mirror of
https://github.com/github/codeql-action.git
synced 2026-10-03 09:14:58 +00:00
Expect the Actions bundle to contain the JavaScript extractor
The Actions QL pack depends on the JavaScript one, which is the only dependency of its kind, so the Actions bundle carries the JavaScript extractor as well as its own. Let each language declare the extractors its bundle is expected to contain, so that the check still fails if a bundle contains anything beyond what its language needs. Fold the generated Actions-only check into this workflow, which now covers every language, and with it the ability for a generated check to run on additional branches, which nothing needs any more. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: d4c7b873-8278-4a36-b67c-6cc5ea3b2316
This commit is contained in:
105
.github/workflows/__per-language-bundle.yml
generated
vendored
105
.github/workflows/__per-language-bundle.yml
generated
vendored
@@ -1,105 +0,0 @@
|
||||
# Warning: This file is generated automatically, and should not be modified.
|
||||
# Instead, please modify the template in the pr-checks directory and run:
|
||||
# pr-checks/sync.sh
|
||||
# to regenerate this file.
|
||||
|
||||
name: PR Check - Per-language bundle
|
||||
env:
|
||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
GO111MODULE: auto
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
- henrymercer/per-language-bundles
|
||||
pull_request: {}
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
schedule:
|
||||
- cron: '0 5 * * *'
|
||||
workflow_dispatch:
|
||||
inputs: {}
|
||||
workflow_call:
|
||||
inputs: {}
|
||||
defaults:
|
||||
run:
|
||||
shell: bash
|
||||
concurrency:
|
||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||
group: per-language-bundle-${{github.ref}}
|
||||
jobs:
|
||||
per-language-bundle:
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
include:
|
||||
- os: ubuntu-latest
|
||||
version: linked
|
||||
name: Per-language bundle
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
timeout-minutes: 45
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
with:
|
||||
version: ${{ matrix.version }}
|
||||
use-all-platform-bundle: 'false'
|
||||
setup-kotlin: 'true'
|
||||
- id: init
|
||||
uses: ./../action/init
|
||||
with:
|
||||
languages: actions
|
||||
tools: https://github.com/dsp-testing/henrymercer-codeql-cli-binaries/releases/download/codeql-bundle-20260825/codeql-bundle-actions-linux64.tar.zst
|
||||
- name: Check that the bundle contains only the Actions extractor
|
||||
env:
|
||||
CODEQL_PATH: ${{ steps.init.outputs.codeql-path }}
|
||||
run: |
|
||||
languages="$("$CODEQL_PATH" resolve languages --format=json | jq -r 'keys[]')"
|
||||
echo "Extractors in the bundle:"
|
||||
echo "$languages"
|
||||
|
||||
if ! echo "$languages" | grep -qx "actions"; then
|
||||
echo "::error::The Actions bundle does not contain the Actions extractor."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# If the bundle still contained extractors for languages we did not ask for, then it would not
|
||||
# have been trimmed, and this test would be silently exercising the combined bundle instead.
|
||||
for language in cpp csharp go java python ruby rust swift; do
|
||||
if echo "$languages" | grep -qx "$language"; then
|
||||
echo "::error::The Actions bundle also contains the ${language} extractor, so it is not trimmed."
|
||||
exit 1
|
||||
fi
|
||||
done
|
||||
- name: Check that the bundle was not added to the toolcache
|
||||
env:
|
||||
CODEQL_PATH: ${{ steps.init.outputs.codeql-path }}
|
||||
run: |
|
||||
# A bundle that is missing most of its extractors must never be left in the toolcache, where
|
||||
# a later job analyzing a different language could pick it up.
|
||||
echo "CodeQL is at $CODEQL_PATH"
|
||||
if [[ "$CODEQL_PATH" == "$RUNNER_TOOL_CACHE"/* ]]; then
|
||||
echo "::error::The per-language bundle was added to the toolcache at $CODEQL_PATH."
