytes(filePath) {
return fs12.statSync(filePath).size;
return fs13.statSync(filePath).size;
}
function resolvePaths(patterns) {
return __awaiter2(this, void 0, void 0, function* () {
@@ -52121,7 +52121,7 @@ var require_cacheUtils = __commonJS({
}
function unlinkFile(filePath) {
return __awaiter2(this, void 0, void 0, function* () {
return util.promisify(fs12.unlink)(filePath);
return util.promisify(fs13.unlink)(filePath);
});
}
function getVersion(app_1) {
@@ -52163,7 +52163,7 @@ var require_cacheUtils = __commonJS({
}
function getGnuTarPathOnWindows() {
return __awaiter2(this, void 0, void 0, function* () {
if (fs12.existsSync(constants_1.GnuTarPathOnWindows)) {
if (fs13.existsSync(constants_1.GnuTarPathOnWindows)) {
return constants_1.GnuTarPathOnWindows;
}
const versionOutput = yield getVersion("tar");
@@ -92320,7 +92320,7 @@ var require_downloadUtils = __commonJS({
var http_client_1 = require_lib();
var storage_blob_1 = require_commonjs15();
var buffer = __importStar2(require("buffer"));
var fs12 = __importStar2(require("fs"));
var fs13 = __importStar2(require("fs"));
var stream2 = __importStar2(require("stream"));
var util = __importStar2(require("util"));
var utils = __importStar2(require_cacheUtils());
@@ -92431,7 +92431,7 @@ var require_downloadUtils = __commonJS({
exports2.DownloadProgress = DownloadProgress;
function downloadCacheHttpClient(archiveLocation, archivePath) {
return __awaiter2(this, void 0, void 0, function* () {
const writeStream = fs12.createWriteStream(archivePath);
const writeStream = fs13.createWriteStream(archivePath);
const httpClient = new http_client_1.HttpClient("actions/cache");
const downloadResponse = yield (0, requestUtils_1.retryHttpClientResponse)("downloadCache", () => __awaiter2(this, void 0, void 0, function* () {
return httpClient.get(archiveLocation);
@@ -92456,7 +92456,7 @@ var require_downloadUtils = __commonJS({
function downloadCacheHttpClientConcurrent(archiveLocation, archivePath, options) {
return __awaiter2(this, void 0, void 0, function* () {
var _a;
const archiveDescriptor = yield fs12.promises.open(archivePath, "w");
const archiveDescriptor = yield fs13.promises.open(archivePath, "w");
const httpClient = new http_client_1.HttpClient("actions/cache", void 0, {
socketTimeout: options.timeoutInMs,
keepAlive: true
@@ -92572,7 +92572,7 @@ var require_downloadUtils = __commonJS({
} else {
const maxSegmentSize = Math.min(134217728, buffer.constants.MAX_LENGTH);
const downloadProgress = new DownloadProgress(contentLength);
const fd = fs12.openSync(archivePath, "w");
const fd = fs13.openSync(archivePath, "w");
try {
downloadProgress.startDisplayTimer();
const controller = new abort_controller_1.AbortController();
@@ -92590,12 +92590,12 @@ var require_downloadUtils = __commonJS({
controller.abort();
throw new Error("Aborting cache download as the download time exceeded the timeout.");
} else if (Buffer.isBuffer(result)) {
fs12.writeFileSync(fd, result);
fs13.writeFileSync(fd, result);
}
}
} finally {
downloadProgress.stopDisplayTimer();
fs12.closeSync(fd);
fs13.closeSync(fd);
}
}
});
@@ -92917,7 +92917,7 @@ var require_cacheHttpClient = __commonJS({
var core12 = __importStar2(require_core());
var http_client_1 = require_lib();
var auth_1 = require_auth();
var fs12 = __importStar2(require("fs"));
var fs13 = __importStar2(require("fs"));
var url_1 = require("url");
var utils = __importStar2(require_cacheUtils());
