Merge remote-tracking branch 'origin/main' into mbg/config/merge

This commit is contained in:
Michael B. Gale
2026-07-09 23:01:05 +01:00
19 changed files with 347 additions and 283 deletions

151
lib/entry-points.js generated
View File

@@ -141462,6 +141462,61 @@ var toolrunner = __toESM(require_toolrunner());
var github = __toESM(require_github());
var io2 = __toESM(require_io());
// src/environment.ts
function getRequiredEnvVar(env, paramName) {
const value = env[paramName];
if (value === void 0 || value.length === 0) {
throw new Error(`${paramName} environment variable must be set`);
}
return value;
}
function getRequiredEnvParam(paramName) {
return getRequiredEnvVar(process.env, paramName);
}
function getOptionalEnvVarFrom(env, paramName) {
const value = env[paramName];
if (value?.trim().length === 0) {
return void 0;
}
return value;
}
function getOptionalEnvVar(paramName) {
return getOptionalEnvVarFrom(process.env, paramName);
}
var ReadOnlyEnv = class {
constructor(vars) {
this.vars = vars;
}
vars;
/** Tries to get the value for `name` and throws if there isn't one. */
getRequired(name) {
return getRequiredEnvVar(this.vars, name);
}
/** Gets the value for `name`, or `undefined` if it isn't set or empty. */
getOptional(name) {
return getOptionalEnvVarFrom(this.vars, name);
}
/** Gets the entries of the underlying `ProcessEnv`. */
entries() {
return Object.entries(this.vars);
}
};
var Env = class extends ReadOnlyEnv {
changed = false;
/** Sets an environment variable. */
set(name, value) {
this.vars[name] = value;
this.changed = true;
}
/** Gets a value indicating whether `set` was called at least once. */
hasChanged() {
return this.changed;
}
};
function getEnv(env = process.env) {
return new Env(env);
}
// src/util.ts
var fs = __toESM(require("fs"));
var fsPromises = __toESM(require("fs/promises"));
@@ -141750,7 +141805,7 @@ var intCoreTag = defineScalarTag("tag:yaml.org,2002:int", {
..."0123456789"
],
resolve: resolveYamlInteger$2,
identify: (object) => Object.prototype.toString.call(object) === "[object Number]" && object % 1 === 0 && !Object.is(object, -0),
identify: (object) => Number.isInteger(object) && !Object.is(object, -0) && object.toString(10).indexOf("e") < 0,
represent: (object) => object.toString(10)
});
var YAML_INTEGER_IMPLICIT_PATTERN = /* @__PURE__ */ new RegExp("^-?(?:0|[1-9][0-9]*)$");
@@ -141778,7 +141833,7 @@ var intJsonTag = defineScalarTag("tag:yaml.org,2002:int", {
implicit: true,
implicitFirstChars: ["-", ..."0123456789"],
resolve: resolveYamlInteger$1,
identify: (object) => Object.prototype.toString.call(object) === "[object Number]" && object % 1 === 0 && !Object.is(object, -0),
identify: (object) => Number.isInteger(object) && !Object.is(object, -0) && object.toString(10).indexOf("e") < 0,
represent: (object) => object.toString(10)
});
var YAML_INTEGER_PATTERN = /* @__PURE__ */ new RegExp("^(?:[-+]?0b[0-1_]+|[-+]?0[0-7_]+|[-+]?0x[0-9a-fA-F_]+|[-+]?[0-9][0-9_]*(?::[0-5]?[0-9])+|[-+]?(?:0|[1-9][0-9_]*))$");
@@ -141812,7 +141867,7 @@ var intYaml11Tag = defineScalarTag("tag:yaml.org,2002:int", {
..."0123456789"
],
resolve: resolveYamlInteger,
identify: (object) => Object.prototype.toString.call(object) === "[object Number]" && object % 1 === 0 && !Object.is(object, -0),
identify: (object) => Number.isInteger(object) && !Object.is(object, -0) && object.toString(10).indexOf("e") < 0,
represent: (object) => object.toString(10)
});
