mirror of
https://github.com/github/codeql-action.git
synced 2026-10-03 17:41:28 +00:00
Compare commits
430 Commits
codeql-bun
...
mbg/skip-f
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
f31b0a8ffd | ||
|
|
065b8dea87 | ||
|
|
546c45705d | ||
|
|
5584cec589 | ||
|
|
d9826583a3 | ||
|
|
9f28912d94 | ||
|
|
d9ef050686 | ||
|
|
a72798355c | ||
|
|
d40707c73d | ||
|
|
e855781840 | ||
|
|
23a5edca55 | ||
|
|
6f5a84b5b5 | ||
|
|
b96794f015 | ||
|
|
02d5093871 | ||
|
|
7e08580a93 | ||
|
|
bfcc52b4f5 | ||
|
|
8c251e757c | ||
|
|
0b7ca400df | ||
|
|
40484b3395 | ||
|
|
977e6ceaea | ||
|
|
40a6b38247 | ||
|
|
deece8f852 | ||
|
|
034db721dd | ||
|
|
313a0b9922 | ||
|
|
31da345c07 | ||
|
|
46dfb14111 | ||
|
|
e06b60f75f | ||
|
|
a48f2d3077 | ||
|
|
657964c39f | ||
|
|
d2fe508a6d | ||
|
|
16da74769e | ||
|
|
e13c3dc834 | ||
|
|
1331773b9a | ||
|
|
2681b03bd6 | ||
|
|
a7a90f3ffb | ||
|
|
4a0b22ec25 | ||
|
|
762a5ed7f7 | ||
|
|
ceb85f25b5 | ||
|
|
9fddc16f0d | ||
|
|
36cbf13b5e | ||
|
|
38dd4a088a | ||
|
|
2f3c1c964a | ||
|
|
5914b031b1 | ||
|
|
102499482f | ||
|
|
9401a335a3 | ||
|
|
3ee8a9398b | ||
|
|
25da1b1495 | ||
|
|
9509fd0822 | ||
|
|
20ec60c2d9 | ||
|
|
4cccb3aa86 | ||
|
|
b724a86493 | ||
|
|
2a03009e3f | ||
|
|
da21771e2e | ||
|
|
bb36f8049c | ||
|
|
276e2ce25d | ||
|
|
ccd5275aa4 | ||
|
|
a0c73122a6 | ||
|
|
50e244824e | ||
|
|
025009006c | ||
|
|
6f530319d8 | ||
|
|
1bcdd0c019 | ||
|
|
f049ecb9ce | ||
|
|
25694c08ea | ||
|
|
0963041ab4 | ||
|
|
1a8ddd7325 | ||
|
|
abc579a511 | ||
|
|
4d1d53ec73 | ||
|
|
6d4d5dfcd6 | ||
|
|
7acc225a21 | ||
|
|
76ba03be44 | ||
|
|
6441b26a49 | ||
|
|
cacb7b37ed | ||
|
|
e2cd31e32e | ||
|
|
be555cf0a3 | ||
|
|
0447ab23b5 | ||
|
|
50ec5a5c18 | ||
|
|
5aea817801 | ||
|
|
580da893f6 | ||
|
|
426c10420b | ||
|
|
dc5bc53050 | ||
|
|
d75af13705 | ||
|
|
0006c77502 | ||
|
|
ec1bd1999f | ||
|
|
4d40c93072 | ||
|
|
3e93618b99 | ||
|
|
42c2ea9ef7 | ||
|
|
f37565646f | ||
|
|
0f2e2bde5c | ||
|
|
cdf488f595 | ||
|
|
7243f38558 | ||
|
|
920ba7cd15 | ||
|
|
ecfa6e1681 | ||
|
|
adcdf4a70d | ||
|
|
b5383aad77 | ||
|
|
9d89e2d1d6 | ||
|
|
bee82de8ba | ||
|
|
c05e445696 | ||
|
|
a952c0706c | ||
|
|
97b7459e09 | ||
|
|
486fec2a3e | ||
|
|
134624c67b | ||
|
|
ff43db8f98 | ||
|
|
4605e03a74 | ||
|
|
099c869cad | ||
|
|
db488ddef3 | ||
|
|
1845f5ba8b | ||
|
|
79a73408b4 | ||
|
|
f9d9f07d37 | ||
|
|
9ee088e136 | ||
|
|
1aef003397 | ||
|
|
508b83bc41 | ||
|
|
fcd8d74cda | ||
|
|
b5d34388b7 | ||
|
|
1f46830a1f | ||
|
|
b60777a215 | ||
|
|
f3deecb42d | ||
|
|
c8ba2d2a05 | ||
|
|
d7d901a925 | ||
|
|
cb9d39fcc1 | ||
|
|
d97b3428e8 | ||
|
|
47fa622223 | ||
|
|
45693cc688 | ||
|
|
93d793c5fe | ||
|
|
c2fd8f54d1 | ||
|
|
c56f48e9bd | ||
|
|
aa0eadc572 | ||
|
|
43250d671a | ||
|
|
5008effa71 | ||
|
|
053d41e61e | ||
|
|
1158e1c92a | ||
|
|
ff2f1c621b | ||
|
|
2d49edbac6 | ||
|
|
951a133f96 | ||
|
|
9875827ada | ||
|
|
be7a3dbb81 | ||
|
|
9310334b11 | ||
|
|
6dc633238e | ||
|
|
b4d8a54218 | ||
|
|
ab5db2519c | ||
|
|
6c0d9018d4 | ||
|
|
bf96b0df93 | ||
|
|
337136ab8a | ||
|
|
a9baab8dee | ||
|
|
33d70867d5 | ||