var uploadUtils_1 = require_uploadUtils();
@@ -93052,7 +93052,7 @@ Other caches with similar key:`);
return __awaiter2(this, void 0, void 0, function* () {
const fileSize = utils.getArchiveFileSizeInBytes(archivePath);
const resourceUrl = getCacheApiUrl(`caches/${cacheId.toString()}`);
const fd = fs12.openSync(archivePath, "r");
const fd = fs13.openSync(archivePath, "r");
const uploadOptions = (0, options_1.getUploadOptions)(options);
const concurrency = utils.assertDefined("uploadConcurrency", uploadOptions.uploadConcurrency);
const maxChunkSize = utils.assertDefined("uploadChunkSize", uploadOptions.uploadChunkSize);
@@ -93066,7 +93066,7 @@ Other caches with similar key:`);
const start = offset;
const end = offset + chunkSize - 1;
offset += maxChunkSize;
yield uploadChunk(httpClient, resourceUrl, () => fs12.createReadStream(archivePath, {
yield uploadChunk(httpClient, resourceUrl, () => fs13.createReadStream(archivePath, {
fd,
start,
end,
@@ -93077,7 +93077,7 @@ Other caches with similar key:`);
}
})));
} finally {
fs12.closeSync(fd);
fs13.closeSync(fd);
}
return;
});
@@ -99033,7 +99033,7 @@ var require_manifest = __commonJS({
var core_1 = require_core();
var os2 = require("os");
var cp = require("child_process");
var fs12 = require("fs");
var fs13 = require("fs");
function _findMatch(versionSpec, stable, candidates, archFilter) {
return __awaiter2(this, void 0, void 0, function* () {
const platFilter = os2.platform();
@@ -99095,10 +99095,10 @@ var require_manifest = __commonJS({
const lsbReleaseFile = "/etc/lsb-release";
const osReleaseFile = "/etc/os-release";
let contents = "";
if (fs12.existsSync(lsbReleaseFile)) {
contents = fs12.readFileSync(lsbReleaseFile).toString();
} else if (fs12.existsSync(osReleaseFile)) {
contents = fs12.readFileSync(osReleaseFile).toString();
if (fs13.existsSync(lsbReleaseFile)) {
contents = fs13.readFileSync(lsbReleaseFile).toString();
} else if (fs13.existsSync(osReleaseFile)) {
contents = fs13.readFileSync(osReleaseFile).toString();
}
return contents;
}
@@ -99307,7 +99307,7 @@ var require_tool_cache = __commonJS({
var core12 = __importStar2(require_core());
var io6 = __importStar2(require_io());
var crypto2 = __importStar2(require("crypto"));
var fs12 = __importStar2(require("fs"));
var fs13 = __importStar2(require("fs"));
var mm = __importStar2(require_manifest());
var os2 = __importStar2(require("os"));
var path12 = __importStar2(require("path"));
@@ -99353,7 +99353,7 @@ var require_tool_cache = __commonJS({
}
function downloadToolAttempt(url2, dest, auth2, headers) {
return __awaiter2(this, void 0, void 0, function* () {
if (fs12.existsSync(dest)) {
if (fs13.existsSync(dest)) {
throw new Error(`Destination file path ${dest} already exists`);
}
const http = new httpm.HttpClient(userAgent2, [], {
@@ -99377,7 +99377,7 @@ var require_tool_cache = __commonJS({
const readStream = responseMessageFactory();
let succeeded = false;
try {
yield pipeline(readStream, fs12.createWriteStream(dest));
yield pipeline(readStream, fs13.createWriteStream(dest));
core12.debug("download complete");
succeeded = true;
return dest;
@@ -99589,11 +99589,11 @@ var require_tool_cache = __commonJS({
arch2 = arch2 || os2.arch();
core12.debug(`Caching tool ${tool} ${version} ${arch2}`);
core12.debug(`source dir: ${sourceDir}`);
if (!fs12.statSync(sourceDir).isDirectory()) {
if (!fs13.statSync(sourceDir).isDirectory()) {
