Merge branch 'main' into mbg/ci/no-more-draft-prs

This commit is contained in:
Michael B. Gale
2026-06-23 18:45:25 +01:00
committed by GitHub
9 changed files with 3076 additions and 2473 deletions

View File

@@ -56,19 +56,19 @@ jobs:
include:
- os: ubuntu-latest
version: stable-v2.19.4
- os: macos-latest-xlarge
- os: macos-15-xlarge
version: stable-v2.19.4
- os: ubuntu-latest
version: stable-v2.20.7
- os: macos-latest-xlarge
- os: macos-15-xlarge
version: stable-v2.20.7
- os: ubuntu-latest
version: stable-v2.21.4
- os: macos-latest-xlarge
- os: macos-15-xlarge
version: stable-v2.21.4
- os: ubuntu-latest
version: stable-v2.22.4
- os: macos-latest-xlarge
- os: macos-15-xlarge
version: stable-v2.22.4
- os: ubuntu-latest
version: stable-v2.23.9
@@ -125,7 +125,8 @@ jobs:
python-version: '3.13'
- name: Use Xcode 16
if: runner.os == 'macOS' && matrix.version != 'nightly-latest'
# Only the older CodeQL CLI versions need Xcode 16, and these run on macOS 15.
if: matrix.os == 'macos-15-xlarge'
run: sudo xcode-select -s "/Applications/Xcode_16.app"
- uses: ./../action/init

View File

@@ -86,9 +86,6 @@ jobs:
version: ${{ matrix.version }}
use-all-platform-bundle: 'false'
setup-kotlin: 'true'
- name: Use Xcode 16
if: runner.os == 'macOS' && matrix.version != 'nightly-latest'
run: sudo xcode-select -s "/Applications/Xcode_16.app"
- uses: ./../action/init
id: init
with:

5414
lib/entry-points.js generated

File diff suppressed because it is too large Load Diff

56
package-lock.json generated
View File

@@ -28,7 +28,7 @@
"follow-redirects": "^1.16.0",
"get-folder-size": "^5.0.0",
"https-proxy-agent": "^7.0.6",
"js-yaml": "^4.2.0",
"js-yaml": "^5.0.0",
"jsonschema": "1.5.0",
"long": "^5.3.2",
"node-forge": "^1.4.0",
@@ -1529,6 +1529,29 @@
"url": "https://github.com/sponsors/sindresorhus"
}
},
"node_modules/@eslint/eslintrc/node_modules/js-yaml": {
"version": "4.2.0",
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.2.0.tgz",
"integrity": "sha512-ePWsvanv0DWuDRsW8dnt+R4jQ31SCRCQ7hhNcPXZPsoBZiemuZNYGf7adZdqX2D86j6rvKp3RpCxVTSb8WQlOw==",
"dev": true,
"funding": [
{
"type": "github",
"url": "https://github.com/sponsors/puzrin"
},
{
"type": "github",
"url": "https://github.com/sponsors/nodeca"
}
],
"license": "MIT",
"dependencies": {
"argparse": "^2.0.1"
},
"bin": {
"js-yaml": "bin/js-yaml.js"
}
},
"node_modules/@eslint/js": {
"version": "9.39.4",
"resolved": "https://registry.npmjs.org/@eslint/js/-/js-9.39.4.tgz",
@@ -2035,6 +2058,29 @@
"url": "https://github.com/sponsors/sindresorhus"
}
},
"node_modules/@microsoft/eslint-formatter-sarif/node_modules/js-yaml": {
"version": "4.2.0",
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.2.0.tgz",
"integrity": "sha512-ePWsvanv0DWuDRsW8dnt+R4jQ31SCRCQ7hhNcPXZPsoBZiemuZNYGf7adZdqX2D86j6rvKp3RpCxVTSb8WQlOw==",
"dev": true,
"funding": [
{
"type": "github",
"url": "https://github.com/sponsors/puzrin"
},
{
"type": "github",
"url": "https://github.com/sponsors/nodeca"
}
],
"license": "MIT",
"dependencies": {
"argparse": "^2.0.1"
},
"bin": {
"js-yaml": "bin/js-yaml.js"
}
},
"node_modules/@mswjs/interceptors": {
"version": "0.41.3",
"resolved": "https://registry.npmjs.org/@mswjs/interceptors/-/interceptors-0.41.3.tgz",
@@ -7059,9 +7105,9 @@
}
},
"node_modules/js-yaml": {
"version": "4.2.0",
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.2.0.tgz",
"integrity": "sha512-ePWsvanv0DWuDRsW8dnt+R4jQ31SCRCQ7hhNcPXZPsoBZiemuZNYGf7adZdqX2D86j6rvKp3RpCxVTSb8WQlOw==",
"version": "5.0.0",
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-5.0.0.tgz",
"integrity": "sha512-GSvaPUbk1U+FMZ7rJzF+F8e5YVtu7KnD40et/5rBXXRBv2jCO9L3qCewvIDDdudC0QycTFlf6EAA+h3kxBsuUw==",
"funding": [
{
"type": "github",
@@ -7077,7 +7123,7 @@
"argparse": "^2.0.1"
},
"bin": {
"js-yaml": "bin/js-yaml.js"
"js-yaml": "bin/js-yaml.mjs"
}
},
"node_modules/jschardet": {