|
|
38055a3c3c | ||
|
|
1f87aed5e6 | ||
|
|
dc1b98ad1c | ||
|
|
6f0220ee37 | ||
|
|
ca1c97228c | ||
|
|
0e8a5d99f8 | ||
|
|
54a084632e | ||
|
|
40f80a8df0 | ||
|
|
b222c3aaea | ||
|
|
11569df0a1 | ||
|
|
0a99875ae5 | ||
|
|
246018e041 | ||
|
|
1332611f51 | ||
|
|
4dc327a942 | ||
|
|
bb19330c5e | ||
|
|
0e85c0e99c | ||
|
|
bfcd769ba1 | ||
|
|
c16c0f3f28 | ||
|
|
208a88adc7 | ||
|
|
f47bb7b9aa | ||
|
|
c205ff6f09 | ||
|
|
b672c70acd | ||
|
|
7131139037 | ||
|
|
b5225f21c5 | ||
|
|
acb38565c9 | ||
|
|
9183a7b6e1 | ||
|
|
b4c390c362 | ||
|
|
5f8c44ba62 | ||
|
|
794f5bc385 | ||
|
|
54109818e0 | ||
|
|
99caaa8b90 | ||
|
|
6117bb503a | ||
|
|
af767ec1f6 | ||
|
|
7d9249f5a5 | ||
|
|
8ebf1091b0 | ||
|
|
bdf39710a2 | ||
|
|
74cfae9be6 | ||
|
|
47a0a833bb | ||
|
|
43ae5e70b0 | ||
|
|
6a90bf1f54 | ||
|
|
c5995f544d | ||
|
|
76c44396d3 | ||
|
|
fad141fa6c | ||
|
|
7d82f1132f | ||
|
|
37bdbde050 | ||
|
|
5595ccaf91 | ||
|
|
4c96123771 | ||
|
|
ec9c75796a | ||
|
|
45c8742e17 | ||
|
|
6a9359a1bd | ||
|
|
065cdc0394 | ||
|
|
f99dd5aeee | ||
|
|
1804b211a3 | ||
|
|
3020a2f462 | ||
|
|
93c3a5a40b | ||
|
|
d1ba80a13d | ||
|
|
e74600b0d9 | ||
|
|
266c7bdbd2 | ||
|
|
daa7fe6fba | ||
|
|
1cd4d01d58 | ||
|
|
d2bfc30bc3 | ||
|
|
68028fcb16 | ||
|
|
c29563eeaa | ||
|
|
155e522997 | ||
|
|
2d3b351ea6 | ||
|
|
5d3eb98e4a | ||
|
|
c5f739bd64 | ||
|
|
2e53f1cea2 | ||
|
|
d0ee43ac62 | ||
|
|
06f1d4ffed | ||
|
|
82f035a501 | ||
|
|
f205ea1c33 | ||
|
|
60a57910be | ||
|
|
3502f79575 | ||
|
|
8f0a4f23c4 | ||
|
|
780c00da3f | ||
|
|
f02afd42b0 | ||
|
|
d57c3ffcba | ||
|
|
e40d079dd9 | ||
|
|
8e6fdffc32 | ||
|
|
ba46ff760e | ||
|
|
b411bbcd4a | ||
|
|
9130ce0f73 | ||
|
|
0cebd1d28d | ||
|
|
d2f5cbbe91 | ||
|
|
c62d824686 | ||
|
|
da0c190101 | ||
|
|
36737508ec | ||
|
|
30c33c9286 | ||
|
|
3ca82bb259 | ||
|
|
42a3b94790 | ||
|
|
13d4882649 | ||
|
|
e55a57b808 | ||
|
|
51d51e8121 | ||
|
|
e893985e8b | ||
|
|
eb692f8b49 | ||
|
|
aac07d2a41 | ||
|
|
de57c4a441 | ||
|
|
2e251072b0 | ||
|
|
94a12eb6f6 | ||
|
|
e28cbacfa1 | ||
|
|
60834a0cd9 | ||
|
|
e9831f72a2 | ||
|
|
766928d055 | ||
|
|
049af32c59 | ||
|
|
c7ae51bb2d | ||
|
|
1f9caf0118 | ||
|
|
18420e3271 | ||
|
|
7e8d8970f0 | ||
|
|
2d4c474c2c | ||
|
|
98c05a17d3 | ||
|
|
8289a49271 | ||
|
|
2a8731cc06 | ||
|
|
3434fbbc53 | ||
|
|
3013ac07bd | ||
|
|
74b15aa2c6 | ||
|
|
f00f809405 | ||
|
|
4c0a1f0aac | ||
|
|
0953dc00da | ||
|
|
cbad145443 | ||
|
|
ab44eb939d | ||
|
|
961b583f9a | ||
|
|
d71461774b | ||
|
|
027ac05d3b | ||
|
|
66a6f42f0a | ||
|
|
c5d621238d | ||
|
|
adba0868a4 | ||
|
|
916098aa8d | ||
|
|
093dce6cc2 | ||
|
|
57eb44123f | ||
|
|
5901394530 | ||
|
|
b69467ce8b | ||
|
|
85d157095f | ||
|
|
2d14f71964 | ||
|
|
d4bfde754d | ||
|
|
6de0a56ae9 | ||
|
|
1564bfa325 | ||
|
|
f170b3a321 | ||
|
|
519b2703bc | ||
|
|
b060f9d53c | ||
|
|
2e6447195b | ||
|
|
ecbe7c245e | ||
|
|
5ba55503d8 | ||
|
|
087006f117 | ||
|
|
372f165402 | ||
|
|
4671ecc1f6 | ||
|
|
1eb720cacc | ||
|
|
d146d63292 | ||
|
|
11b8f752cf | ||
|
|
5c0fb499d4 | ||
|
|
6cce0e741f | ||
|
|
05f56be836 | ||
|
|
8a0be82efa | ||
|
|
