Expect the Actions bundle to contain the JavaScript extractor

The Actions QL pack depends on the JavaScript one, which is the only
dependency of its kind, so the Actions bundle carries the JavaScript
extractor as well as its own. Let each language declare the extractors
its bundle is expected to contain, so that the check still fails if a
bundle contains anything beyond what its language needs.

Fold the generated Actions-only check into this workflow, which now
covers every language, and with it the ability for a generated check to
run on additional branches, which nothing needs any more.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: d4c7b873-8278-4a36-b67c-6cc5ea3b2316
This commit is contained in:
Henry Mercer
2026-08-26 16:21:22 +01:00
parent a1e61b1512
commit cc807b741b
4 changed files with 19 additions and 181 deletions

View File

@@ -1,105 +0,0 @@
# Warning: This file is generated automatically, and should not be modified.
# Instead, please modify the template in the pr-checks directory and run:
# pr-checks/sync.sh
# to regenerate this file.
name: PR Check - Per-language bundle
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GO111MODULE: auto
on:
push:
branches:
- main
- releases/v*
- henrymercer/per-language-bundles
pull_request: {}
merge_group:
types:
- checks_requested
schedule:
- cron: '0 5 * * *'
workflow_dispatch:
inputs: {}
workflow_call:
inputs: {}
defaults:
run:
shell: bash
concurrency:
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
group: per-language-bundle-${{github.ref}}
jobs:
per-language-bundle:
strategy:
fail-fast: false
matrix:
include:
- os: ubuntu-latest
version: linked
name: Per-language bundle
if: github.triggering_actor != 'dependabot[bot]'
permissions:
contents: read
security-events: read
timeout-minutes: 45
runs-on: ${{ matrix.os }}
steps:
- name: Check out repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Prepare test
id: prepare-test
uses: ./.github/actions/prepare-test
with:
version: ${{ matrix.version }}
use-all-platform-bundle: 'false'
setup-kotlin: 'true'
- id: init
uses: ./../action/init
with:
languages: actions
tools: https://github.com/dsp-testing/henrymercer-codeql-cli-binaries/releases/download/codeql-bundle-20260825/codeql-bundle-actions-linux64.tar.zst
- name: Check that the bundle contains only the Actions extractor
env:
CODEQL_PATH: ${{ steps.init.outputs.codeql-path }}
run: |
languages="$("$CODEQL_PATH" resolve languages --format=json | jq -r 'keys[]')"
echo "Extractors in the bundle:"
echo "$languages"
if ! echo "$languages" | grep -qx "actions"; then
echo "::error::The Actions bundle does not contain the Actions extractor."
exit 1
fi
# If the bundle still contained extractors for languages we did not ask for, then it would not
# have been trimmed, and this test would be silently exercising the combined bundle instead.
for language in cpp csharp go java python ruby rust swift; do
if echo "$languages" | grep -qx "$language"; then
echo "::error::The Actions bundle also contains the ${language} extractor, so it is not trimmed."
exit 1
fi
done
- name: Check that the bundle was not added to the toolcache
env:
CODEQL_PATH: ${{ steps.init.outputs.codeql-path }}
run: |
# A bundle that is missing most of its extractors must never be left in the toolcache, where
# a later job analyzing a different language could pick it up.
echo "CodeQL is at $CODEQL_PATH"
if [[ "$CODEQL_PATH" == "$RUNNER_TOOL_CACHE"/* ]]; then
echo "::error::The per-language bundle was added to the toolcache at $CODEQL_PATH."
exit 1
fi
# The runner image ships with its own CodeQL in the toolcache, so look for the version we
# downloaded rather than for CodeQL in general.
cached_version="$RUNNER_TOOL_CACHE/CodeQL/0.0.0-20260825"
if [ -d "$cached_version" ]; then
echo "::error::The per-language bundle was added to the toolcache at $cached_version."
exit 1
fi
- uses: ./../action/analyze
with:
upload-database: false
env:
CODEQL_ACTION_TEST_MODE: true

