diff --git a/lib/analyze-action-post.js b/lib/analyze-action-post.js index aaed462b3..c62fe14bc 100644 --- a/lib/analyze-action-post.js +++ b/lib/analyze-action-post.js @@ -46044,6 +46044,7 @@ var require_package = __commonJS({ "@types/js-yaml": "^4.0.9", "@types/node": "^20.19.9", "@types/node-forge": "^1.3.14", + "@types/sarif": "^2.1.7", "@types/semver": "^7.7.1", "@types/sinon": "^21.0.0", ava: "^6.4.1", diff --git a/lib/analyze-action.js b/lib/analyze-action.js index 982289ce3..15d0059a0 100644 --- a/lib/analyze-action.js +++ b/lib/analyze-action.js @@ -46044,6 +46044,7 @@ var require_package = __commonJS({ "@types/js-yaml": "^4.0.9", "@types/node": "^20.19.9", "@types/node-forge": "^1.3.14", + "@types/sarif": "^2.1.7", "@types/semver": "^7.7.1", "@types/sinon": "^21.0.0", ava: "^6.4.1", @@ -105901,9 +105902,9 @@ var semver = __toESM(require_semver2()); var fs = __toESM(require("fs")); var InvalidSarifUploadError = class extends Error { }; -function getToolNames(sarif) { +function getToolNames(sarifFile) { const toolNames = {}; - for (const run2 of sarif.runs || []) { + for (const run2 of sarifFile.runs || []) { const tool = run2.tool || {}; const driver = tool.driver || {}; if (typeof driver.name === "string" && driver.name.length > 0) { @@ -105918,7 +105919,7 @@ function readSarifFile(sarifFilePath) { function combineSarifFiles(sarifFiles, logger) { logger.info(`Loading SARIF file(s)`); const combinedSarif = { - version: null, + version: "2.1.0", runs: [] }; for (const sarifFile of sarifFiles) { diff --git a/lib/autobuild-action.js b/lib/autobuild-action.js index a5e822b8e..b5886f65c 100644 --- a/lib/autobuild-action.js +++ b/lib/autobuild-action.js @@ -46044,6 +46044,7 @@ var require_package = __commonJS({ "@types/js-yaml": "^4.0.9", "@types/node": "^20.19.9", "@types/node-forge": "^1.3.14", + "@types/sarif": "^2.1.7", "@types/semver": "^7.7.1", "@types/sinon": "^21.0.0", ava: "^6.4.1", diff --git a/lib/init-action-post.js b/lib/init-action-post.js index 7631d46f7..7bc36d338 100644 --- a/lib/init-action-post.js +++ b/lib/init-action-post.js @@ -46044,6 +46044,7 @@ var require_package = __commonJS({ "@types/js-yaml": "^4.0.9", "@types/node": "^20.19.9", "@types/node-forge": "^1.3.14", + "@types/sarif": "^2.1.7", "@types/semver": "^7.7.1", "@types/sinon": "^21.0.0", ava: "^6.4.1", @@ -164004,9 +164005,9 @@ var minimumVersion = "3.14"; var fs = __toESM(require("fs")); var InvalidSarifUploadError = class extends Error { }; -function getToolNames(sarif) { +function getToolNames(sarifFile) { const toolNames = {}; - for (const run3 of sarif.runs || []) { + for (const run3 of sarifFile.runs || []) { const tool = run3.tool || {}; const driver = tool.driver || {}; if (typeof driver.name === "string" && driver.name.length > 0) { @@ -164021,7 +164022,7 @@ function readSarifFile(sarifFilePath) { function combineSarifFiles(sarifFiles, logger) { logger.info(`Loading SARIF file(s)`); const combinedSarif = { - version: null, + version: "2.1.0", runs: [] }; for (const sarifFile of sarifFiles) { diff --git a/lib/init-action.js b/lib/init-action.js index bce9e2dfc..35173ccc1 100644 --- a/lib/init-action.js +++ b/lib/init-action.js @@ -46044,6 +46044,7 @@ var require_package = __commonJS({ "@types/js-yaml": "^4.0.9", "@types/node": "^20.19.9", "@types/node-forge": "^1.3.14", + "@types/sarif": "^2.1.7", "@types/semver": "^7.7.1", "@types/sinon": "^21.0.0", ava: "^6.4.1", diff --git a/lib/resolve-environment-action.js b/lib/resolve-environment-action.js index fe419d910..d9929d50a 100644 --- a/lib/resolve-environment-action.js +++ b/lib/resolve-environment-action.js @@ -46044,6 +46044,7 @@ var require_package = __commonJS({ "@types/js-yaml": "^4.0.9", "@types/node": "^20.19.9", "@types/node-forge": "^1.3.14", + "@types/sarif": "^2.1.7", "@types/semver": "^7.7.1", "@types/sinon": "^21.0.0", ava: "^6.4.1", diff --git a/lib/setup-codeql-action.js b/lib/setup-codeql-action.js index e9a5e8dce..02dfee0e4 100644 --- a/lib/setup-codeql-action.js +++ b/lib/setup-codeql-action.js @@ -46044,6 +46044,7 @@ var require_package = __commonJS({ "@types/js-yaml": "^4.0.9", "@types/node": "^20.19.9", "@types/node-forge": "^1.3.14", + "@types/sarif": "^2.1.7", "@types/semver": "^7.7.1", "@types/sinon": "^21.0.0", ava: "^6.4.1", diff --git a/lib/start-proxy-action-post.js b/lib/start-proxy-action-post.js index 14fa9fd05..145b953d1 100644 --- a/lib/start-proxy-action-post.js +++ b/lib/start-proxy-action-post.js @@ -46044,6 +46044,7 @@ var require_package = __commonJS({ "@types/js-yaml": "^4.0.9", "@types/node": "^20.19.9", "@types/node-forge": "^1.3.14", + "@types/sarif": "^2.1.7", "@types/semver": "^7.7.1", "@types/sinon": "^21.0.0", ava: "^6.4.1", diff --git a/lib/start-proxy-action.js b/lib/start-proxy-action.js index 13996a08f..389e59502 100644 --- a/lib/start-proxy-action.js +++ b/lib/start-proxy-action.js @@ -46044,6 +46044,7 @@ var require_package = __commonJS({ "@types/js-yaml": "^4.0.9", "@types/node": "^20.19.9", "@types/node-forge": "^1.3.14", + "@types/sarif": "^2.1.7", "@types/semver": "^7.7.1", "@types/sinon": "^21.0.0", ava: "^6.4.1", diff --git a/lib/upload-lib.js b/lib/upload-lib.js index a258cc46a..13996f1d0 100644 --- a/lib/upload-lib.js +++ b/lib/upload-lib.js @@ -47341,6 +47341,7 @@ var require_package = __commonJS({ "@types/js-yaml": "^4.0.9", "@types/node": "^20.19.9", "@types/node-forge": "^1.3.14", + "@types/sarif": "^2.1.7", "@types/semver": "^7.7.1", "@types/sinon": "^21.0.0", ava: "^6.4.1", @@ -105917,9 +105918,9 @@ var semver = __toESM(require_semver2()); var fs = __toESM(require("fs")); var InvalidSarifUploadError = class extends Error { }; -function getToolNames(sarif) { +function getToolNames(sarifFile) { const toolNames = {}; - for (const run of sarif.runs || []) { + for (const run of sarifFile.runs || []) { const tool = run.tool || {}; const driver = tool.driver || {}; if (typeof driver.name === "string" && driver.name.length > 0) { @@ -105934,7 +105935,7 @@ function readSarifFile(sarifFilePath) { function combineSarifFiles(sarifFiles, logger) { logger.info(`Loading SARIF file(s)`); const combinedSarif = { - version: null, + version: "2.1.0", runs: [] }; for (const sarifFile of sarifFiles) { diff --git a/lib/upload-sarif-action-post.js b/lib/upload-sarif-action-post.js index 103b279d1..1c7a49152 100644 --- a/lib/upload-sarif-action-post.js +++ b/lib/upload-sarif-action-post.js @@ -46044,6 +46044,7 @@ var require_package = __commonJS({ "@types/js-yaml": "^4.0.9", "@types/node": "^20.19.9", "@types/node-forge": "^1.3.14", + "@types/sarif": "^2.1.7", "@types/semver": "^7.7.1", "@types/sinon": "^21.0.0", ava: "^6.4.1", diff --git a/lib/upload-sarif-action.js b/lib/upload-sarif-action.js index f853efa10..5cf366968 100644 --- a/lib/upload-sarif-action.js +++ b/lib/upload-sarif-action.js @@ -46044,6 +46044,7 @@ var require_package = __commonJS({ "@types/js-yaml": "^4.0.9", "@types/node": "^20.19.9", "@types/node-forge": "^1.3.14", + "@types/sarif": "^2.1.7", "@types/semver": "^7.7.1", "@types/sinon": "^21.0.0", ava: "^6.4.1", @@ -105892,9 +105893,9 @@ var semver = __toESM(require_semver2()); var fs = __toESM(require("fs")); var InvalidSarifUploadError = class extends Error { }; -function getToolNames(sarif) { +function getToolNames(sarifFile) { const toolNames = {}; - for (const run2 of sarif.runs || []) { + for (const run2 of sarifFile.runs || []) { const tool = run2.tool || {}; const driver = tool.driver || {}; if (typeof driver.name === "string" && driver.name.length > 0) { @@ -105909,7 +105910,7 @@ function