f6ed33c7e4 | ||
|
|
96bc4c7e0f | ||
|
|
1b0d2714d6 | ||
|
|
f9442c40cc | ||
|
|
be24c11a39 | ||
|
|
60339edd56 | ||
|
|
32ed58dc59 | ||
|
|
49f2e37310 | ||
|
|
3479f3fca1 | ||
|
|
f58d69685d | ||
|
|
1f57eb0ff5 | ||
|
|
009715ddbf | ||
|
|
90ea144182 | ||
|
|
f342ca9247 | ||
|
|
a2bfb64790 | ||
|
|
84ae30d972 | ||
|
|
909828cd53 | ||
|
|
0c76f63b6d | ||
|
|
e8e914f04e | ||
|
|
15e2f310e1 | ||
|
|
7248c38b8f | ||
|
|
e4fba868fa | ||
|
|
fb50ab5d62 | ||
|
|
72f6a9da0d | ||
|
|
3b5ee58597 | ||
|
|
bfb6be4b5e | ||
|
|
526ab84f98 | ||
|
|
d6217b9b8c | ||
|
|
e0647621c2 | ||
|
|
e0faed8391 | ||
|
|
73aad0eaa9 | ||
|
|
385bcdc5af | ||
|
|
de0229cea1 | ||
|
|
115e8cbbe9 | ||
|
|
dbdf0b0c7d | ||
|
|
830c23121c | ||
|
|
69fd9e97ba | ||
|
|
b85568788a | ||
|
|
3c20a74df3 | ||
|
|
1040e2a159 | ||
|
|
14e8bf9e67 | ||
|
|
3f208c9347 | ||
|
|
d57cc916e8 | ||
|
|
dd35309c87 | ||
|
|
da21ad6a71 | ||
|
|
cf463419fd | ||
|
|
7db34ae6f4 | ||
|
|
8125f87336 | ||
|
|
7c4a258544 | ||
|
|
0297913805 | ||
|
|
1226301537 | ||
|
|
7188fc3636 | ||
|
|
c8b5f69be6 | ||
|
|
9e7c070092 | ||
|
|
4292bd7215 | ||
|
|
7b19180f8d | ||
|
|
3492b7e9ab | ||
|
|
3654baa924 | ||
|
|
2d682ac05f | ||
|
|
23f6a50753 | ||
|
|
1ee3c75d19 | ||
|
|
e053684dc5 | ||
|
|
6803c5671d | ||
|
|
8507f884db | ||
|
|
c31b06d582 | ||
|
|
cc5c777dcd | ||
|
|
c224750821 | ||
|
|
db76a66b98 | ||
|
|
c263ed7d83 | ||
|
|
60e79ccb20 | ||
|
|
b82a08934e | ||
|
|
247ce88c8f | ||
|
|
decb87044a | ||
|
|
abce6483ea | ||
|
|
23339952d6 | ||
|
|
57ca205769 | ||
|
|
001d4ae610 | ||
|
|
6d3bde3729 | ||
|
|
9832a9df15 | ||
|
|
c73d965e34 | ||
|
|
9c0c11a49e | ||
|
|
423e3416b1 | ||
|
|
41c7af7cf0 | ||
|
|
1a0eca3555 | ||
|
|
d705aa30b5 | ||
|
|
a1c676d2f6 | ||
|
|
47e9c29998 | ||
|
|
b946565527 | ||
|
|
205b37b035 | ||
|
|
6d70593fb7 | ||
|
|
80599cc5d9 | ||
|
|
ae48798f3b | ||
|
|
a464bf19e9 | ||
|
|
9b314f4394 | ||
|
|
d694648fd8 | ||
|
|
583bf3e8c5 | ||
|
|
f9a9f4862b | ||
|
|
d4b3323463 | ||
|
|
fd0ae66c1e | ||
|
|
e2472fc5f9 | ||
|
|
4b861b89fc | ||
|
|
4f688dedd0 | ||
|
|
28a0813a12 | ||
|
|
2c45c8158b | ||
|
|
5c030f4a48 | ||
|
|
78d71fb252 | ||
|
|
5e212030b8 | ||
|
|
639fc5d7ea | ||
|
|
c8ed70e459 | ||
|
|
212aa33f48 | ||
|
|
460cc0c970 | ||
|
|
557921759b | ||
|
|
c3da0a9ad3 | ||
|
|
4ca9f5301b | ||
|
|
440cebc19d | ||
|
|
1b146d1b6a | ||
|
|
d0b11cae68 | ||
|
|
a10d7a7891 | ||
|
|
14952376dc | ||
|
|
85052938f8 | ||
|
|
4c2bf01170 | ||
|
|
2f9048cfbd | ||
|
|
2dbfdcaa83 | ||
|
|
1542951d09 | ||
|
|
4fb6147969 | ||
|
|
50b3687dd7 | ||
|
|
b6d92e33f7 | ||
|
|
b0eaa56a8f | ||
|
|
e387ec1de1 | ||
|
|
a29dee455c | ||
|
|
5172487de5 | ||
|
|
8763bac625 | ||
|
|
dab0ab7cb7 |
1
.github/actions/release-branches/action.yml
vendored
1
.github/actions/release-branches/action.yml
vendored
@@ -22,7 +22,6 @@ runs:
|
||||
MAJOR_VERSION: ${{ inputs.major_version }}
|
||||
LATEST_TAG: ${{ inputs.latest_tag }}
|
||||
run: |
|
||||
npm ci
|
||||
npx tsx ./pr-checks/release-branches.ts \
|
||||
--major-version "$MAJOR_VERSION" \
|
||||
--latest-tag "$LATEST_TAG"
|
||||
|
||||
11