View File

@@ -36,6 +36,9 @@ jobs:
- language: actions
platform: linux64
os: ubuntu-latest
# The Actions QL pack depends on the JavaScript one, which is the only dependency of its
# kind, so the Actions bundle has to carry the JavaScript extractor as well.
expected-extractors: actions javascript
- language: cpp
platform: linux64
os: ubuntu-latest
@@ -93,24 +96,31 @@ jobs:
languages: ${{ matrix.language }}
build-mode: ${{ matrix['build-mode'] }}
tools: https://github.com/dsp-testing/henrymercer-codeql-cli-binaries/releases/download/${{ env.BUNDLE_TAG }}/codeql-bundle-${{ matrix.language }}-${{ matrix.platform }}.tar.zst
- name: Check that the bundle contains only the expected extractor
- name: Check that the bundle contains only the expected extractors
env:
CODEQL_PATH: ${{ steps.init.outputs.codeql-path }}
LANGUAGE: ${{ matrix.language }}
EXPECTED_EXTRACTORS: ${{ matrix['expected-extractors'] || matrix.language }}
run: |
extractors="$("$CODEQL_PATH" resolve languages --format=json | jq -r 'keys[]')"
echo "Extractors in the bundle:"
echo "$extractors"
echo "Expected: $EXPECTED_EXTRACTORS"
if ! echo "$extractors" | grep -qx "$LANGUAGE"; then
echo "::error::The ${LANGUAGE} bundle does not contain the ${LANGUAGE} extractor."
exit 1
fi
for expected in $EXPECTED_EXTRACTORS; do
if ! echo "$extractors" | grep -qx "$expected"; then
echo "::error::The ${LANGUAGE} bundle does not contain the ${expected} extractor."
exit 1
fi
done
# If the bundle still contained extractors for languages we did not ask for, then it would
# not have been trimmed, and this job would be silently validating the combined bundle.
# If the bundle contained extractors beyond those the language needs, then it would not
# have been trimmed, and this job would be silently validating the combined bundle.
for other in actions cpp csharp go java javascript python ruby rust swift; do
if [ "$other" != "$LANGUAGE" ] && echo "$extractors" | grep -qx "$other"; then
if echo "$EXPECTED_EXTRACTORS" | grep -qw "$other"; then
continue
fi
if echo "$extractors" | grep -qx "$other"; then
echo "::error::The ${LANGUAGE} bundle also contains the ${other} extractor, so it is not trimmed."
exit 1
fi

View File

@@ -1,56 +0,0 @@
name: "Per-language bundle"
description: "Tests that a CodeQL bundle containing only a single language can analyze that language"
versions:
- linked # Unused: this test pins `tools` to a specific per-language bundle.
# TODO: Remove once per-language bundles ship in a release, so that this check no longer needs to be
# exercised on a feature branch.
extraPushBranches:
- henrymercer/per-language-bundles
steps:
- id: init
uses: ./../action/init
with:
languages: actions
tools: https://github.com/dsp-testing/henrymercer-codeql-cli-binaries/releases/download/codeql-bundle-20260825/codeql-bundle-actions-linux64.tar.zst
- name: Check that the bundle contains only the Actions extractor
env:
CODEQL_PATH: ${{ steps.init.outputs.codeql-path }}
run: |
languages="$("$CODEQL_PATH" resolve languages --format=json | jq -r 'keys[]')"
echo "Extractors in the bundle:"
echo "$languages"
if ! echo "$languages" | grep -qx "actions"; then
echo "::error::The Actions bundle does not contain the Actions extractor."
exit 1
fi
# If the bundle still contained extractors for languages we did not ask for, then it would not
# have been trimmed, and this test would be silently exercising the combined bundle instead.
for language in cpp csharp go java python ruby rust swift; do
if echo "$languages" | grep -qx "$language"; then
echo "::error::The Actions bundle also contains the ${language} extractor, so it is not trimmed."
exit 1
fi
done
- name: Check that the bundle was not added to the toolcache
env:
CODEQL_PATH: ${{ steps.init.outputs.codeql-path }}
run: |
# A bundle that is missing most of its extractors must never be left in the toolcache, where
# a later job analyzing a different language could pick it up.
echo "CodeQL is at $CODEQL_PATH"
if [[ "$CODEQL_PATH" == "$RUNNER_TOOL_CACHE"/* ]]; then
echo "::error::The per-language bundle was added to the toolcache at $CODEQL_PATH."
exit 1
fi
# The runner image ships with its own CodeQL in the toolcache, so look for the version we
# downloaded rather than for CodeQL in general.
cached_version="$RUNNER_TOOL_CACHE/CodeQL/0.0.0-20260825"
if [ -d "$cached_version" ]; then
echo "::error::The per-language bundle was added to the toolcache at $cached_version."
exit 1
fi
- uses: ./../action/analyze
with:
upload-database: false

View File

@@ -90,13 +90,6 @@ interface Specification extends JobSpecification {
/** If set, this check is part of a named collection that gets its own caller workflow. */
collection?: string;
/**
* Additional branches on which a push should run this check.
*
* Useful for temporarily exercising a check on a feature branch without opening a pull request.
*/
extraPushBranches?: string[];
}
/** Minimal type to represent steps in Actions workflows. */
@@ -770,11 +763,7 @@ function main(): void {
},
on: {
push: {
branches: [
"main",
"releases/v*",
...(checkSpecification.extraPushBranches ?? []),
],
branches: ["main", "releases/v*"],
},
pull_request: {},
merge_group: {