|
||||
exit 1
|
||||
fi
|
||||
# The runner image ships with its own CodeQL in the toolcache, so look for the version we
|
||||
# downloaded rather than for CodeQL in general.
|
||||
cached_version="$RUNNER_TOOL_CACHE/CodeQL/0.0.0-20260825"
|
||||
if [ -d "$cached_version" ]; then
|
||||
echo "::error::The per-language bundle was added to the toolcache at $cached_version."
|
||||
exit 1
|
||||
fi
|
||||
- uses: ./../action/analyze
|
||||
with:
|
||||
upload-database: false
|
||||
env:
|
||||
CODEQL_ACTION_TEST_MODE: true
|
||||
@@ -36,6 +36,9 @@ jobs:
|
||||
- language: actions
|
||||
platform: linux64
|
||||
os: ubuntu-latest
|
||||
# The Actions QL pack depends on the JavaScript one, which is the only dependency of its
|
||||
# kind, so the Actions bundle has to carry the JavaScript extractor as well.
|
||||
expected-extractors: actions javascript
|
||||
- language: cpp
|
||||
platform: linux64
|
||||
os: ubuntu-latest
|
||||
@@ -93,24 +96,31 @@ jobs:
|
||||
languages: ${{ matrix.language }}
|
||||
build-mode: ${{ matrix['build-mode'] }}
|
||||
tools: https://github.com/dsp-testing/henrymercer-codeql-cli-binaries/releases/download/${{ env.BUNDLE_TAG }}/codeql-bundle-${{ matrix.language }}-${{ matrix.platform }}.tar.zst
|
||||
- name: Check that the bundle contains only the expected extractor
|
||||
- name: Check that the bundle contains only the expected extractors
|
||||
env:
|
||||
CODEQL_PATH: ${{ steps.init.outputs.codeql-path }}
|
||||
LANGUAGE: ${{ matrix.language }}
|
||||
EXPECTED_EXTRACTORS: ${{ matrix['expected-extractors'] || matrix.language }}
|
||||
run: |
|
||||
extractors="$("$CODEQL_PATH" resolve languages --format=json | jq -r 'keys[]')"
|
||||
echo "Extractors in the bundle:"
|
||||
echo "$extractors"
|
||||
echo "Expected: $EXPECTED_EXTRACTORS"
|
||||
|
||||
if ! echo "$extractors" | grep -qx "$LANGUAGE"; then
|
||||
echo "::error::The ${LANGUAGE} bundle does not contain the ${LANGUAGE} extractor."
|
||||
exit 1
|
||||
fi
|
||||
for expected in $EXPECTED_EXTRACTORS; do
|
||||
if ! echo "$extractors" | grep -qx "$expected"; then
|
||||
echo "::error::The ${LANGUAGE} bundle does not contain the ${expected} extractor."
|
||||
exit 1
|
||||
fi
|
||||
done
|
||||
|
||||
# If the bundle still contained extractors for languages we did not ask for, then it would
|
||||
# not have been trimmed, and this job would be silently validating the combined bundle.
|
||||
# If the bundle contained extractors beyond those the language needs, then it would not
|
||||
# have been trimmed, and this job would be silently validating the combined bundle.
|
||||
for other in actions cpp csharp go java javascript python ruby rust swift; do
|
||||
if [ "$other" != "$LANGUAGE" ] && echo "$extractors" | grep -qx "$other"; then
|
||||
if echo "$EXPECTED_EXTRACTORS" | grep -qw "$other"; then
|
||||
continue
|
||||
fi
|
||||
if echo "$extractors" | grep -qx "$other"; then
|
||||
echo "::error::The ${LANGUAGE} bundle also contains the ${other} extractor, so it is not trimmed."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
@@ -1,56 +0,0 @@
|
||||
name: "Per-language bundle"
|
||||
description: "Tests that a CodeQL bundle containing only a single language can analyze that language"
|
||||
versions:
|
||||
- linked # Unused: this test pins `tools` to a specific per-language bundle.