.github/actions/release-initialise/action.yml
vendored
11
.github/actions/release-initialise/action.yml
vendored
@@ -21,16 +21,9 @@ runs:
|
||||
node-version: 24
|
||||
cache: 'npm'
|
||||
|
||||
- name: Set up Python
|
||||
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
|
||||
with:
|
||||
python-version: '3.12'
|
||||
|
||||
- name: Install dependencies
|
||||
run: |
|
||||
python -m pip install --upgrade pip
|
||||
pip install PyGithub==2.3.0 requests
|
||||
- name: Install JavaScript dependencies
|
||||
shell: bash
|
||||
run: npm ci
|
||||
|
||||
- name: Update git config
|
||||
run: |
|
||||
|
||||
16
.github/instructions/release-merge.instructions.md
vendored
Normal file
16
.github/instructions/release-merge.instructions.md
vendored
Normal file
@@ -0,0 +1,16 @@
|
||||
---
|
||||
applyTo: "CHANGELOG.md,src/defaults.json,lib/defaults.json,src/api-compatibility.json"
|
||||
---
|
||||
|
||||
# Merging release, mergeback, and backport PRs
|
||||
|
||||
The release process creates a cascade of PRs (`main` → `releases/vN`, then
|
||||
`releases/vN` → `main` mergeback, then `releases/vN` → `releases/v(N-1)`
|
||||
backport). These PRs reliably touch `CHANGELOG.md`, `src/defaults.json` /
|
||||
`lib/defaults.json` (bundle/CLI version bump), and `src/api-compatibility.json`.
|
||||
|
||||
Such PRs **must be merged with a merge commit**. Never squash or rebase, as
|
||||
that breaks the branch linkage the release automation relies on.
|
||||
|
||||
When arming auto-merge on these PRs, use `--merge` (e.g. `gh pr merge --merge`),
|
||||
not `--squash` or `--rebase`.
|
||||
474
.github/update-release-branch.py
vendored
474
.github/update-release-branch.py
vendored
@@ -1,474 +0,0 @@
|
||||
import argparse
|
||||
import datetime
|
||||
import fileinput
|
||||
import re
|
||||
from github import Github
|
||||
import json
|
||||
import os
|
||||
import subprocess
|
||||
|
||||
EMPTY_CHANGELOG = """# CodeQL Action Changelog
|
||||
|
||||
## [UNRELEASED]
|
||||
|
||||
No user facing changes.
|
||||
|
||||
"""
|
||||
|
||||
# NB: This exact commit message is used to find commits for reverting during backports.
|
||||
# Changing it requires a transition period where both old and new versions are supported.
|
||||
BACKPORT_COMMIT_MESSAGE = 'Update version and changelog for v'
|
||||
|
||||
# Commit message used for rebuild commits, both those produced by this script and those produced
|
||||
# by the `Rebuild Action` workflow (`.github/workflows/rebuild.yml`).
|
||||
REBUILD_COMMIT_MESSAGE = 'Rebuild'
|
||||
|
||||
# Name of the remote
|
||||
ORIGIN = 'origin'
|
||||
|
||||
# Environment variables to check for a GitHub API token.
|
||||
TOKEN_ENVIRONMENT_VARIABLES = ('GH_TOKEN', 'GITHUB_TOKEN')
|
||||
|
||||
# Gets a GitHub API token from one of the supported environment variables.
|
||||
def get_github_token():
|
||||
for variable_name in TOKEN_ENVIRONMENT_VARIABLES:
|
||||
token = os.environ.get(variable_name, '').strip()
|
||||
if token:
|
||||
return token
|
||||
raise Exception('Missing GitHub token. Set GITHUB_TOKEN or GH_TOKEN.')