throw new Error("sourceDir is not a directory");
}
const destPath = yield _createToolPath(tool, version, arch2);
for (const itemName of fs12.readdirSync(sourceDir)) {
for (const itemName of fs13.readdirSync(sourceDir)) {
const s = path12.join(sourceDir, itemName);
yield io6.cp(s, destPath, { recursive: true });
}
@@ -99607,7 +99607,7 @@ var require_tool_cache = __commonJS({
arch2 = arch2 || os2.arch();
core12.debug(`Caching tool ${tool} ${version} ${arch2}`);
core12.debug(`source file: ${sourceFile}`);
if (!fs12.statSync(sourceFile).isFile()) {
if (!fs13.statSync(sourceFile).isFile()) {
throw new Error("sourceFile is not a file");
}
const destFolder = yield _createToolPath(tool, version, arch2);
@@ -99636,7 +99636,7 @@ var require_tool_cache = __commonJS({
versionSpec = semver9.clean(versionSpec) || "";
const cachePath = path12.join(_getCacheDirectory(), toolName, versionSpec, arch2);
core12.debug(`checking cache: ${cachePath}`);
if (fs12.existsSync(cachePath) && fs12.existsSync(`${cachePath}.complete`)) {
if (fs13.existsSync(cachePath) && fs13.existsSync(`${cachePath}.complete`)) {
core12.debug(`Found tool in cache ${toolName} ${versionSpec} ${arch2}`);
toolPath = cachePath;
} else {
@@ -99649,12 +99649,12 @@ var require_tool_cache = __commonJS({
const versions = [];
arch2 = arch2 || os2.arch();
const toolPath = path12.join(_getCacheDirectory(), toolName);
if (fs12.existsSync(toolPath)) {
const children = fs12.readdirSync(toolPath);
if (fs13.existsSync(toolPath)) {
const children = fs13.readdirSync(toolPath);
for (const child of children) {
if (isExplicitVersion(child)) {
const fullPath = path12.join(toolPath, child, arch2 || "");
if (fs12.existsSync(fullPath) && fs12.existsSync(`${fullPath}.complete`)) {
if (fs13.existsSync(fullPath) && fs13.existsSync(`${fullPath}.complete`)) {
versions.push(child);
}
}
@@ -99725,7 +99725,7 @@ var require_tool_cache = __commonJS({
function _completeToolPath(tool, version, arch2) {
const folderPath = path12.join(_getCacheDirectory(), tool, semver9.clean(version) || version, arch2 || "");
const markerPath = `${folderPath}.complete`;
fs12.writeFileSync(markerPath, "");
fs13.writeFileSync(markerPath, "");
core12.debug("finished caching tool");
}
function isExplicitVersion(versionSpec) {
@@ -103235,7 +103235,7 @@ __export(upload_lib_exports, {
getGroupedSarifFilePaths: () => getGroupedSarifFilePaths,
populateRunAutomationDetails: () => populateRunAutomationDetails,
postProcessSarifFiles: () => postProcessSarifFiles,
readSarifFile: () => readSarifFile,
readSarifFile: () => readSarifFile2,
shouldConsiderConfigurationError: () => shouldConsiderConfigurationError,
shouldConsiderInvalidRequest: () => shouldConsiderInvalidRequest,
shouldShowCombineSarifFilesDeprecationWarning: () => shouldShowCombineSarifFilesDeprecationWarning,
@@ -103249,7 +103249,7 @@ __export(upload_lib_exports, {
writePostProcessedFiles: () => writePostProcessedFiles
});
module.exports = __toCommonJS(upload_lib_exports);
var fs11 = __toESM(require("fs"));
var fs12 = __toESM(require("fs"));
var path11 = __toESM(require("path"));
var url = __toESM(require("url"));
var import_zlib = __toESM(require("zlib"));
@@ -103257,7 +103257,7 @@ var core11 = __toESM(require_core());
var jsonschema2 = __toESM(require_lib2());
// src/actions-util.ts
var fs2 = __toESM(require("fs"));
var fs3 = __toESM(require("fs"));
var path2 = __toESM(require("path"));
