mirror of
https://github.com/github/codeql-action.git
synced 2026-10-03 09:14:58 +00:00
Merge branch 'main' into mbg/ci/no-more-draft-prs
This commit is contained in:
11
.github/workflows/__multi-language-autodetect.yml
generated
vendored
11
.github/workflows/__multi-language-autodetect.yml
generated
vendored
@@ -56,19 +56,19 @@ jobs:
|
||||
include:
|
||||
- os: ubuntu-latest
|
||||
version: stable-v2.19.4
|
||||
- os: macos-latest-xlarge
|
||||
- os: macos-15-xlarge
|
||||
version: stable-v2.19.4
|
||||
- os: ubuntu-latest
|
||||
version: stable-v2.20.7
|
||||
- os: macos-latest-xlarge
|
||||
- os: macos-15-xlarge
|
||||
version: stable-v2.20.7
|
||||
- os: ubuntu-latest
|
||||
version: stable-v2.21.4
|
||||
- os: macos-latest-xlarge
|
||||
- os: macos-15-xlarge
|
||||
version: stable-v2.21.4
|
||||
- os: ubuntu-latest
|
||||
version: stable-v2.22.4
|
||||
- os: macos-latest-xlarge
|
||||
- os: macos-15-xlarge
|
||||
version: stable-v2.22.4
|
||||
- os: ubuntu-latest
|
||||
version: stable-v2.23.9
|
||||
@@ -125,7 +125,8 @@ jobs:
|
||||
python-version: '3.13'
|
||||
|
||||
- name: Use Xcode 16
|
||||
if: runner.os == 'macOS' && matrix.version != 'nightly-latest'
|
||||
# Only the older CodeQL CLI versions need Xcode 16, and these run on macOS 15.
|
||||
if: matrix.os == 'macos-15-xlarge'
|
||||
run: sudo xcode-select -s "/Applications/Xcode_16.app"
|
||||
|
||||
- uses: ./../action/init
|
||||
|
||||
3
.github/workflows/__swift-custom-build.yml
generated
vendored
3
.github/workflows/__swift-custom-build.yml
generated
vendored
@@ -86,9 +86,6 @@ jobs:
|
||||
version: ${{ matrix.version }}
|
||||
use-all-platform-bundle: 'false'
|
||||
setup-kotlin: 'true'
|
||||
- name: Use Xcode 16
|
||||
if: runner.os == 'macOS' && matrix.version != 'nightly-latest'
|
||||
run: sudo xcode-select -s "/Applications/Xcode_16.app"
|
||||
- uses: ./../action/init
|
||||
id: init
|
||||
with:
|
||||
|
||||
5414
lib/entry-points.js
generated
5414
lib/entry-points.js
generated
File diff suppressed because it is too large
Load Diff
56
package-lock.json
generated
56
package-lock.json
generated
@@ -28,7 +28,7 @@
|
||||
"follow-redirects": "^1.16.0",
|
||||
"get-folder-size": "^5.0.0",
|
||||
"https-proxy-agent": "^7.0.6",
|
||||
"js-yaml": "^4.2.0",
|
||||
"js-yaml": "^5.0.0",
|
||||
"jsonschema": "1.5.0",
|
||||
"long": "^5.3.2",
|
||||
"node-forge": "^1.4.0",
|
||||
@@ -1529,6 +1529,29 @@
|
||||
"url": "https://github.com/sponsors/sindresorhus"
|
||||
}
|
||||
},
|
||||
"node_modules/@eslint/eslintrc/node_modules/js-yaml": {
|
||||
"version": "4.2.0",
|
||||
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.2.0.tgz",
|
||||
"integrity": "sha512-ePWsvanv0DWuDRsW8dnt+R4jQ31SCRCQ7hhNcPXZPsoBZiemuZNYGf7adZdqX2D86j6rvKp3RpCxVTSb8WQlOw==",
|
||||
"dev": true,
|
||||
"funding": [
|
||||
{
|
||||
"type": "github",
|
||||
"url": "https://github.com/sponsors/puzrin"
|
||||
},
|
||||
{
|
||||
"type": "github",
|
||||
"url": "https://github.com/sponsors/nodeca"
|
||||
}
|
||||
],
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"argparse": "^2.0.1"
|
||||