|
||||
|
||||
# Runs git with the given args and returns the stdout.
|
||||
# Raises an error if git does not exit successfully (unless passed
|
||||
# allow_non_zero_exit_code=True).
|
||||
def run_git(*args, allow_non_zero_exit_code=False):
|
||||
cmd = ['git', *args]
|
||||
p = subprocess.run(cmd, stdout=subprocess.PIPE, stderr=subprocess.PIPE)
|
||||
if not allow_non_zero_exit_code and p.returncode != 0:
|
||||
raise Exception(f'Call to {" ".join(cmd)} exited with code {p.returncode} stderr: {p.stderr.decode("ascii")}.')
|
||||
return p.stdout.decode('ascii')
|
||||
|
||||
# Runs the given command, streaming output to the console.
|
||||
# Raises an error if the command does not exit successfully.
|
||||
def run_command(*args):
|
||||
cmd = list(args)
|
||||
print(f'Running `{" ".join(cmd)}`.')
|
||||
subprocess.run(cmd, check=True)
|
||||
|
||||
# Rebuilds the action and commits any changes.
|
||||
def rebuild_action():
|
||||
# For backports, the only source-level change vs the source branch is the new version number,
|
||||
# so we just need to refresh the version embedded in `lib/`.
|
||||
run_command('npm', 'ci')
|
||||
run_command('npm', 'run', 'build')
|
||||
|
||||
run_git('add', '--all')
|
||||
# `git diff --cached --quiet` exits 0 if there are no staged changes, 1 if there are.
|
||||
if subprocess.run(['git', 'diff', '--cached', '--quiet']).returncode == 0:
|
||||
print('Rebuild produced no changes; skipping Rebuild commit.')
|
||||
else:
|
||||
run_git('commit', '-m', REBUILD_COMMIT_MESSAGE)
|
||||
print('Created Rebuild commit.')
|
||||
|
||||
# Returns true if the given branch exists on the origin remote
|
||||
def branch_exists_on_remote(branch_name):
|
||||
return run_git('ls-remote', '--heads', ORIGIN, branch_name).strip() != ''
|
||||
|
||||
# Opens a PR from the given branch to the target branch
|
||||
def open_pr(
|
||||
repo, all_commits, source_branch_short_sha, new_branch_name, source_branch, target_branch,
|
||||
conductor, is_primary_release, conflicted_files):
|
||||
# Sort the commits into the pull requests that introduced them,
|
||||
# and any commits that don't have a pull request
|
||||
pull_requests = []
|
||||
commits_without_pull_requests = []
|
||||
for commit in all_commits:
|
||||
pr = get_pr_for_commit(commit)
|
||||
|
||||
if pr is None:
|
||||
commits_without_pull_requests.append(commit)
|
||||
elif not any(p for p in pull_requests if p.number == pr.number):
|
||||
pull_requests.append(pr)
|
||||
|
||||
print(f'Found {len(pull_requests)} pull requests.')
|
||||
print(f'Found {len(commits_without_pull_requests)} commits not in a pull request.')
|
||||
|
||||
# Sort PRs and commits by age
|
||||
pull_requests = sorted(pull_requests, key=lambda pr: pr.number)
|
||||
commits_without_pull_requests = sorted(commits_without_pull_requests, key=lambda c: c.commit.author.date)
|
||||
|
||||
# Start constructing the body text
|
||||
body = []
|
||||
body.append(f'Merging {source_branch_short_sha} into `{target_branch}`.')
|
||||
|
||||
body.append('')
|
||||
body.append(f'Conductor for this PR is @{conductor}.')
|
||||
|
||||
# List all PRs merged
|
||||
if len(pull_requests) > 0:
|
||||
body.append('')
|
||||
body.append('Contains the following pull requests:')
|
||||
for pr in pull_requests:
|
||||
# Use PR author if they are GitHub staff, otherwise use the merger
|
||||
display_user = get_pr_author_if_staff(pr) or get_merger_of_pr(repo, pr)
|
||||
body.append(f'- #{pr.number} (@{display_user})')
|
||||
|
||||
# List all commits not part of a PR
|
||||
if len(commits_without_pull_requests) > 0:
|
||||
body.append('')
|
||||
body.append('Contains the following commits not from a pull request:')
|
||||
for commit in commits_without_pull_requests:
|
||||
author_description = f' (@{commit.author.login})' if commit.author is not None else ''
|
||||
body.append(f'- {commit.sha} - {get_truncated_commit_message(commit)}{author_description}')
|
||||
|
||||
body.append('')
|
||||
body.append('Please do the following:')
|
||||
if len(conflicted_files) > 0:
|
||||
body.append(' - [ ] Ensure `package.json` file contains the correct version.')