var core4 = __toESM(require_core());
var toolrunner = __toESM(require_toolrunner());
@@ -103265,7 +103265,7 @@ var github = __toESM(require_github());
var io2 = __toESM(require_io());
// src/util.ts
var fs = __toESM(require("fs"));
var fs2 = __toESM(require("fs"));
var path = __toESM(require("path"));
var core3 = __toESM(require_core());
var io = __toESM(require_io());
@@ -103278,21 +103278,21 @@ async function getFolderSize(itemPath, options) {
getFolderSize.loose = async (itemPath, options) => await core(itemPath, options);
getFolderSize.strict = async (itemPath, options) => await core(itemPath, options, { strict: true });
async function core(rootItemPath, options = {}, returnType = {}) {
const fs12 = options.fs || await import("node:fs/promises");
const fs13 = options.fs || await import("node:fs/promises");
let folderSize = 0n;
const foundInos = /* @__PURE__ */ new Set();
const errors = [];
await processItem(rootItemPath);
async function processItem(itemPath) {
if (options.ignore?.test(itemPath)) return;
const stats = returnType.strict ? await fs12.lstat(itemPath, { bigint: true }) : await fs12.lstat(itemPath, { bigint: true }).catch((error3) => errors.push(error3));
const stats = returnType.strict ? await fs13.lstat(itemPath, { bigint: true }) : await fs13.lstat(itemPath, { bigint: true }).catch((error3) => errors.push(error3));
if (typeof stats !== "object") return;
if (!foundInos.has(stats.ino)) {
foundInos.add(stats.ino);
folderSize += stats.size;
}
if (stats.isDirectory()) {
const directoryItems = returnType.strict ? await fs12.readdir(itemPath) : await fs12.readdir(itemPath).catch((error3) => errors.push(error3));
const directoryItems = returnType.strict ? await fs13.readdir(itemPath) : await fs13.readdir(itemPath).catch((error3) => errors.push(error3));
if (typeof directoryItems !== "object") return;
await Promise.all(
directoryItems.map(
@@ -105915,6 +105915,7 @@ var safeDump = renamed("safeDump", "dump");
var semver = __toESM(require_semver2());
// src/sarif/index.ts
var fs = __toESM(require("fs"));
function getToolNames(sarif) {
const toolNames = {};
for (const run of sarif.runs || []) {
@@ -105926,6 +105927,9 @@ function getToolNames(sarif) {
}
return Object.keys(toolNames);
}
function readSarifFile(sarifFilePath) {
return JSON.parse(fs.readFileSync(sarifFilePath, "utf8"));
}
// src/util.ts
var BASE_DATABASE_OIDS_FILE_NAME = "base-database-oids.json";
@@ -106089,7 +106093,7 @@ function cloneObject(obj) {
async function cleanUpPath(file, name, logger) {
logger.debug(`Cleaning up ${name}.`);
try {
await fs.promises.rm(file, {
await fs2.promises.rm(file, {
force: true,
recursive: true
});
@@ -106147,7 +106151,7 @@ function getRelativeScriptPath() {
function getWorkflowEvent() {
const eventJsonFile = getRequiredEnvParam("GITHUB_EVENT_PATH");
try {
return JSON.parse(fs2.readFileSync(eventJsonFile, "utf-8"));
return JSON.parse(fs3.readFileSync(eventJsonFile, "utf-8"));
} catch (e) {
throw new Error(
`Unable to read workflow event JSON from ${eventJsonFile}: ${e}`
@@ -106579,7 +106583,7 @@ function wrapApiConfigurationError(e) {
}
// src/codeql.ts
var fs9 = __toESM(require("fs"));
var fs10 = __toESM(require("fs"));
var path9 = __toESM(require("path"));
var core10 = __toESM(require_core());
var toolrunner3 = __toESM(require_toolrunner());
@@ -106827,7 +106831,7 @@ function wrapCliConfigurationError(cliError) {
}
// src/config-utils.ts
var fs5 = __toESM(require("fs"));