},
|
||||
"bin": {
|
||||
"js-yaml": "bin/js-yaml.js"
|
||||
}
|
||||
},
|
||||
"node_modules/@eslint/js": {
|
||||
"version": "9.39.4",
|
||||
"resolved": "https://registry.npmjs.org/@eslint/js/-/js-9.39.4.tgz",
|
||||
@@ -2035,6 +2058,29 @@
|
||||
"url": "https://github.com/sponsors/sindresorhus"
|
||||
}
|
||||
},
|
||||
"node_modules/@microsoft/eslint-formatter-sarif/node_modules/js-yaml": {
|
||||
"version": "4.2.0",
|
||||
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.2.0.tgz",
|
||||
"integrity": "sha512-ePWsvanv0DWuDRsW8dnt+R4jQ31SCRCQ7hhNcPXZPsoBZiemuZNYGf7adZdqX2D86j6rvKp3RpCxVTSb8WQlOw==",
|
||||
"dev": true,
|
||||
"funding": [
|
||||
{
|
||||
"type": "github",
|
||||
"url": "https://github.com/sponsors/puzrin"
|
||||
},
|
||||
{
|
||||
"type": "github",
|
||||
"url": "https://github.com/sponsors/nodeca"
|
||||
}
|
||||
],
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"argparse": "^2.0.1"
|
||||
},
|
||||
"bin": {
|
||||
"js-yaml": "bin/js-yaml.js"
|
||||
}
|
||||
},
|
||||
"node_modules/@mswjs/interceptors": {
|
||||
"version": "0.41.3",
|
||||
"resolved": "https://registry.npmjs.org/@mswjs/interceptors/-/interceptors-0.41.3.tgz",
|
||||
@@ -7059,9 +7105,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/js-yaml": {
|
||||
"version": "4.2.0",
|
||||
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.2.0.tgz",
|
||||
"integrity": "sha512-ePWsvanv0DWuDRsW8dnt+R4jQ31SCRCQ7hhNcPXZPsoBZiemuZNYGf7adZdqX2D86j6rvKp3RpCxVTSb8WQlOw==",
|
||||
"version": "5.0.0",
|
||||
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-5.0.0.tgz",
|
||||
"integrity": "sha512-GSvaPUbk1U+FMZ7rJzF+F8e5YVtu7KnD40et/5rBXXRBv2jCO9L3qCewvIDDdudC0QycTFlf6EAA+h3kxBsuUw==",
|
||||
"funding": [
|
||||
{
|
||||
"type": "github",
|
||||
@@ -7077,7 +7123,7 @@
|
||||
"argparse": "^2.0.1"
|
||||
},
|
||||
"bin": {
|
||||
"js-yaml": "bin/js-yaml.js"
|
||||
"js-yaml": "bin/js-yaml.mjs"
|
||||
}
|
||||
},
|
||||
"node_modules/jschardet": {
|
||||
|
||||
@@ -36,7 +36,7 @@
|
||||
"follow-redirects": "^1.16.0",
|
||||
"get-folder-size": "^5.0.0",
|
||||
"https-proxy-agent": "^7.0.6",
|
||||
"js-yaml": "^4.2.0",
|
||||
"js-yaml": "^5.0.0",
|
||||
"jsonschema": "1.5.0",
|
||||
"long": "^5.3.2",
|
||||
"node-forge": "^1.4.0",
|
||||
|
||||
@@ -4,6 +4,16 @@ operatingSystems:
|
||||
- ubuntu
|
||||
- os: macos
|
||||
runner-image: macos-latest-xlarge
|
||||
# Older CodeQL CLI versions only support Swift up to 6.1, which requires Xcode 16. That is
|
||||
# not available on macOS 26, so run these versions on macOS 15 where we select Xcode 16
|
||||
# below. See https://github.com/actions/runner-images/issues/14167.
|
||||
- os: macos
|
||||
runner-image: macos-15-xlarge
|
||||
codeql-versions:
|
||||
- stable-v2.19.4
|
||||
- stable-v2.20.7
|
||||
- stable-v2.21.4
|
||||
- stable-v2.22.4
|
||||
env:
|
||||
CODEQL_ACTION_RESOLVE_SUPPORTED_LANGUAGES_USING_CLI: true
|
||||
installGo: true
|
||||
@@ -18,7 +28,8 @@ steps:
|
||||
python-version: "3.13"
|
||||
|
||||
- name: Use Xcode 16
|
||||
if: runner.os == 'macOS' && matrix.version != 'nightly-latest'