View File

@@ -36,7 +36,7 @@
"follow-redirects": "^1.16.0",
"get-folder-size": "^5.0.0",
"https-proxy-agent": "^7.0.6",
"js-yaml": "^4.2.0",
"js-yaml": "^5.0.0",
"jsonschema": "1.5.0",
"long": "^5.3.2",
"node-forge": "^1.4.0",

View File

@@ -4,6 +4,16 @@ operatingSystems:
- ubuntu
- os: macos
runner-image: macos-latest-xlarge
# Older CodeQL CLI versions only support Swift up to 6.1, which requires Xcode 16. That is
# not available on macOS 26, so run these versions on macOS 15 where we select Xcode 16
# below. See https://github.com/actions/runner-images/issues/14167.
- os: macos
runner-image: macos-15-xlarge
codeql-versions:
- stable-v2.19.4
- stable-v2.20.7
- stable-v2.21.4
- stable-v2.22.4
env:
CODEQL_ACTION_RESOLVE_SUPPORTED_LANGUAGES_USING_CLI: true
installGo: true
@@ -18,7 +28,8 @@ steps:
python-version: "3.13"
- name: Use Xcode 16
if: runner.os == 'macOS' && matrix.version != 'nightly-latest'
# Only the older CodeQL CLI versions need Xcode 16, and these run on macOS 15.
if: matrix.os == 'macos-15-xlarge'
run: sudo xcode-select -s "/Applications/Xcode_16.app"
- uses: ./../action/init

View File

@@ -11,9 +11,6 @@ installDotNet: true
env:
DOTNET_GENERATE_ASPNET_CERTIFICATE: "false"
steps:
- name: Use Xcode 16
if: runner.os == 'macOS' && matrix.version != 'nightly-latest'
run: sudo xcode-select -s "/Applications/Xcode_16.app"
- uses: ./../action/init
id: init
with:

View File

@@ -54,6 +54,13 @@ type OperatingSystem =
os: OperatingSystemIdentifier;
/** Optional runner image label. */
"runner-image"?: string;
/**
* Optional CodeQL versions to run on this entry. If specified, this entry runs only these
* versions. A sibling entry for the same OS that omits `codeql-versions` runs all versions
* not claimed by any sibling entry. This allows pinning specific CodeQL versions to a
* particular runner image while letting the remaining versions default to another.
*/
"codeql-versions"?: string[];
};
/**
@@ -352,6 +359,28 @@ function generateJobMatrix(
): Array<Record<string, any>> {
let matrix: Array<Record<string, any>> = [];
const operatingSystems = checkSpecification.operatingSystems ?? ["ubuntu"];
// For each OS, collect the CodeQL versions explicitly claimed by entries that specify
// `codeql-versions`. A sibling entry for the same OS that omits `codeql-versions` runs all
// versions not in this set.
const claimedVersionsByOs = new Map<string, Set<string>>();
for (const operatingSystemConfig of operatingSystems) {
if (typeof operatingSystemConfig === "string") {
continue;
}
const entryVersions = operatingSystemConfig["codeql-versions"];
if (!entryVersions) {
continue;
}
const claimed =
claimedVersionsByOs.get(operatingSystemConfig.os) ?? new Set<string>();
for (const entryVersion of entryVersions) {
claimed.add(entryVersion);
}
claimedVersionsByOs.set(operatingSystemConfig.os, claimed);
}
for (const version of checkSpecification.versions ?? defaultTestVersions) {
if (version === "latest") {
throw new Error(
@@ -364,7 +393,6 @@ function generateJobMatrix(
"macos-latest",
"windows-latest",
];
const operatingSystems = checkSpecification.operatingSystems ?? ["ubuntu"];
for (const operatingSystemConfig of operatingSystems) {
const operatingSystem =
@@ -379,6 +407,19 @@ function generateJobMatrix(
continue;
}
// An entry that specifies `codeql-versions` runs only those versions. A sibling entry for
// the same OS that omits `codeql-versions` runs all versions not claimed by its siblings.
const entryVersions =
typeof operatingSystemConfig === "string"
? undefined
: operatingSystemConfig["codeql-versions"];
const runsThisVersion = entryVersions
? entryVersions.includes(version)
: !claimedVersionsByOs.get(operatingSystem)?.has(version);
if (!runsThisVersion) {
continue;
}
const runnerImagesForOs =
typeof operatingSystemConfig === "string" ||
operatingSystemConfig["runner-image"] === undefined

View File

@@ -281,11 +281,11 @@ extensions:
.join(checkoutPath, range.path)
.replaceAll(path.sep, "/");
// Using yaml.dump() with `forceQuotes: true` ensures that all special
// Using yaml.dump() with `quoteStyle: "double"` ensures that all special
// characters are escaped, and that the path is always rendered as a
// quoted string on a single line.
return (
` - [${yaml.dump(filename, { forceQuotes: true }).trim()}, ` +
` - [${yaml.dump(filename, { quoteStyle: "single" }).trim()}, ` +
`${range.startLine}, ${range.endLine}]\n`
);
})