var fs6 = __toESM(require("fs"));
var path6 = __toESM(require("path"));
// src/caching-utils.ts
@@ -106942,7 +106946,7 @@ function writeDiagnostic(config, language, diagnostic) {
}
// src/diff-informed-analysis-utils.ts
var fs4 = __toESM(require("fs"));
var fs5 = __toESM(require("fs"));
var path5 = __toESM(require("path"));
// src/feature-flags.ts
@@ -106953,7 +106957,7 @@ var bundleVersion = "codeql-bundle-v2.24.2";
var cliVersion = "2.24.2";
// src/overlay/index.ts
var fs3 = __toESM(require("fs"));
var fs4 = __toESM(require("fs"));
var path4 = __toESM(require("path"));
var actionsCache = __toESM(require_cache5());
@@ -107164,12 +107168,12 @@ async function writeBaseDatabaseOidsFile(config, sourceRoot) {
const gitFileOids = await getFileOidsUnderPath(sourceRoot);
const gitFileOidsJson = JSON.stringify(gitFileOids);
const baseDatabaseOidsFilePath = getBaseDatabaseOidsFilePath(config);
await fs3.promises.writeFile(baseDatabaseOidsFilePath, gitFileOidsJson);
await fs4.promises.writeFile(baseDatabaseOidsFilePath, gitFileOidsJson);
}
async function readBaseDatabaseOidsFile(config, logger) {
const baseDatabaseOidsFilePath = getBaseDatabaseOidsFilePath(config);
try {
const contents = await fs3.promises.readFile(
const contents = await fs4.promises.readFile(
baseDatabaseOidsFilePath,
"utf-8"
);
@@ -107196,7 +107200,7 @@ async function writeOverlayChangesFile(config, sourceRoot, logger) {
logger.debug(
`Writing overlay changed files to ${overlayChangesFile}: ${changedFilesJson}`
);
await fs3.promises.writeFile(overlayChangesFile, changedFilesJson);
await fs4.promises.writeFile(overlayChangesFile, changedFilesJson);
return overlayChangesFile;
}
function computeChangedFiles(baseFileOids, overlayFileOids) {
@@ -107467,11 +107471,11 @@ function getDiffRangesJsonFilePath() {
}
function readDiffRangesJsonFile(logger) {
const jsonFilePath = getDiffRangesJsonFilePath();
if (!fs4.existsSync(jsonFilePath)) {
if (!fs5.existsSync(jsonFilePath)) {
logger.debug(`Diff ranges JSON file does not exist at ${jsonFilePath}`);
return void 0;
}
const jsonContents = fs4.readFileSync(jsonFilePath, "utf8");
const jsonContents = fs5.readFileSync(jsonFilePath, "utf8");
logger.debug(
`Read pr-diff-range JSON file from ${jsonFilePath}:
${jsonContents}`
@@ -107520,10 +107524,10 @@ function getPathToParsedConfigFile(tempDir) {
}
async function getConfig(tempDir, logger) {
const configFile = getPathToParsedConfigFile(tempDir);
if (!fs5.existsSync(configFile)) {
if (!fs6.existsSync(configFile)) {
return void 0;
}
const configString = fs5.readFileSync(configFile, "utf8");
const configString = fs6.readFileSync(configFile, "utf8");
logger.debug("Loaded config:");
logger.debug(configString);
const config = JSON.parse(configString);
@@ -107559,7 +107563,7 @@ function appendExtraQueryExclusions(extraQueryExclusions, cliConfig) {
}
// src/setup-codeql.ts
var fs8 = __toESM(require("fs"));
var fs9 = __toESM(require("fs"));
var path8 = __toESM(require("path"));
var toolcache3 = __toESM(require_tool_cache());
var import_fast_deep_equal = __toESM(require_fast_deep_equal());
@@ -107621,7 +107625,7 @@ var v4_default = v4;
// src/tar.ts
var import_child_process = require("child_process");
var fs6 = __toESM(require("fs"));
var fs7 = __toESM(require("fs"));
var stream = __toESM(require("stream"));
var import_toolrunner = __toESM(require_toolrunner());
var io4 = __toESM(require_io());
