Point to the Default Setup config schema from the per-language bundle check

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
Henry Mercer
2026-10-02 14:30:02 +01:00
parent 113b18e688
commit f6a7f00613
2 changed files with 10 additions and 5 deletions

View File

@@ -86,7 +86,11 @@ export interface UserConfig {
"default-setup"?: DefaultSetupConfig;
}
/** A subset of the `UserConfig` schema that is used by Default Setup. */
/**
* A subset of the `UserConfig` schema that is used by Default Setup. None of these properties may
* add queries, since a per-language CodeQL bundle can be used with a `config` input that only sets
* them.
*/
const DEFAULT_SETUP_CONFIG_SCHEMA = {
"threat-models": json.optional(json.array(json.string)),
"default-setup": json.optional<DefaultSetupConfig>(

View File

@@ -58,8 +58,8 @@ export interface QueryConfigInputs {
* query packs are downloaded together with their dependencies.
*
* Any configuration file is assumed to configure such queries, since reading it may need file or API
* access. The `config` input is only assumed to if it sets anything other than valid threat models
* and model packs, which are the properties that default setup uses.
* access. So is the `config` input, unless it only sets the properties that default setup sets (see
* `matchesDefaultSetupConfigSchema`).
*
* @throws A `ConfigurationError` if the `queries` input or the `github-codeql-extra-queries`
* repository property is a '+' with no queries after it, unless an input that's checked earlier
@@ -75,8 +75,9 @@ export function getOtherLanguagePacksReason(
);
}
// The `config` input can configure queries in the same way as a configuration file. Default
// setup only uses it for threat models and model packs, neither of which adds queries.
// The `config` input can configure queries in the same way as a configuration file. The
// properties that default setup sets, listed in `DEFAULT_SETUP_CONFIG_SCHEMA` in
// `config/db-config.ts`, don't add queries.
if (
inputs.configInput !== undefined &&
!matchesDefaultSetupConfigSchema(inputs.configInput)