|
||||
body.append(' - [ ] Add a commit to this branch to resolve the merge conflicts ' +
|
||||
'in the following files:')
|
||||
body.extend([f' - `{file}`' for file in conflicted_files])
|
||||
body.append(' - [ ] Rebuild the Action locally (`npm run build`) and push any changes to the ' +
|
||||
f'built output in `lib` as a separate commit named exactly `{REBUILD_COMMIT_MESSAGE}`.')
|
||||
body.append(' - [ ] Ensure another maintainer has reviewed the additional commits you added to this ' +
|
||||
'branch to resolve the merge conflicts.')
|
||||
body.append(' - [ ] Ensure the CHANGELOG displays the correct version and date.')
|
||||
body.append(' - [ ] Ensure the CHANGELOG includes all relevant, user-facing changes since the last release.')
|
||||
body.append(f' - [ ] Check that there are not any unexpected commits being merged into the `{target_branch}` branch.')
|
||||
body.append(' - [ ] Ensure the docs team is aware of any documentation changes that need to be released.')
|
||||
|
||||
body.append(' - [ ] Approve running the full set of PR checks if you have not pushed any changes.')
|
||||
body.append(' - [ ] Approve and merge this PR. Make sure `Create a merge commit` is selected rather than `Squash and merge` or `Rebase and merge`.')
|
||||
|
||||
if is_primary_release:
|
||||
body.append(' - [ ] Merge the mergeback PR that will automatically be created once this PR is merged.')
|
||||
body.append(' - [ ] Merge all backport PRs to older release branches, that will automatically be created once this PR is merged.')
|
||||
|
||||
title = f'Merge {source_branch} into {target_branch}'
|
||||
|
||||
# Create the pull request
|
||||
pr = repo.create_pull(title=title, body='\n'.join(body), head=new_branch_name, base=target_branch)
|
||||
print(f'Created PR #{str(pr.number)}')
|
||||
|
||||
# Assign the conductor
|
||||
pr.add_to_assignees(conductor)
|
||||
print(f'Assigned PR to {conductor}')
|
||||
|
||||
# Gets a list of the SHAs of all commits that have happened on the source branch
|
||||
# since the last release to the target branch.
|
||||
# This will not include any commits that exist on the target branch
|
||||
# that aren't on the source branch.
|
||||
def get_commit_difference(repo, source_branch, target_branch):
|
||||
# Passing split nothing means that the empty string splits to nothing: compare `''.split() == []`
|
||||
# to `''.split('\n') == ['']`.
|
||||
commits = run_git('log', '--pretty=format:%H', f'{ORIGIN}/{target_branch}..{ORIGIN}/{source_branch}').strip().split()
|
||||
|
||||
# Convert to full-fledged commit objects
|
||||
commits = [repo.get_commit(c) for c in commits]
|
||||
|
||||
# Filter out merge commits for PRs
|
||||
return list(filter(lambda c: not is_pr_merge_commit(c), commits))
|
||||
|
||||
# Is the given commit the automatic merge commit from when merging a PR
|
||||
def is_pr_merge_commit(commit):
|
||||
return commit.committer is not None and commit.committer.login == 'web-flow' and len(commit.parents) > 1
|
||||
|
||||
# Gets a copy of the commit message that should display nicely
|
||||
def get_truncated_commit_message(commit):
|
||||
message = commit.commit.message.split('\n')[0]
|
||||
if len(message) > 60:
|
||||
return f'{message[:57]}...'
|
||||
else:
|
||||
return message
|
||||
|
||||
# Converts a commit into the PR that introduced it to the source branch.
|
||||
# Returns the PR object, or None if no PR could be found.
|
||||
def get_pr_for_commit(commit):
|
||||
prs = commit.get_pulls()
|
||||
|
||||
if prs.totalCount > 0:
|
||||
# In the case that there are multiple PRs, return the earliest one
|
||||
prs = list(prs)
|
||||
sorted_prs = sorted(prs, key=lambda pr: int(pr.number))
|
||||
return sorted_prs[0]
|
||||
else:
|
||||
return None
|
||||
|
||||
# Get the person who merged the pull request.
|
||||
# For most cases this will be the same as the author, but for PRs opened
|
||||
# by external contributors getting the merger will get us the GitHub
|
||||
# employee who reviewed and merged the PR.
|
||||
def get_merger_of_pr(repo, pr):
|
||||
return repo.get_commit(pr.merge_commit_sha).author.login
|
||||
|
||||
# Get the PR author if they are GitHub staff, otherwise None.
|
||||
def get_pr_author_if_staff(pr):
|
||||
if pr.user is None:
|
||||
return None
|
||||
if getattr(pr.user, 'site_admin', False):
|
||||
return pr.user.login
|
||||
return None
|
||||
|
||||
def get_current_version():
|
||||
with open('package.json', 'r') as f:
|
||||
return json.load(f)['version']
