Merge pull request #4037 from github/mbg/repo-props/tools

Add repository property for `tools` input
This commit is contained in:
Michael B. Gale
2026-07-24 15:09:22 +00:00
committed by GitHub
11 changed files with 392 additions and 92 deletions

137
lib/entry-points.js generated
View File

@@ -146430,6 +146430,7 @@ async function createStatusReportBase(actionName, status, actionStartedAt, confi
analysis_key,
build_mode: config?.buildMode,
commit_oid: commitOid,
computed_inputs: {},
first_party_analysis: isFirstPartyAnalysis(actionName),
job_name: jobName,
job_run_uuid: jobRunUUID,
@@ -147008,6 +147009,11 @@ var featureConfig = {
envVar: "CODEQL_ACTION_START_PROXY_USE_FEATURES_RELEASE",
minimumVersion: void 0
},
["tools_repository_property" /* ToolsRepositoryProperty */]: {
defaultValue: false,
envVar: "CODEQL_ACTION_TOOLS_REPOSITORY_PROPERTY",
minimumVersion: void 0
},
["upload_overlay_db_to_api" /* UploadOverlayDbToApi */]: {
defaultValue: false,
envVar: "CODEQL_ACTION_UPLOAD_OVERLAY_DB_TO_API",
@@ -147973,12 +147979,14 @@ function getUnknownLanguagesError(languages) {
}
// src/feature-flags/properties.ts
var github2 = __toESM(require_github());
var GITHUB_CODEQL_PROPERTY_PREFIX = "github-codeql-";
var RepositoryPropertyName = /* @__PURE__ */ ((RepositoryPropertyName2) => {
RepositoryPropertyName2["CONFIG_FILE"] = "github-codeql-config-file";
RepositoryPropertyName2["DISABLE_OVERLAY"] = "github-codeql-disable-overlay";
RepositoryPropertyName2["EXTRA_QUERIES"] = "github-codeql-extra-queries";
RepositoryPropertyName2["FILE_COVERAGE_ON_PRS"] = "github-codeql-file-coverage-on-prs";
RepositoryPropertyName2["TOOLS"] = "github-codeql-tools";
return RepositoryPropertyName2;
})(RepositoryPropertyName || {});
function isString2(value) {
@@ -147997,7 +148005,8 @@ var repositoryPropertyParsers = {
["github-codeql-config-file" /* CONFIG_FILE */]: stringProperty,
["github-codeql-disable-overlay" /* DISABLE_OVERLAY */]: booleanProperty,
["github-codeql-extra-queries" /* EXTRA_QUERIES */]: stringProperty,
["github-codeql-file-coverage-on-prs" /* FILE_COVERAGE_ON_PRS */]: booleanProperty
["github-codeql-file-coverage-on-prs" /* FILE_COVERAGE_ON_PRS */]: booleanProperty,
["github-codeql-tools" /* TOOLS */]: stringProperty
};
async function loadPropertiesFromApi(logger, repositoryNwo) {
try {
@@ -148077,6 +148086,26 @@ var KNOWN_REPOSITORY_PROPERTY_NAMES = new Set(
function isKnownPropertyName(name) {
return KNOWN_REPOSITORY_PROPERTY_NAMES.has(name);
}
async function loadRepositoryProperties(repositoryNwo, logger) {
const repositoryOwnerType = github2.context.payload.repository?.owner.type;
logger.debug(
`Repository owner type is '${repositoryOwnerType ?? "unknown"}'.`
);
if (repositoryOwnerType === "User") {
logger.debug(
"Skipping loading repository properties because the repository is owned by a user and therefore cannot have repository properties."
