diff --git a/CHANGELOG.md b/CHANGELOG.md index 0a67c5b7a..dc22e818d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,6 +6,10 @@ See the [releases page](https://github.com/github/codeql-action/releases) for th - The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and download the native `linux-arm64` CodeQL bundle when available. [#4072](https://github.com/github/codeql-action/pull/4072) +## 4.37.9 - 26 Aug 2026 + +- Update default CodeQL bundle version to [2.26.4](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4). [#4106](https://github.com/github/codeql-action/pull/4106) + ## 4.37.8 - 21 Aug 2026 No user facing changes. diff --git a/lib/defaults.json b/lib/defaults.json index b5d9f1364..1098ef459 100644 --- a/lib/defaults.json +++ b/lib/defaults.json @@ -1,6 +1,6 @@ { - "bundleVersion": "codeql-bundle-v2.26.3", - "cliVersion": "2.26.3", - "priorBundleVersion": "codeql-bundle-v2.26.2", - "priorCliVersion": "2.26.2" + "bundleVersion": "codeql-bundle-v2.26.4", + "cliVersion": "2.26.4", + "priorBundleVersion": "codeql-bundle-v2.26.3", + "priorCliVersion": "2.26.3" } diff --git a/lib/entry-points.js b/lib/entry-points.js index 5c740addd..aae754168 100644 --- a/lib/entry-points.js +++ b/lib/entry-points.js @@ -146023,7 +146023,7 @@ function getDiffRangesJsonFilePath(env = getEnv()) { return path2.join(getTemporaryDirectory(env), PR_DIFF_RANGE_JSON_FILENAME); } function getActionVersion() { - return "4.37.9"; + return "4.37.10"; } function getWorkflowEventName(env = getEnv()) { return env.getRequired("GITHUB_EVENT_NAME" /* GITHUB_EVENT_NAME */); @@ -147569,8 +147569,8 @@ var path6 = __toESM(require("path")); var semver4 = __toESM(require_semver2()); // src/defaults.json -var bundleVersion = "codeql-bundle-v2.26.3"; -var cliVersion = "2.26.3"; +var bundleVersion = "codeql-bundle-v2.26.4"; +var cliVersion = "2.26.4"; // src/overlay/index.ts var fs5 = __toESM(require("fs")); @@ -151504,10 +151504,10 @@ async function downloadAndExtract(codeqlURL, compressionMethod, dest, authorizat logger.info( `Downloading CodeQL tools from ${codeqlURL} . This may take a while.` ); + const startTime = import_perf_hooks2.performance.now(); try { if (compressionMethod === "zstd" && process.platform === "linux") { logger.info(`Streaming the extraction of the CodeQL bundle.`); - const toolsInstallStart = import_perf_hooks2.performance.now(); await downloadAndExtractZstdWithStreaming( codeqlURL, dest, @@ -151516,15 +151516,13 @@ async function downloadAndExtract(codeqlURL, compressionMethod, dest, authorizat tarVersion, logger ); - const combinedDurationMs = Math.round( - import_perf_hooks2.performance.now() - toolsInstallStart - ); + const totalDurationMs = Math.round(import_perf_hooks2.performance.now() - startTime); logger.info( `Finished downloading and extracting CodeQL bundle to ${dest} (${formatDuration( - combinedDurationMs + totalDurationMs )}).` ); - return {}; + return { totalDurationMs }; } } catch (e) { core11.warning( @@ -151566,7 +151564,11 @@ async function downloadAndExtract(codeqlURL, compressionMethod, dest, authorizat } finally { await cleanUpPath(archivedBundlePath, "CodeQL bundle archive", logger); } - return { downloadDurationMs }; + return { + downloadDurationMs, + extractionDurationMs, + totalDurationMs: Math.round(import_perf_hooks2.performance.now() - startTime) + }; } async function downloadAndExtractZstdWithStreaming(codeqlURL, dest, authorization, headers, tarVersion, logger) { fs13.mkdirSync(dest, { recursive: true }); @@ -161678,6 +161680,12 @@ async function sendCompletedStatusReport2(startedAt, config, configFile, toolsIn if (toolsDownloadStatusReport?.downloadDurationMs !== void 0) { initToolsDownloadFields.tools_download_duration_ms = toolsDownloadStatusReport.downloadDurationMs; } + if (toolsDownloadStatusReport?.extractionDurationMs !== void 0) { + initToolsDownloadFields.tools_extraction_duration_ms = toolsDownloadStatusReport.extractionDurationMs; + } + if (toolsDownloadStatusReport?.totalDurationMs !== void 0) { + initToolsDownloadFields.tools_total_duration_ms = toolsDownloadStatusReport.totalDurationMs; + } if (toolsFeatureFlagsValid !== void 0) { initToolsDownloadFields.tools_feature_flags_valid = toolsFeatureFlagsValid; } @@ -162698,6 +162706,12 @@ async function sendCompletedStatusReport3(startedAt, toolsInput, toolsDownloadSt if (toolsDownloadStatusReport?.downloadDurationMs !