|
||||
# TODO: Remove once per-language bundles ship in a release, so that this check no longer needs to be
|
||||
# exercised on a feature branch.
|
||||
extraPushBranches:
|
||||
- henrymercer/per-language-bundles
|
||||
steps:
|
||||
- id: init
|
||||
uses: ./../action/init
|
||||
with:
|
||||
languages: actions
|
||||
tools: https://github.com/dsp-testing/henrymercer-codeql-cli-binaries/releases/download/codeql-bundle-20260825/codeql-bundle-actions-linux64.tar.zst
|
||||
- name: Check that the bundle contains only the Actions extractor
|
||||
env:
|
||||
CODEQL_PATH: ${{ steps.init.outputs.codeql-path }}
|
||||
run: |
|
||||
languages="$("$CODEQL_PATH" resolve languages --format=json | jq -r 'keys[]')"
|
||||
echo "Extractors in the bundle:"
|
||||
echo "$languages"
|
||||
|
||||
if ! echo "$languages" | grep -qx "actions"; then
|
||||
echo "::error::The Actions bundle does not contain the Actions extractor."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# If the bundle still contained extractors for languages we did not ask for, then it would not
|
||||
# have been trimmed, and this test would be silently exercising the combined bundle instead.
|
||||
for language in cpp csharp go java python ruby rust swift; do
|
||||
if echo "$languages" | grep -qx "$language"; then
|
||||
echo "::error::The Actions bundle also contains the ${language} extractor, so it is not trimmed."
|
||||
exit 1
|
||||
fi
|
||||
done
|
||||
- name: Check that the bundle was not added to the toolcache
|
||||
env:
|
||||
CODEQL_PATH: ${{ steps.init.outputs.codeql-path }}
|
||||
run: |
|
||||
# A bundle that is missing most of its extractors must never be left in the toolcache, where
|
||||
# a later job analyzing a different language could pick it up.
|
||||
echo "CodeQL is at $CODEQL_PATH"
|
||||
if [[ "$CODEQL_PATH" == "$RUNNER_TOOL_CACHE"/* ]]; then
|
||||
echo "::error::The per-language bundle was added to the toolcache at $CODEQL_PATH."
|
||||
exit 1
|
||||
fi
|
||||
# The runner image ships with its own CodeQL in the toolcache, so look for the version we
|
||||
# downloaded rather than for CodeQL in general.
|
||||
cached_version="$RUNNER_TOOL_CACHE/CodeQL/0.0.0-20260825"
|
||||
if [ -d "$cached_version" ]; then
|
||||
echo "::error::The per-language bundle was added to the toolcache at $cached_version."
|
||||
exit 1
|
||||
fi
|
||||
- uses: ./../action/analyze
|
||||
with:
|
||||
upload-database: false
|
||||
@@ -90,13 +90,6 @@ interface Specification extends JobSpecification {
|
||||
|
||||
/** If set, this check is part of a named collection that gets its own caller workflow. */
|
||||
collection?: string;
|
||||
|
||||
/**
|
||||
* Additional branches on which a push should run this check.
|
||||
*
|
||||
* Useful for temporarily exercising a check on a feature branch without opening a pull request.
|
||||
*/
|
||||
extraPushBranches?: string[];
|
||||
}
|
||||
|
||||
/** Minimal type to represent steps in Actions workflows. */
|
||||
@@ -770,11 +763,7 @@ function main(): void {
|
||||
},
|
||||
on: {
|
||||
push: {
|
||||
branches: [
|
||||
"main",
|
||||
"releases/v*",
|
||||
...(checkSpecification.extraPushBranches ?? []),
|
||||
],
|
||||
branches: ["main", "releases/v*"],
|
||||
},
|
||||
pull_request: {},
|
||||
merge_group: {
|
||||
|
||||
Reference in New Issue
Block a user