var YAML_FLOAT_PATTERN$1 = /* @__PURE__ */ new RegExp("^(?:[-+]?[0-9]+(?:\\.[0-9]*)?(?:[eE][-+]?[0-9]+)?|[-+]?\\.[0-9]+(?:[eE][-+]?[0-9]+)?|[-+]?\\.(?:inf|Inf|INF)|\\.(?:nan|NaN|NAN))$");
@@ -141845,7 +141900,7 @@ var floatCoreTag = defineScalarTag("tag:yaml.org,2002:float", {
..."0123456789"
],
resolve: resolveYamlFloat$2,
identify: (object) => Object.prototype.toString.call(object) === "[object Number]" && (object % 1 !== 0 || Object.is(object, -0)),
identify: (object) => typeof object === "number" && (!Number.isInteger(object) || Object.is(object, -0) || object.toString(10).indexOf("e") >= 0),
represent: representYamlFloat$2
});
var YAML_FLOAT_IMPLICIT_PATTERN = /* @__PURE__ */ new RegExp("^-?(?:0|[1-9][0-9]*)(?:\\.[0-9]*)?(?:[eE][-+]?[0-9]+)?$");
@@ -141878,7 +141933,7 @@ var floatJsonTag = defineScalarTag("tag:yaml.org,2002:float", {
implicit: true,
implicitFirstChars: ["-", ..."0123456789"],
resolve: resolveYamlFloat$1,
identify: (object) => Object.prototype.toString.call(object) === "[object Number]" && (object % 1 !== 0 || Object.is(object, -0)),
identify: (object) => typeof object === "number" && (!Number.isInteger(object) || Object.is(object, -0) || object.toString(10).indexOf("e") >= 0),
represent: representYamlFloat$1
});
var YAML_FLOAT_PATTERN = /* @__PURE__ */ new RegExp("^(?:[-+]?(?:(?:[0-9][0-9_]*)?\\.[0-9_]*)(?:[eE][-+][0-9]+)?|[-+]?[0-9][0-9_]*(?::[0-5]?[0-9])+\\.[0-9_]*|[-+]?\\.(?:inf|Inf|INF)|\\.(?:nan|NaN|NAN))$");
@@ -141915,7 +141970,7 @@ var floatYaml11Tag = defineScalarTag("tag:yaml.org,2002:float", {
..."0123456789"
],
resolve: resolveYamlFloat,
identify: (object) => Object.prototype.toString.call(object) === "[object Number]" && (object % 1 !== 0 || Object.is(object, -0)),
identify: (object) => typeof object === "number" && (!Number.isInteger(object) || Object.is(object, -0) || object.toString(10).indexOf("e") >= 0),
represent: representYamlFloat
});
var mergeTag = defineScalarTag("tag:yaml.org,2002:merge", {
@@ -142614,7 +142669,8 @@ var DEFAULT_CONSTRUCTOR_OPTIONS = {
filename: "",
schema: CORE_SCHEMA,
json: false,
maxMergeSeqLength: 20
maxTotalMergeKeys: 1e4,
maxAliases: -1
};
function eventPosition$1(event) {
if ("tagStart" in event && event.tagStart !== NO_RANGE$2) return event.tagStart;
@@ -142702,6 +142758,7 @@ function isMappingTag(tag) {
}
function mergeKeys(state, frame, source, sourceTag) {
for (const sourceKey of sourceTag.keys(source)) {
if (state.maxTotalMergeKeys !== -1 && ++state.totalMergeKeys > state.maxTotalMergeKeys) throwError$1(state, `merge keys exceeded maxTotalMergeKeys (${state.maxTotalMergeKeys})`);
if (frame.tag.has(frame.value, sourceKey)) continue;
const err = frame.tag.addPair(frame.value, sourceKey, sourceTag.get(source, sourceKey));
if (err) throwError$1(state, err);
@@ -142711,14 +142768,8 @@ function mergeKeys(state, frame, source, sourceTag) {
function mergeSource(state, frame, source, sourceTag) {
state.position = frame.keyPosition;
if (isMappingTag(sourceTag)) mergeKeys(state, frame, source, sourceTag);
else if (sourceTag.nodeKind === "sequence" && Array.isArray(source)) {
const seen = /* @__PURE__ */ new Set();
for (const element of source) {
if (seen.has(element)) continue;
seen.add(element);
mergeKeys(state, frame, element, frame.tag);
}
} else throwError$1(state, "cannot merge mappings; the provided source object is unacceptable");
else if (sourceTag.nodeKind === "sequence" && Array.isArray(source)) for (const element of source) mergeKeys(state, frame, element, frame.tag);
else throwError$1(state, "cannot merge mappings; the provided source object is unacceptable");