== void 0) { initToolsDownloadFields.tools_download_duration_ms = toolsDownloadStatusReport.downloadDurationMs; } + if (toolsDownloadStatusReport?.extractionDurationMs !== void 0) { + initToolsDownloadFields.tools_extraction_duration_ms = toolsDownloadStatusReport.extractionDurationMs; + } + if (toolsDownloadStatusReport?.totalDurationMs !== void 0) { + initToolsDownloadFields.tools_total_duration_ms = toolsDownloadStatusReport.totalDurationMs; + } if (toolsFeatureFlagsValid !== void 0) { initToolsDownloadFields.tools_feature_flags_valid = toolsFeatureFlagsValid; } diff --git a/package-lock.json b/package-lock.json index c63a1e310..2ef7d4791 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "codeql", - "version": "4.37.9", + "version": "4.37.10", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "codeql", - "version": "4.37.9", + "version": "4.37.10", "license": "MIT", "workspaces": [ "pr-checks" diff --git a/package.json b/package.json index 8f1232ef3..4eaef40a6 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "codeql", - "version": "4.37.9", + "version": "4.37.10", "private": true, "description": "CodeQL action", "scripts": { diff --git a/src/defaults.json b/src/defaults.json index b5d9f1364..1098ef459 100644 --- a/src/defaults.json +++ b/src/defaults.json @@ -1,6 +1,6 @@ { - "bundleVersion": "codeql-bundle-v2.26.3", - "cliVersion": "2.26.3", - "priorBundleVersion": "codeql-bundle-v2.26.2", - "priorCliVersion": "2.26.2" + "bundleVersion": "codeql-bundle-v2.26.4", + "cliVersion": "2.26.4", + "priorBundleVersion": "codeql-bundle-v2.26.3", + "priorCliVersion": "2.26.3" } diff --git a/src/init-action.ts b/src/init-action.ts index 6b5ed392e..8173d67aa 100644 --- a/src/init-action.ts +++ b/src/init-action.ts @@ -174,6 +174,14 @@ async function sendCompletedStatusReport( initToolsDownloadFields.tools_download_duration_ms = toolsDownloadStatusReport.downloadDurationMs; } + if (toolsDownloadStatusReport?.extractionDurationMs !== undefined) { + initToolsDownloadFields.tools_extraction_duration_ms = + toolsDownloadStatusReport.extractionDurationMs; + } + if (toolsDownloadStatusReport?.totalDurationMs !== undefined) { + initToolsDownloadFields.tools_total_duration_ms = + toolsDownloadStatusReport.totalDurationMs; + } if (toolsFeatureFlagsValid !== undefined) { initToolsDownloadFields.tools_feature_flags_valid = toolsFeatureFlagsValid; } diff --git a/src/setup-codeql-action.ts b/src/setup-codeql-action.ts index 7873449f9..bb6b73c9a 100644 --- a/src/setup-codeql-action.ts +++ b/src/setup-codeql-action.ts @@ -85,6 +85,14 @@ async function sendCompletedStatusReport( initToolsDownloadFields.tools_download_duration_ms = toolsDownloadStatusReport.downloadDurationMs; } + if (toolsDownloadStatusReport?.extractionDurationMs !== undefined) { + initToolsDownloadFields.tools_extraction_duration_ms = + toolsDownloadStatusReport.extractionDurationMs; + } + if (toolsDownloadStatusReport?.totalDurationMs !== undefined) { + initToolsDownloadFields.tools_total_duration_ms = + toolsDownloadStatusReport.totalDurationMs; + } if (toolsFeatureFlagsValid !== undefined) { initToolsDownloadFields.tools_feature_flags_valid = toolsFeatureFlagsValid; } diff --git a/src/setup-codeql.test.ts b/src/setup-codeql.test.ts index b6b287ff8..5751688fa 100644 --- a/src/setup-codeql.test.ts +++ b/src/setup-codeql.test.ts @@ -254,6 +254,7 @@ test.serial( codeqlFolder: "codeql", statusReport: { downloadDurationMs: 200, + totalDurationMs: 300, }, toolsVersion: LINKED_CLI_VERSION.cliVersion, }); @@ -306,6 +307,7 @@ test.serial( codeqlFolder: "codeql", statusReport: { downloadDurationMs: 200, + totalDurationMs: 300, }, toolsVersion: expectedVersion, }); diff --git a/src/status-report.ts b/src/status-report.ts index e61b04f9d..57020c394 100644 --- a/src/status-report.ts +++ b/src/status-report.ts @@ -620,8 +620,21 @@ export interface InitWithConfigStatusReport extends InitStatusReport { /** Fields of the init status report populated when the tools source is `download`. */ export interface InitToolsDownloadFields { - /** Time taken to download the bundle, in milliseconds. */ + /** + * Time taken to download the bundle, in milliseconds. Not populated when the bundle is downloaded + * and extracted concurrently. + */ tools_download_duration_ms?: number; + /** + * Time taken to extract the bundle, in milliseconds. Not populated when the bundle is downloaded + * and extracted concurrently. + */ + tools_extraction_duration_ms?: number; + /** + * Total time taken to make the bundle available