);
return new Success({});
}
try {
return new Success(await loadPropertiesFromApi(logger, repositoryNwo));
} catch (error3) {
logger.warning(
`Failed to load repository properties: ${getErrorMessage(error3)}`
);
return new Failure(error3);
}
}
// src/config/db-config.ts
var ORG_SCHEMA = {
@@ -154035,7 +154064,7 @@ var fs19 = __toESM(require("fs"));
var path17 = __toESM(require("path"));
var core14 = __toESM(require_core());
var toolrunner4 = __toESM(require_toolrunner());
var github2 = __toESM(require_github());
var github3 = __toESM(require_github());
var io6 = __toESM(require_io());
async function initCodeQL(toolsInput, apiDetails, tempDir, variant, defaultCliVersion, rawLanguages, useOverlayAwareDefaultCliVersion, features, logger) {
logger.startGroup("Setup CodeQL tools");
@@ -154232,7 +154261,7 @@ function logFileCoverageOnPrsDeprecationWarning(logger) {
if (process.env["CODEQL_ACTION_DID_LOG_FILE_COVERAGE_ON_PRS_DEPRECATION" /* DID_LOG_FILE_COVERAGE_ON_PRS_DEPRECATION */]) {
return;
}
const repositoryOwnerType = github2.context.payload.repository?.owner.type;
const repositoryOwnerType = github3.context.payload.repository?.owner.type;
let message = "Starting April 2026, the CodeQL Action will skip computing file coverage information on pull requests to improve analysis performance. File coverage information will still be computed on non-PR analyses.";
const envVarOptOut = "set the `CODEQL_ACTION_FILE_COVERAGE_ON_PRS` environment variable to `true`.";
const repoPropertyOptOut = 'create a custom repository property with the name `github-codeql-file-coverage-on-prs` and the type "True/false", then set this property to `true` in the repository\'s settings.';
@@ -157359,7 +157388,7 @@ var import_async = __toESM(require_async(), 1);
var import_path6 = require("path");
// node_modules/archiver/lib/error.js
var import_util32 = __toESM(require("util"), 1);
var import_util33 = __toESM(require("util"), 1);
var ERROR_CODES = {
ABORTED: "archive was aborted",
DIRECTORYDIRPATHREQUIRED: "diretory dirpath argument must be a non-empty string value",
@@ -157384,7 +157413,7 @@ function ArchiverError(code, data) {
this.code = code;
this.data = data;
}
import_util32.default.inherits(ArchiverError, Error);
import_util33.default.inherits(ArchiverError, Error);
// node_modules/archiver/lib/core.js
var import_readable_stream2 = __toESM(require_ours(), 1);
@@ -160315,10 +160344,43 @@ async function runWrapper3() {
var fs28 = __toESM(require("fs"));
var path24 = __toESM(require("path"));
var core21 = __toESM(require_core());
var github3 = __toESM(require_github());
var io7 = __toESM(require_io());
var semver10 = __toESM(require_semver2());
// src/config/inputs.ts
async function getToolsInput(action, repositoryProperties) {
const name = "tools" /* Tools */;
const input = action.actions.getOptionalInput(name);
const propertyValue = repositoryProperties["github-codeql-tools" /* TOOLS */];
const allowRepositoryProperty = await action.features.getValue(
"tools_repository_property" /* ToolsRepositoryProperty */
);
if (allowRepositoryProperty && propertyValue?.startsWith("!")) {
action.logger.info(
`Using ${name} input from repository property (enforced): ${propertyValue}`
);
return {
// Drop the '!' from the value.
value: propertyValue.substring(1),
source: "repository-property" /* RepositoryProperty */
};
}
if (input !== void 0) {
action.logger.info(`Using ${name} input from workflow: ${input}`);
return { value: input, source: "workflow" /* Workflow */ };
}
if (allowRepositoryProperty && propertyValue !== void 0) {
action.logger.info(
`Using ${name} input from repository property: ${propertyValue}`
);
return {
value: propertyValue,
source: "repository-property" /* RepositoryProperty */
};
}
return void 0;
}
// src/workflow.ts
var fs27 = __toESM(require("fs"));
var path23 = __toESM(require("path"));
@@ -160609,7 +160671,7 @@ async function sendStartingStatusReport(startedAt, config, logger) {
await sendStatusReport(statusReportBase);
}
}
async function sendCompletedStatusReport2(startedAt, config, configFile, toolsDownloadStatusReport, toolsFeatureFlagsValid, toolsSource, toolsVersion, overlayBaseDatabaseStats, dependencyCachingResults, logger, error3) {
async function sendCompletedStatusReport2(startedAt, config, configFile, toolsInput, toolsDownloadStatusReport, toolsFeatureFlagsValid, toolsSource, toolsVersion, overlayBaseDatabaseStats, dependencyCachingResults, logger, error3) {
const statusReportBase = await createStatusReportBase(
"init" /* Init */,
getActionsStatus(error3),
@@ -160626,11 +160688,14 @@ async function sendCompletedStatusReport2(startedAt, config, configFile, toolsDo
const workflowLanguages = getOptionalInput("languages");
const initStatusReport = {
...statusReportBase,
tools_input: getOptionalInput("tools") || "",
tools_input: toolsInput?.value || "",
tools_resolved_version: toolsVersion,
tools_source: toolsSource || "UNKNOWN" /* Unknown */,
workflow_languages: workflowLanguages || ""
};
if (toolsInput !== void 0) {
initStatusReport.computed_inputs.tools = toolsInput;
}
const initToolsDownloadFields = {};
if (toolsDownloadStatusReport?.downloadDurationMs !== void 0) {
initToolsDownloadFields.tools_download_duration_ms = toolsDownloadStatusReport.downloadDurationMs;
@@ -160666,6 +160731,7 @@ async function run3(actionState) {
let codeql;
let features;
let sourceRoot;
let toolsInput;
let toolsDownloadStatusReport;
let toolsFeatureFlagsValid;
let toolsSource;
@@ -160721,6 +160787,10 @@ async function run3(actionState) {
`The 'init' action should not be run in the same workflow as 'setup-codeql'.`
);
}
toolsInput = await getToolsInput(
actionStateWithFeatures,
repositoryProperties
);
const codeQLDefaultVersionInfo = await features.getEnabledDefaultCliVersions(gitHubVersion.type);
toolsFeatureFlagsValid = codeQLDefaultVersionInfo.toolsFeatureFlagsValid;
const rawLanguages = getRawLanguagesNoAutodetect(
@@ -160728,7 +160798,7 @@ async function run3(actionState) {
);
const useOverlayAwareDefaultCliVersion = analysisKinds?.length === 1 && analysisKinds[0] === "code-scanning" /* CodeScanning */;
const initCodeQLResult = await initCodeQL(
getOptionalInput("tools"),
toolsInput?.value,
apiDetails,
getTemporaryDirectory(),
gitHubVersion.type,
@@ -161046,6 +161116,7 @@ exec ${goBinaryPath} "$@"`
config,
void 0,
// We only report config info on success.