}
function addMappingValue(state, frame, key, value, tag) {
state.position = frame.keyPosition;
@@ -142739,7 +142790,6 @@ function addValue(state, value, tag) {
} else if (frame.kind === "sequence") {
if (frame.merge) {
if (!isMappingTag(tag)) throwError$1(state, "cannot merge mappings; the provided source object is unacceptable");
if (frame.index >= state.maxMergeSeqLength) throwError$1(state, `merge sequence length exceeded maxMergeSeqLength (${state.maxMergeSeqLength})`);
}
const err = frame.tag.addItem(frame.value, value, frame.index++);
if (err) throwError$1(state, err);
@@ -142776,7 +142826,9 @@ function constructFromEvents(events, options) {
position: 0,
frames: [],
anchors: /* @__PURE__ */ new Map(),
tagHandlers: /* @__PURE__ */ Object.create(null)
tagHandlers: /* @__PURE__ */ Object.create(null),
totalMergeKeys: 0,
aliasCount: 0
};
while (state.eventIndex < state.events.length) {
const event = state.events[state.eventIndex++];
@@ -142784,6 +142836,7 @@ function constructFromEvents(events, options) {
switch (event.type) {
case 1:
state.anchors = /* @__PURE__ */ new Map();
state.aliasCount = 0;
state.tagHandlers = /* @__PURE__ */ Object.create(null);
for (const directive of event.directives) if (directive.kind === "tag") state.tagHandlers[directive.handle] = directive.prefix;
state.frames.push({
@@ -142834,6 +142887,7 @@ function constructFromEvents(events, options) {
break;
}
case 5: {
if (state.maxAliases !== -1 && ++state.aliasCount > state.maxAliases) throwError$1(state, `aliases exceeded maxAliases (${state.maxAliases})`);
const name = state.source.slice(event.anchorStart, event.anchorEnd);
const anchor = state.anchors.get(name);
if (!anchor) throwError$1(state, `unidentified alias "${name}"`);
@@ -144433,7 +144487,7 @@ var semver = __toESM(require_semver2());
// src/api-compatibility.json
var maximumVersion = "3.22";
var minimumVersion = "3.16";
var minimumVersion = "3.17";
// src/json/index.ts
function parseString(data) {
@@ -144776,36 +144830,6 @@ function initializeEnvironment(version) {
core2.exportVariable("CODEQL_ACTION_FEATURE_WILL_UPLOAD" /* FEATURE_WILL_UPLOAD */, "true");
core2.exportVariable("CODEQL_ACTION_VERSION" /* VERSION */, version);
}
function getEnv(env = process.env) {
return {
getRequired: (name) => getRequiredEnvVar(env, name),
getOptional: (name) => getOptionalEnvVarFrom(env, name),
entries: () => Object.entries(env),
set: (name, value) => {
env[name] = value;
}
};
}
function getRequiredEnvVar(env, paramName) {
const value = env[paramName];
if (value === void 0 || value.length === 0) {
throw new Error(`${paramName} environment variable must be set`);
}
return value;
}
function getRequiredEnvParam(paramName) {
return getRequiredEnvVar(process.env, paramName);
}
function getOptionalEnvVarFrom(env, paramName) {
const value = env[paramName];
if (value?.trim().length === 0) {
return void 0;
}
return value;
}
function getOptionalEnvVar(paramName) {
return getOptionalEnvVarFrom(process.env, paramName);
}
var HTTPError = class extends Error {
status;
constructor(message, status) {
@@ -145156,8 +145180,7 @@ var getOptionalInput = function(name) {
return value.length > 0 ? value : void 0;
};
function getTemporaryDirectory(env = getEnv()) {
const value = env.getOptional("CODEQL_ACTION_TEMP" /* TEMP */);
return value !== void 0 && value !== "" ? value : env.getRequired("RUNNER_TEMP" /* RUNNER_TEMP */);
return env.getOptional("CODEQL_ACTION_TEMP" /* TEMP */) ?? env.getRequired("RUNNER_TEMP" /* RUNNER_TEMP */);
}