readSarifFile(sarifFilePath) { function combineSarifFiles(sarifFiles, logger) { logger.info(`Loading SARIF file(s)`); const combinedSarif = { - version: null, + version: "2.1.0", runs: [] }; for (const sarifFile of sarifFiles) { diff --git a/src/sarif/index.ts b/src/sarif/index.ts index 11f5f6e3d..acb19e1e9 100644 --- a/src/sarif/index.ts +++ b/src/sarif/index.ts @@ -2,84 +2,18 @@ import * as fs from "fs"; import { Logger } from "../logging"; -export interface SarifLocation { - physicalLocation?: { - artifactLocation?: { - uri?: string; - }; - }; -} +import * as sarif from "sarif"; -export interface SarifNotification { - locations?: SarifLocation[]; -} +// Re-export some types with other names for backwards-compatibility +export type SarifLocation = sarif.Location; +export type SarifNotification = sarif.Notification; +export type SarifInvocation = sarif.Invocation; +export type SarifResult = sarif.Result; +export type SarifRun = sarif.Run; +export type SarifFile = sarif.Log; -export interface SarifInvocation { - toolExecutionNotifications?: SarifNotification[]; -} - -export interface SarifResult { - ruleId?: string; - rule?: { - id?: string; - }; - message?: { - text?: string; - }; - locations: Array<{ - physicalLocation: { - artifactLocation: { - uri: string; - }; - region?: { - startLine?: number; - }; - }; - }>; - relatedLocations?: Array<{ - physicalLocation: { - artifactLocation: { - uri: string; - }; - region?: { - startLine?: number; - }; - }; - }>; - partialFingerprints: { - primaryLocationLineHash?: string; - }; -} - -export interface SarifRun { - tool?: { - driver?: { - guid?: string; - name?: string; - fullName?: string; - semanticVersion?: string; - version?: string; - }; - }; - automationDetails?: { - id?: string; - }; - artifacts?: string[]; - invocations?: SarifInvocation[]; - results?: SarifResult[]; -} - -export interface SarifFile { - version?: string | null; - runs: SarifRun[]; -} - -export type SarifRunKey = { - name: string | undefined; - fullName: string | undefined; - version: string | undefined; - semanticVersion: string | undefined; - guid: string | undefined; +// `automationId` is non-standard. +export type SarifRunKey = sarif.ToolComponent & { automationId: string | undefined; }; @@ -93,10 +27,10 @@ export class InvalidSarifUploadError extends Error {} * * Returns an array of unique string tool names. */ -export function getToolNames(sarif: SarifFile): string[] { +export function getToolNames(sarifFile: SarifFile): string[] { const toolNames = {}; - for (const run of sarif.runs || []) { + for (const run of sarifFile.runs || []) { const tool = run.tool || {}; const driver = tool.driver || {}; if (typeof driver.name === "string" && driver.name.length > 0) { @@ -119,7 +53,7 @@ export function combineSarifFiles( ): SarifFile { logger.info(`Loading SARIF file(s)`); const combinedSarif: SarifFile = { - version: null, + version: "2.1.0", runs: [], }; diff --git a/src/upload-lib.test.ts b/src/upload-lib.test.ts index 677d9f2aa..dbaa7d8e0 100644 --- a/src/upload-lib.test.ts +++ b/src/upload-lib.test.ts @@ -13,7 +13,12 @@ import { getRunnerLogger, Logger } from "./logging"; import { setupTests } from "./testing-utils"; import * as uploadLib from "./upload-lib"; import { UploadPayload } from "./upload-lib/types"; -import { GitHubVariant, initializeEnvironment, withTmpDir } from "./util"; +import { + GitHubVariant, + initializeEnvironment, + SarifFile, + withTmpDir, +} from "./util"; setupTests(test); @@ -262,13 +267,18 @@ test("getGroupedSarifFilePaths - Other file", async (t) => { }); test("populateRunAutomationDetails", (t) => { - let sarif = { - runs: [{}], + const tool = { driver: { name: "test tool" } }; + let sarif: SarifFile = { + version: "2.1.0", + runs: [{ tool }], }; const analysisKey = ".github/workflows/codeql-analysis.yml:analyze"; - let expectedSarif = { - runs: [{ automationDetails: { id: "language:javascript/os:linux/" } }], + let expectedSarif: SarifFile = { + version: "2.1.0", + runs: [ + { tool, automationDetails: { id: "language:javascript/os:linux/" } }, + ], }; // Category has priority over analysis_key/environment @@ -290,8 +300,14 @@ test("populateRunAutomationDetails", (t) => { t.deepEqual(modifiedSarif, expectedSarif); // check that the automation details doesn't get overwritten - sarif = { runs: [{ automationDetails: { id: "my_id" } }] }; - expectedSarif = { runs: [{ automationDetails: { id: "my_id" } }] }; + sarif = { + version: "2.1.0", + runs: [{ tool, automationDetails: { id: "my_id" } }], + }; + expectedSarif = { + version: "2.1.0", + runs: [{ tool, automationDetails: { id: "my_id" } }], + }; modifiedSarif = uploadLib.populateRunAutomationDetails( sarif, undefined, @@ -301,11 +317,16 @@ test("populateRunAutomationDetails", (t) => { t.deepEqual(modifiedSarif, expectedSarif); // check multiple runs - sarif = { runs: [{ automationDetails: { id: "my_id" } }, {}] }; + sarif = { + version: "2.1.0", + runs: [{ tool, automationDetails: { id: "my_id" } }, { tool }], + }; expectedSarif = { + version: "2.1.0", runs: [ - { automationDetails: { id: "my_id" } }, + { tool, automationDetails: { id: "my_id" } }, { + tool, automationDetails: { id: ".github/workflows/codeql-analysis.yml:analyze/language:javascript/os:linux/", }, @@ -515,20 +536,8 @@ test("validateUniqueCategory for automation details id and tool name", (t) => { ); // Our category sanitization is not perfect. Here are some examples - // of where we see false clashes - t.notThrows(() => - uploadLib.validateUniqueCategory( - createMockSarif("abc"), - CodeScanning.sentinelPrefix, - ), - ); - t.throws(() => - uploadLib.validateUniqueCategory( - createMockSarif("abc", "_"), - CodeScanning.sentinelPrefix, - ), - ); - + // of where we see false clashes because we replace some characters + // with `_` in `sanitize`. t.notThrows(() => uploadLib.validateUniqueCategory( createMockSarif("abc", "def__"), @@ -537,7 +546,7 @@ test("validateUniqueCategory for automation details id and tool name", (t) => { ); t.throws(() => uploadLib.validateUniqueCategory( - createMockSarif("abc_def"), + createMockSarif("abc_def", "_"), CodeScanning.sentinelPrefix, ), ); @@ -561,7 +570,10 @@ test("validateUniqueCategory for multiple runs", (t) => { const sarif2 = createMockSarif("ghi", "jkl"); // duplicate categories are allowed within the same sarif file - const multiSarif = { runs: [sarif1.runs[0], sarif1.runs[0], sarif2.runs[0]] }; + const multiSarif: SarifFile = { + version: "2.1.0", + runs: [sarif1.runs[0], sarif1.runs[0], sarif2.runs[0]], + }; t.notThrows(() => uploadLib.validateUniqueCategory(multiSarif, CodeScanning.sentinelPrefix), ); @@ -891,8 +903,9 @@ test("shouldConsiderInvalidRequest returns correct recognises processing errors" t.false(uploadLib.shouldConsiderInvalidRequest(error3)); }); -function createMockSarif(id?: string, tool?: string) { +function createMockSarif(id?: string, tool?: string): SarifFile { return { + version: "2.1.0", runs: [ { automationDetails: { @@ -900,7 +913,7 @@ function createMockSarif(id?: string, tool?: string) { }, tool: { driver: { - name: tool, + name: tool || "test tool", }, }, }, diff --git a/src/upload-sarif.test.ts b/src/upload-sarif.test.ts index d32c0c031..e7ee91174 100644 --- a/src/upload-sarif.test.ts +++ b/src/upload-sarif.test.ts @@ -33,7 +33,11 @@ function mockPostProcessSarifFiles() { sinon.match.any, analysisConfig, ) - .resolves({ sarif: { runs: [] }, analysisKey: "", environment: "" }); + .resolves({ + sarif: { version: "2.1.0", runs: [] }, + analysisKey: "", + environment: "", + }); } return postProcessSarifFiles;