toolsInput,
toolsDownloadStatusReport,
toolsFeatureFlagsValid,
toolsSource,
@@ -161063,6 +161134,7 @@ exec ${goBinaryPath} "$@"`
startedAt,
config,
configFile,
toolsInput,
toolsDownloadStatusReport,
toolsFeatureFlagsValid,
toolsSource,
@@ -161072,26 +161144,6 @@ exec ${goBinaryPath} "$@"`
logger
);
}
async function loadRepositoryProperties(repositoryNwo, logger) {
const repositoryOwnerType = github3.context.payload.repository?.owner.type;
logger.debug(
`Repository owner type is '${repositoryOwnerType ?? "unknown"}'.`
);
if (repositoryOwnerType === "User") {
logger.debug(
"Skipping loading repository properties because the repository is owned by a user and therefore cannot have repository properties."
);
return new Success({});
}
try {
return new Success(await loadPropertiesFromApi(logger, repositoryNwo));
} catch (error3) {
logger.warning(
`Failed to load repository properties: ${getErrorMessage(error3)}`
);
return new Failure(error3);
}
}
var init = {
name: "init" /* Init */,
run: run3
@@ -161642,7 +161694,7 @@ async function runWrapper6() {
// src/setup-codeql-action.ts
var core24 = __toESM(require_core());
async function sendCompletedStatusReport3(startedAt, toolsDownloadStatusReport, toolsFeatureFlagsValid, toolsSource, toolsVersion, logger, error3) {
async function sendCompletedStatusReport3(startedAt, toolsInput, toolsDownloadStatusReport, toolsFeatureFlagsValid, toolsSource, toolsVersion, logger, error3) {
const statusReportBase = await createStatusReportBase(
"setup-codeql" /* SetupCodeQL */,
getActionsStatus(error3),
@@ -161658,11 +161710,14 @@ async function sendCompletedStatusReport3(startedAt, toolsDownloadStatusReport,
}
const initStatusReport = {
...statusReportBase,
tools_input: getOptionalInput("tools") || "",
tools_input: toolsInput?.value || "",
tools_resolved_version: toolsVersion,
tools_source: toolsSource || "UNKNOWN" /* Unknown */,
workflow_languages: ""
};
if (toolsInput !== void 0) {
initStatusReport.computed_inputs.tools = toolsInput;
}
const initToolsDownloadFields = {};
if (toolsDownloadStatusReport?.downloadDurationMs !== void 0) {
initToolsDownloadFields.tools_download_duration_ms = toolsDownloadStatusReport.downloadDurationMs;
@@ -161672,11 +161727,10 @@ async function sendCompletedStatusReport3(startedAt, toolsDownloadStatusReport,
}
await sendStatusReport({ ...initStatusReport, ...initToolsDownloadFields });
}
async function run6({
startedAt,
logger
}) {
async function run6(actionState) {
const { logger, startedAt } = actionState;
let codeql;
let toolsInput;
let toolsDownloadStatusReport;
let toolsFeatureFlagsValid;
let toolsSource;
@@ -161699,6 +161753,12 @@ async function run6({
getTemporaryDirectory(),
logger
);
const repositoryPropertiesResult = await loadRepositoryProperties(
repositoryNwo,
logger
);
const repositoryProperties = repositoryPropertiesResult.orElse({});
const actionStateWithFeatures = { ...actionState, features };
const jobRunUuid = v4_default();
logger.info(`Job run UUID is ${jobRunUuid}.`);
core24.exportVariable("JOB_RUN_UUID" /* JOB_RUN_UUID */, jobRunUuid);
@@ -161713,6 +161773,10 @@ async function run6({
if (statusReportBase !== void 0) {
await sendStatusReport(statusReportBase);
}
toolsInput = await getToolsInput(
actionStateWithFeatures,
repositoryProperties
);
const codeQLDefaultVersionInfo = await features.getEnabledDefaultCliVersions(gitHubVersion.type);
toolsFeatureFlagsValid = codeQLDefaultVersionInfo.toolsFeatureFlagsValid;
const rawLanguages = getRawLanguagesNoAutodetect(
@@ -161720,7 +161784,7 @@ async function run6({
);
const analysisKinds = await getAnalysisKinds(logger, features);
const initCodeQLResult = await initCodeQL(
getOptionalInput("tools"),
toolsInput?.value,
apiDetails,
getTemporaryDirectory(),
gitHubVersion.type,
@@ -161757,6 +161821,7 @@ async function run6({
}
await sendCompletedStatusReport3(
startedAt,
toolsInput,
toolsDownloadStatusReport,
toolsFeatureFlagsValid,
toolsSource,