var PR_DIFF_RANGE_JSON_FILENAME = "pr-diff-range.json";
function getDiffRangesJsonFilePath(env = getEnv()) {
@@ -145305,7 +145328,7 @@ var getFileType = async (filePath) => {
}
};
function isSelfHostedRunner(env = getEnv()) {
return env.getOptional("RUNNER_ENVIRONMENT") === "self-hosted";
return env.getOptional("RUNNER_ENVIRONMENT" /* RUNNER_ENVIRONMENT */) === "self-hosted";
}
function isDynamicWorkflow(env = getEnv()) {
return getWorkflowEventName(env) === "dynamic";
@@ -145401,8 +145424,10 @@ function getPullRequestBranches(env = getEnv()) {
head: pullRequest.head.label
};
}
const codeScanningRef = env.getOptional("CODE_SCANNING_REF");
const codeScanningBaseBranch = env.getOptional("CODE_SCANNING_BASE_BRANCH");
const codeScanningRef = env.getOptional("CODE_SCANNING_REF" /* CODE_SCANNING_REF */);
const codeScanningBaseBranch = env.getOptional(
"CODE_SCANNING_BASE_BRANCH" /* CODE_SCANNING_BASE_BRANCH */
);
if (codeScanningRef && codeScanningBaseBranch) {
return {
base: codeScanningBaseBranch,
@@ -145611,15 +145636,15 @@ function createApiClientWithDetails(apiDetails, { allowExternal = false } = {})
})
);
}
function getApiDetails() {
function getApiDetails(env = getEnv()) {
return {
auth: getRequiredInput("token"),
url: getRequiredEnvParam("GITHUB_SERVER_URL" /* GITHUB_SERVER_URL */),
apiURL: getRequiredEnvParam("GITHUB_API_URL" /* GITHUB_API_URL */)
url: env.getRequired("GITHUB_SERVER_URL" /* GITHUB_SERVER_URL */),
apiURL: env.getRequired("GITHUB_API_URL" /* GITHUB_API_URL */)
};
}
function getApiClient() {
return createApiClientWithDetails(getApiDetails());
function getApiClient(env = getEnv()) {
return createApiClientWithDetails(getApiDetails(env));
}
function getApiClientWithExternalAuth(apiDetails) {
return createApiClientWithDetails(apiDetails, { allowExternal: true });
@@ -151085,9 +151110,9 @@ async function getCombinedTracerConfig(codeql, config) {
// src/codeql.ts
var cachedCodeQL = void 0;
var CODEQL_MINIMUM_VERSION = "2.19.4";
var CODEQL_NEXT_MINIMUM_VERSION = "2.19.4";
var GHES_VERSION_MOST_RECENTLY_DEPRECATED = "3.15";
var GHES_MOST_RECENT_DEPRECATION_DATE = "2026-04-09";
var CODEQL_NEXT_MINIMUM_VERSION = "2.20.7";
var GHES_VERSION_MOST_RECENTLY_DEPRECATED = "3.16";
var GHES_MOST_RECENT_DEPRECATION_DATE = "2026-07-01";
var EXTRACTION_DEBUG_MODE_VERBOSITY = "progress++";
async function setupCodeQL(toolsInput, apiDetails, tempDir, variant, defaultCliVersion, rawLanguages, useOverlayAwareDefaultCliVersion, features, logger, checkVersion) {
try {
@@ -151720,7 +151745,7 @@ async function setupCppAutobuild(codeql, logger) {
logger
);
if (await features.getValue("cpp_dependency_installation_enabled" /* CppDependencyInstallation */, codeql)) {
if (process.env["RUNNER_ENVIRONMENT"] === "self-hosted" && process.env[envVar] !== "true") {
if (process.env["RUNNER_ENVIRONMENT" /* RUNNER_ENVIRONMENT */] === "self-hosted" && process.env[envVar] !== "true") {
logger.info(
`Disabling ${featureName} as we are on a self-hosted runner.${getWorkflowEventName() !== "dynamic" ? ` To override this, set the ${envVar} environment variable to 'true' in your workflow. See ${"https://docs.github.com/en/actions/learn-github-actions/variables#defining-environment-variables-for-a-single-workflow" /* DEFINE_ENV_VARIABLES */} for more information.` : ""}`
);
@@ -162753,7 +162778,7 @@ tmp/lib/tmp.js:
*)
js-yaml/dist/js-yaml.mjs:
(*! js-yaml 5.1.0 https://github.com/nodeca/js-yaml @license MIT *)
(*! js-yaml 5.2.0 https://github.com/nodeca/js-yaml @license MIT *)
long/index.js:
(**