on disk, in milliseconds. This includes any time + * spent on a streaming attempt that failed and fell back to downloading before extracting. + */ + tools_total_duration_ms?: number; /** * Whether the relevant tools dotcom feature flags have been misconfigured. * Only populated if we attempt to determine the default version based on the dotcom feature flags. */ diff --git a/src/tools-download.test.ts b/src/tools-download.test.ts index 66fe0e72e..d2f15f4dc 100644 --- a/src/tools-download.test.ts +++ b/src/tools-download.test.ts @@ -15,7 +15,7 @@ import { withTmpDir } from "./util"; setupTests(test); test.serial( - "downloadAndExtract reports the duration when downloading before extracting", + "downloadAndExtract reports the durations when downloading before extracting", async (t) => { await withTmpDir(async (tmpDir) => { const archivePath = path.join(tmpDir, "codeql-bundle.tar.gz"); @@ -34,6 +34,8 @@ test.serial( ); t.assert(Number.isInteger(statusReport.downloadDurationMs)); + t.assert(Number.isInteger(statusReport.extractionDurationMs)); + t.assert(Number.isInteger(statusReport.totalDurationMs)); }); }, ); @@ -67,6 +69,7 @@ test.serial( ); t.assert(Number.isInteger(statusReport.downloadDurationMs)); + t.assert(Number.isInteger(statusReport.totalDurationMs)); t.true(request.isDone()); t.false(extractTarZst.called); t.true(downloadTool.calledOnce); @@ -76,7 +79,7 @@ test.serial( ); test.serial( - "downloadAndExtract omits the download duration when streaming extraction", + "downloadAndExtract reports only the total duration when streaming extraction", async (t) => { await withTmpDir(async (tmpDir) => { sinon.stub(process, "platform").value("linux"); @@ -106,7 +109,9 @@ test.serial( getRunnerLogger(true), ); - t.deepEqual(statusReport, {}); + t.assert(Number.isInteger(statusReport.totalDurationMs)); + t.is(statusReport.downloadDurationMs, undefined); + t.is(statusReport.extractionDurationMs, undefined); t.false(downloadTool.called); t.true(extractTarZst.calledOnce); t.true(request.isDone()); diff --git a/src/tools-download.ts b/src/tools-download.ts index 9b2fa8723..d7a978908 100644 --- a/src/tools-download.ts +++ b/src/tools-download.ts @@ -31,7 +31,21 @@ const STREAMING_STALL_TIMEOUT_MS = 5 * 60 * 1000; // 5 minutes const TOOLCACHE_TOOL_NAME = "CodeQL"; export type ToolsDownloadStatusReport = { + /** + * Time spent downloading the bundle, in milliseconds. Not populated when the bundle is downloaded + * and extracted concurrently, since the two cannot be told apart. + */ downloadDurationMs?: number; + /** + * Time spent extracting the bundle, in milliseconds. Not populated when the bundle is downloaded + * and extracted concurrently, since the two cannot be told apart. + */ + extractionDurationMs?: number; + /** + * Total time taken to make the bundle available on disk, in milliseconds. This includes any time + * spent on a streaming attempt that failed and fell back to downloading before extracting. + */ + totalDurationMs: number; }; export async function downloadAndExtract( @@ -47,11 +61,12 @@ export async function downloadAndExtract( `Downloading CodeQL tools from ${codeqlURL} . This may take a while.`, ); + const startTime = performance.now(); + try { if (compressionMethod === "zstd" && process.platform === "linux") { logger.info(`Streaming the extraction of the CodeQL bundle.`); - const toolsInstallStart = performance.now(); await downloadAndExtractZstdWithStreaming( codeqlURL, dest, @@ -61,16 +76,14 @@ export async function downloadAndExtract( logger, ); - const combinedDurationMs = Math.round( - performance.now() - toolsInstallStart, - ); + const totalDurationMs = Math.round(performance.now() - startTime); logger.info( `Finished downloading and extracting CodeQL bundle to ${dest} (${formatDuration( - combinedDurationMs, + totalDurationMs, )}).`, ); - return {}; + return { totalDurationMs }; } } catch (e) { core.warning( @@ -98,7 +111,7 @@ export async function downloadAndExtract( )}).`, ); - let extractionDurationMs: number; + let extractionDurationMs: number | undefined; try { logger.info("Extracting CodeQL bundle."); @@ -120,7 +133,11 @@ export async function downloadAndExtract( await cleanUpPath(archivedBundlePath, "CodeQL bundle archive", logger); } - return { downloadDurationMs }; + return { + downloadDurationMs, + extractionDurationMs, + totalDurationMs: Math.round(performance.now() - startTime), + }; } async function downloadAndExtractZstdWithStreaming(