|
||||
# Only the older CodeQL CLI versions need Xcode 16, and these run on macOS 15.
|
||||
if: matrix.os == 'macos-15-xlarge'
|
||||
run: sudo xcode-select -s "/Applications/Xcode_16.app"
|
||||
|
||||
- uses: ./../action/init
|
||||
|
||||
@@ -11,9 +11,6 @@ installDotNet: true
|
||||
env:
|
||||
DOTNET_GENERATE_ASPNET_CERTIFICATE: "false"
|
||||
steps:
|
||||
- name: Use Xcode 16
|
||||
if: runner.os == 'macOS' && matrix.version != 'nightly-latest'
|
||||
run: sudo xcode-select -s "/Applications/Xcode_16.app"
|
||||
- uses: ./../action/init
|
||||
id: init
|
||||
with:
|
||||
|
||||
@@ -54,6 +54,13 @@ type OperatingSystem =
|
||||
os: OperatingSystemIdentifier;
|
||||
/** Optional runner image label. */
|
||||
"runner-image"?: string;
|
||||
/**
|
||||
* Optional CodeQL versions to run on this entry. If specified, this entry runs only these
|
||||
* versions. A sibling entry for the same OS that omits `codeql-versions` runs all versions
|
||||
* not claimed by any sibling entry. This allows pinning specific CodeQL versions to a
|
||||
* particular runner image while letting the remaining versions default to another.
|
||||
*/
|
||||
"codeql-versions"?: string[];
|
||||
};
|
||||
|
||||
/**
|
||||
@@ -352,6 +359,28 @@ function generateJobMatrix(
|
||||
): Array<Record<string, any>> {
|
||||
let matrix: Array<Record<string, any>> = [];
|
||||
|
||||
const operatingSystems = checkSpecification.operatingSystems ?? ["ubuntu"];
|
||||
|
||||
// For each OS, collect the CodeQL versions explicitly claimed by entries that specify
|
||||
// `codeql-versions`. A sibling entry for the same OS that omits `codeql-versions` runs all
|
||||
// versions not in this set.
|
||||
const claimedVersionsByOs = new Map<string, Set<string>>();
|
||||
for (const operatingSystemConfig of operatingSystems) {
|
||||
if (typeof operatingSystemConfig === "string") {
|
||||
continue;
|
||||
}
|
||||
const entryVersions = operatingSystemConfig["codeql-versions"];
|
||||
if (!entryVersions) {
|
||||
continue;
|
||||
}
|
||||
const claimed =
|
||||
claimedVersionsByOs.get(operatingSystemConfig.os) ?? new Set<string>();
|
||||
for (const entryVersion of entryVersions) {
|
||||
claimed.add(entryVersion);
|
||||
}
|
||||
claimedVersionsByOs.set(operatingSystemConfig.os, claimed);
|
||||
}
|
||||
|
||||
for (const version of checkSpecification.versions ?? defaultTestVersions) {
|
||||
if (version === "latest") {
|
||||
throw new Error(
|
||||
@@ -364,7 +393,6 @@ function generateJobMatrix(
|
||||
"macos-latest",
|
||||
"windows-latest",
|
||||
];
|
||||
const operatingSystems = checkSpecification.operatingSystems ?? ["ubuntu"];
|
||||
|
||||
for (const operatingSystemConfig of operatingSystems) {
|
||||
const operatingSystem =
|
||||
@@ -379,6 +407,19 @@ function generateJobMatrix(
|
||||
continue;
|
||||
}
|
||||
|
||||
// An entry that specifies `codeql-versions` runs only those versions. A sibling entry for
|
||||
// the same OS that omits `codeql-versions` runs all versions not claimed by its siblings.
|
||||
const entryVersions =
|
||||
typeof operatingSystemConfig === "string"
|
||||
? undefined
|
||||
: operatingSystemConfig["codeql-versions"];
|
||||
const runsThisVersion = entryVersions
|
||||
? entryVersions.includes(version)
|
||||
: !claimedVersionsByOs.get(operatingSystem)?.has(version);
|
||||
if (!runsThisVersion) {
|
||||
continue;
|
||||
}
|
||||
|
||||
const runnerImagesForOs =
|
||||
typeof operatingSystemConfig === "string" ||
|
||||
operatingSystemConfig["runner-image"] === undefined
|
||||
|
||||
@@ -281,11 +281,11 @@ extensions:
|
||||
.join(checkoutPath, range.path)
|
||||
.replaceAll(path.sep, "/");
|
||||
|
||||
// Using yaml.dump() with `forceQuotes: true` ensures that all special
|
||||
// Using yaml.dump() with `quoteStyle: "double"` ensures that all special
|
||||
// characters are escaped, and that the path is always rendered as a
|
||||
// quoted string on a single line.
|
||||
return (
|
||||
` - [${yaml.dump(filename, { forceQuotes: true }).trim()}, ` +
|
||||
` - [${yaml.dump(filename, { quoteStyle: "single" }).trim()}, ` +
|
||||
`${range.startLine}, ${range.endLine}]\n`
|
||||
);
|
||||
})
|
||||
|
||||
Reference in New Issue
Block a user