@@ -107694,7 +107698,7 @@ async function isZstdAvailable(logger) {
}
}
async function extract(tarPath, dest, compressionMethod, tarVersion, logger) {
fs6.mkdirSync(dest, { recursive: true });
fs7.mkdirSync(dest, { recursive: true });
switch (compressionMethod) {
case "gzip":
return await toolcache.extractTar(tarPath, dest);
@@ -107778,7 +107782,7 @@ function inferCompressionMethod(tarPath) {
}
// src/tools-download.ts
var fs7 = __toESM(require("fs"));
var fs8 = __toESM(require("fs"));
var os = __toESM(require("os"));
var path7 = __toESM(require("path"));
var import_perf_hooks = require("perf_hooks");
@@ -107885,7 +107889,7 @@ async function downloadAndExtract(codeqlURL, compressionMethod, dest, authorizat
};
}
async function downloadAndExtractZstdWithStreaming(codeqlURL, dest, authorization, headers, tarVersion, logger) {
fs7.mkdirSync(dest, { recursive: true });
fs8.mkdirSync(dest, { recursive: true });
const agent = new import_http_client.HttpClient().getAgent(codeqlURL);
headers = Object.assign(
{ "User-Agent": "CodeQL Action" },
@@ -107922,7 +107926,7 @@ function getToolcacheDirectory(version) {
}
function writeToolcacheMarkerFile(extractedPath, logger) {
const markerFilePath = `${extractedPath}.complete`;
fs7.writeFileSync(markerFilePath, "");
fs8.writeFileSync(markerFilePath, "");
logger.info(`Created toolcache marker file ${markerFilePath}`);
}
function sanitizeUrlForStatusReport(url2) {
@@ -108057,7 +108061,7 @@ async function findOverridingToolsInCache(humanReadableVersion, logger) {
const candidates = toolcache3.findAllVersions("CodeQL").filter(isGoodVersion).map((version) => ({
folder: toolcache3.find("CodeQL", version),
version
})).filter(({ folder }) => fs8.existsSync(path8.join(folder, "pinned-version")));
})).filter(({ folder }) => fs9.existsSync(path8.join(folder, "pinned-version")));
if (candidates.length === 1) {
const candidate = candidates[0];
logger.debug(
@@ -108611,7 +108615,7 @@ async function getCodeQLForCmd(cmd, checkVersion) {
"tools",
"tracing-config.lua"
);
return fs9.existsSync(tracingConfigPath);
return fs10.existsSync(tracingConfigPath);
},
async isScannedLanguage(language) {
return !await this.isTracedLanguage(language);
@@ -109091,7 +109095,7 @@ async function writeCodeScanningConfigFile(config, logger) {
logger.startGroup("Augmented user configuration file contents");
logger.info(dump(augmentedConfig));
logger.endGroup();
fs9.writeFileSync(codeScanningConfigFile, dump(augmentedConfig));
fs10.writeFileSync(codeScanningConfigFile, dump(augmentedConfig));
return codeScanningConfigFile;
}
var TRAP_CACHE_SIZE_MB = 1024;
@@ -109135,7 +109139,7 @@ async function getJobRunUuidSarifOptions(codeql) {
}
// src/fingerprints.ts
var fs10 = __toESM(require("fs"));
var fs11 = __toESM(require("fs"));
var import_path2 = __toESM(require("path"));
// node_modules/long/index.js
@@ -110123,7 +110127,7 @@ async function hash(callback, filepath) {
}
updateHash(current);
};
const readStream = fs10.createReadStream(filepath, "utf8");
const readStream = fs11.createReadStream(filepath, "utf8");
for await (const data of readStream) {
for (let i = 0; i < data.length; ++i) {
processCharacter(data.charCodeAt(i));
@@ -110198,11 +110202,11 @@ function resolveUriToFile(location, artifacts, sourceRoot, logger) {
if (!import_path2.default.isAbsolute(uri)) {
uri = srcRootPrefix + uri;
}
if (!fs10.existsSync(uri)) {
if (!fs11.existsSync(uri)) {