|
||||
|
||||
# `npm version` doesn't always work because of merge conflicts, so we
|
||||
# replace the version in package.json textually.
|
||||
def replace_version_package_json(prev_version, new_version):
|
||||
prev_line_is_codeql = False
|
||||
for line in fileinput.input('package.json', inplace = True, encoding='utf-8'):
|
||||
if prev_line_is_codeql and f'\"version\": \"{prev_version}\"' in line:
|
||||
print(line.replace(prev_version, new_version), end='')
|
||||
else:
|
||||
prev_line_is_codeql = False
|
||||
print(line, end='')
|
||||
if '\"name\": \"codeql\",' in line:
|
||||
prev_line_is_codeql = True
|
||||
|
||||
def get_today_string():
|
||||
today = datetime.datetime.today()
|
||||
return '{:%d %b %Y}'.format(today)
|
||||
|
||||
def process_changelog_for_backports(source_branch_major_version, target_branch_major_version):
|
||||
|
||||
# changelog entries can use the following format to indicate
|
||||
# that they only apply to newer versions
|
||||
some_versions_only_regex = re.compile(r'\[v(\d+)\+ only\]')
|
||||
|
||||
output = ''
|
||||
|
||||
with open('CHANGELOG.md', 'r') as f:
|
||||
|
||||
# until we find the first section, just duplicate all lines
|
||||
found_first_section = False
|
||||
while not found_first_section:
|
||||
line = f.readline()
|
||||
if not line:
|
||||
raise Exception('Could not find any change sections in CHANGELOG.md') # EOF
|
||||
|
||||
if line.startswith('## '):
|
||||
line = line.replace(f'## {source_branch_major_version}', f'## {target_branch_major_version}')
|
||||
found_first_section = True
|
||||
|
||||
output += line
|
||||
|
||||
# found_content tracks whether we hit two headings in a row
|
||||
found_content = False
|
||||
output += '\n'
|
||||
while True:
|
||||
line = f.readline()
|
||||
if not line:
|
||||
break # EOF
|
||||
line = line.rstrip('\n')
|
||||
|
||||
# filter out changenote entries that apply only to newer versions
|
||||
match = some_versions_only_regex.search(line)
|
||||
if match:
|
||||
if int(target_branch_major_version) < int(match.group(1)):
|
||||
continue
|
||||
|
||||
if line.startswith('## '):
|
||||
line = line.replace(f'## {source_branch_major_version}', f'## {target_branch_major_version}')
|
||||
if found_content == False:
|
||||
# we have found two headings in a row, so we need to add the placeholder message.
|
||||
output += 'No user facing changes.\n'
|
||||
found_content = False
|
||||
output += f'\n{line}\n\n'
|
||||
else:
|
||||
if line.strip() != '':
|
||||
found_content = True
|
||||
# we use the original line here, rather than the stripped version
|
||||
# so that we preserve indentation
|
||||
output += line + '\n'
|
||||
|
||||
with open('CHANGELOG.md', 'w') as f:
|
||||
f.write(output)
|
||||
|
||||
def update_changelog(version):
|
||||
if (os.path.exists('CHANGELOG.md')):
|
||||
content = ''
|
||||
with open('CHANGELOG.md', 'r') as f:
|
||||
content = f.read()
|
||||
else:
|
||||
content = EMPTY_CHANGELOG
|
||||
|
||||
newContent = content.replace('[UNRELEASED]', f'{version} - {get_today_string()}', 1)
|
||||
|
||||
with open('CHANGELOG.md', 'w') as f:
|
||||
f.write(newContent)
|
||||
|
||||
|
||||
def main():
|
||||
parser = argparse.ArgumentParser('update-release-branch.py')
|
||||
|
||||
parser.add_argument(
|
||||
'--repository-nwo',
|
||||
type=str,
|
||||
required=True,
|
||||
help='The nwo of the repository, for example github/codeql-action.'
|
||||
)
|
||||
parser.add_argument(
|
||||
'--source-branch',
|
||||
type=str,
|
||||
required=True,
|
||||
help='Source branch for release branch update.'
|
||||
)
|
||||
parser.add_argument(
|
||||
'--target-branch',
|
||||
type=str,
|
||||
required=True,
|
||||
help='Target branch for release branch update.'
|
||||
)
|
||||
parser.add_argument(
|
||||
'--is-primary-release',
|
||||
action='store_true',
|
||||
default=False,
|
||||
help='Whether this update is the primary release for the current major version.'
|
||||
)
|
||||
parser.add_argument(
|
||||
'--conductor',
|
||||
type=str,
|
||||
required=True,
|
||||
help='The GitHub handle of the person who is conducting the release process.'
|
||||
)
|
||||
|
||||
args = parser.parse_args()
|
||||
|
||||
source_branch = args.source_branch
|
||||
target_branch = args.target_branch
|
||||
is_primary_release = args.is_primary_release
|
||||
|
||||
repo = Github(get_github_token()).get_repo(args.repository_nwo)
|
||||
|
||||
# the target branch will be of the form releases/vN, where N is the major version number
|
||||
target_branch_major_version = target_branch.strip('releases/v')
|
||||
|
||||
# split version into major, minor, patch
|
||||
_, v_minor, v_patch = get_current_version().split('.')