logger.debug(`Unable to compute fingerprint for non-existent file: ${uri}`);
return void 0;
}
if (fs10.statSync(uri).isDirectory()) {
if (fs11.statSync(uri).isDirectory()) {
logger.debug(`Unable to compute fingerprint for directory: ${uri}`);
return void 0;
}
@@ -110299,9 +110303,7 @@ function combineSarifFiles(sarifFiles, logger) {
};
for (const sarifFile of sarifFiles) {
logger.debug(`Loading SARIF file: ${sarifFile}`);
const sarifObject = JSON.parse(
fs11.readFileSync(sarifFile, "utf8")
);
const sarifObject = readSarifFile(sarifFile);
if (combinedSarif.version === null) {
combinedSarif.version = sarifObject.version;
} else if (combinedSarif.version !== sarifObject.version) {
@@ -110371,9 +110373,7 @@ async function shouldDisableCombineSarifFiles(sarifObjects, githubVersion) {
}
async function combineSarifFilesUsingCLI(sarifFiles, gitHubVersion, features, logger) {
logger.info("Combining SARIF files using the CodeQL CLI");
const sarifObjects = sarifFiles.map((sarifFile) => {
return JSON.parse(fs11.readFileSync(sarifFile, "utf8"));
});
const sarifObjects = sarifFiles.map(readSarifFile);
const deprecationWarningMessage = gitHubVersion.type === "GitHub Enterprise Server" /* GHES */ ? "and will be removed in GitHub Enterprise Server 3.18" : "and will be removed in July 2025";
const deprecationMoreInformationMessage = "For more information, see https://github.blog/changelog/2024-05-06-code-scanning-will-stop-combining-runs-from-a-single-upload";
if (!areAllRunsProducedByCodeQL(sarifObjects)) {
@@ -110426,13 +110426,13 @@ async function combineSarifFilesUsingCLI(sarifFiles, gitHubVersion, features, lo
codeQL = initCodeQLResult.codeql;
}
const baseTempDir = path11.resolve(tempDir, "combined-sarif");
fs11.mkdirSync(baseTempDir, { recursive: true });
const outputDirectory = fs11.mkdtempSync(path11.resolve(baseTempDir, "output-"));
fs12.mkdirSync(baseTempDir, { recursive: true });
const outputDirectory = fs12.mkdtempSync(path11.resolve(baseTempDir, "output-"));
const outputFile = path11.resolve(outputDirectory, "combined-sarif.sarif");
await codeQL.mergeResults(sarifFiles, outputFile, {
mergeRunsFromEqualCategory: true
});
return JSON.parse(fs11.readFileSync(outputFile, "utf8"));
return readSarifFile(outputFile);
}
function populateRunAutomationDetails(sarif, category, analysis_key, environment) {
const automationID = getAutomationID2(category, analysis_key, environment);
@@ -110469,7 +110469,7 @@ async function uploadPayload(payload, repositoryNwo, logger, analysis) {
`SARIF upload disabled by an environment variable. Saving to ${payloadSaveFile}`
);
logger.info(`Payload: ${JSON.stringify(payload, null, 2)}`);
fs11.writeFileSync(payloadSaveFile, JSON.stringify(payload, null, 2));
fs12.writeFileSync(payloadSaveFile, JSON.stringify(payload, null, 2));
return "dummy-sarif-id";
}
const client = getApiClient();
@@ -110503,7 +110503,7 @@ async function uploadPayload(payload, repositoryNwo, logger, analysis) {
function findSarifFilesInDir(sarifPath, isSarif) {
const sarifFiles = [];
const walkSarifFiles = (dir) => {
const entries = fs11.readdirSync(dir, { withFileTypes: true });
const entries = fs12.readdirSync(dir, { withFileTypes: true });
for (const entry of entries) {
if (entry.isFile() && isSarif(entry.name)) {
sarifFiles.push(path11.resolve(dir, entry.name));
@@ -110516,11 +110516,11 @@ function findSarifFilesInDir(sarifPath, isSarif) {
return sarifFiles;
}
function getSarifFilePaths(sarifPath, isSarif) {
if (!fs11.existsSync(sarifPath)) {
if (!fs12.existsSync(sarifPath)) {
throw new ConfigurationError(`Path does not exist: ${sarifPath}`);
}
let sarifFiles;
if (fs11.lstatSync(sarifPath).isDirectory()) {
if (fs12.lstatSync(sarifPath).isDirectory()) {
sarifFiles = findSarifFilesInDir(sarifPath, isSarif);
if (sarifFiles.length === 0) {
throw new ConfigurationError(
@@ -110533,7 +110533,7 @@ function getSarifFilePaths(sarifPath, isSarif) {
return sarifFiles;
}
async function getGroupedSarifFilePaths(logger, sarifPath) {
const stats = fs11.statSync(sarifPath, { throwIfNoEntry: false });
const stats = fs12.statSync(sarifPath, { throwIfNoEntry: false });
if (stats === void 0) {
throw new ConfigurationError(`Path does not exist: ${sarifPath}`);
}
@@ -110596,9 +110596,9 @@ function countResultsInSarif(sarif) {
}
return numResults;
}
function readSarifFile(sarifFilePath) {
function readSarifFile2(sarifFilePath) {
try {
return JSON.parse(fs11.readFileSync(sarifFilePath, "utf8"));
return readSarifFile(sarifFilePath);
} catch (e) {
throw new InvalidSarifUploadError(
`Invalid SARIF. JSON syntax error: ${getErrorMessage(e)}`
@@ -110667,7 +110667,7 @@ function buildPayload(commitOid, ref, analysisKey, analysisName, zippedSarif, wo
payloadObj.base_sha = mergeBaseCommitOid;
} else if (process.env.GITHUB_EVENT_PATH) {
const githubEvent = JSON.parse(
fs11.readFileSync(process.env.GITHUB_EVENT_PATH, "utf8")
fs12.readFileSync(process.env.GITHUB_EVENT_PATH, "utf8")
);
payloadObj.base_ref = `refs/heads/${githubEvent.pull_request.base.ref}`;
payloadObj.base_sha = githubEvent.pull_request.base.sha;
@@ -110682,7 +110682,7 @@ async function postProcessSarifFiles(logger, features, checkoutPath, sarifPaths,
category = analysis.fixCategory(logger, category);
if (sarifPaths.length > 1) {
for (const sarifPath of sarifPaths) {
const parsedSarif = readSarifFile(sarifPath);
const parsedSarif = readSarifFile2(sarifPath);
validateSarifFileSchema(parsedSarif, sarifPath, logger);
}
sarif = await combineSarifFilesUsingCLI(
@@ -110693,7 +110693,7 @@ async function postProcessSarifFiles(logger, features, checkoutPath, sarifPaths,
);
} else {
const sarifPath = sarifPaths[0];
sarif = readSarifFile(sarifPath);
sarif = readSarifFile2(sarifPath);
validateSarifFileSchema(sarif, sarifPath, logger);
await throwIfCombineSarifFilesDisabled([sarif], gitHubVersion);
}
@@ -110801,9 +110801,9 @@ async function uploadPostProcessedFiles(logger, checkoutPath, uploadTarget, post
};
}
function dumpSarifFile(sarifPayload, outputDir, logger, uploadTarget) {
if (!fs11.existsSync(outputDir)) {
fs11.mkdirSync(outputDir, { recursive: true });
} else if (!fs11.lstatSync(outputDir).isDirectory()) {
if (!fs12.existsSync(outputDir)) {
fs12.mkdirSync(outputDir, { recursive: true });
} else if (!fs12.lstatSync(outputDir).isDirectory()) {
throw new ConfigurationError(
`The path that processed SARIF files should be written to exists, but is not a directory: ${outputDir}`
);
@@ -110813,7 +110813,7 @@ function dumpSarifFile(sarifPayload, outputDir, logger, uploadTarget) {
`upload${uploadTarget.sarifExtension}`
);
logger.info(`Writing processed SARIF file to ${outputFile}`);
fs11.writeFileSync(outputFile, sarifPayload);
fs12.writeFileSync(outputFile, sarifPayload);
}
var STATUS_CHECK_FREQUENCY_MILLISECONDS = 5 * 1e3;
var STATUS_CHECK_TIMEOUT_MILLISECONDS = 2 * 60 * 1e3;