|
||||
|
||||
version = f"{target_branch_major_version}.{v_minor}.{v_patch}"
|
||||
|
||||
# Print what we intend to go
|
||||
print(f'Considering difference between {source_branch} and {target_branch}...')
|
||||
source_branch_short_sha = run_git('rev-parse', '--short', f'{ORIGIN}/{source_branch}').strip()
|
||||
print(f'Current head of {source_branch} is {source_branch_short_sha}.')
|
||||
|
||||
# See if there are any commits to merge in
|
||||
commits = get_commit_difference(repo=repo, source_branch=source_branch, target_branch=target_branch)
|
||||
if len(commits) == 0:
|
||||
print(f'No commits to merge from {source_branch} to {target_branch}.')
|
||||
return
|
||||
|
||||
# define distinct prefix in order to support specific pr checks on backports
|
||||
branch_prefix = 'update' if is_primary_release else 'backport'
|
||||
|
||||
# The branch name is based off of the name of branch being merged into
|
||||
# and the SHA of the branch being merged from. Thus if the branch already
|
||||
# exists we can assume we don't need to recreate it.
|
||||
new_branch_name = f'{branch_prefix}-v{version}-{source_branch_short_sha}'
|
||||
print(f'Branch name is {new_branch_name}.')
|
||||
|
||||
# Check if the branch already exists. If so we can abort as this script
|
||||
# has already run on this combination of branches.
|
||||
if branch_exists_on_remote(new_branch_name):
|
||||
print(f'Branch {new_branch_name} already exists. Nothing to do.')
|
||||
return
|
||||
|
||||
# Create the new branch and push it to the remote
|
||||
print(f'Creating branch {new_branch_name}.')
|
||||
|
||||
# The process of creating the v{Older} release can run into merge conflicts. We commit the unresolved
|
||||
# conflicts so a maintainer can easily resolve them (vs erroring and requiring maintainers to
|
||||
# reconstruct the release manually)
|
||||
conflicted_files = []
|
||||
|
||||
if not is_primary_release:
|
||||
|
||||
# the source branch will be of the form releases/vN, where N is the major version number
|
||||
source_branch_major_version = source_branch.strip('releases/v')
|
||||
|
||||
# If we're performing a backport, start from the target branch
|
||||
print(f'Creating {new_branch_name} from the {ORIGIN}/{target_branch} branch')
|
||||
run_git('checkout', '-b', new_branch_name, f'{ORIGIN}/{target_branch}')
|
||||
|
||||
# Revert the commit that we made as part of the last release that updated the version number and
|
||||
# changelog to refer to {older}.x.x variants. This avoids merge conflicts in the changelog and
|
||||
# package.json files when we merge in the v{latest} branch.
|
||||
# This commit will not exist the first time we release the v{N-1} branch from the v{N} branch, so we
|
||||
# use `git log --grep` to conditionally revert the commit.
|
||||
print('Reverting the version number and changelog updates from the last release to avoid conflicts')
|
||||
vOlder_update_commits = run_git('log', '--grep', f'^{BACKPORT_COMMIT_MESSAGE}', '--format=%H').split()
|
||||
|
||||
if len(vOlder_update_commits) > 0:
|
||||
print(f' Reverting {vOlder_update_commits[0]}')
|
||||
# Only revert the newest commit as older ones will already have been reverted in previous
|
||||
# releases.
|
||||
run_git('revert', vOlder_update_commits[0], '--no-edit')
|
||||
|
||||
# Also revert the "Rebuild" commit, whether created by this script or by the
|
||||
# `Rebuild Action` workflow.
|
||||
rebuild_commit = run_git('log', '--grep', f'^{REBUILD_COMMIT_MESSAGE}$', '--format=%H').split()[0]
|
||||
print(f' Reverting {rebuild_commit}')
|
||||
run_git('revert', rebuild_commit, '--no-edit')
|
||||
|
||||
else:
|
||||
print(' Nothing to revert.')
|
||||
|
||||
print(f'Merging {ORIGIN}/{source_branch} into the release prep branch')
|
||||
# Commit any conflicts (see the comment for `conflicted_files`)
|
||||
run_git('merge', f'{ORIGIN}/{source_branch}', allow_non_zero_exit_code=True)
|
||||
conflicted_files = run_git('diff', '--name-only', '--diff-filter', 'U').splitlines()
|
||||
if len(conflicted_files) > 0:
|
||||
run_git('add', '.')
|
||||
run_git('commit', '--no-edit')
|
||||
|
||||
# Migrate the package version number from a vLatest version number to a vOlder version number.
|
||||
# `package-lock.json` is updated as part of the subsequent rebuild step (see `rebuild_action`).
|
||||
print(f'Setting version number to {version} in package.json')
|
||||
replace_version_package_json(get_current_version(), version)
|
||||
run_git('add', 'package.json')
|
||||
|
||||
# Migrate the changelog notes from vLatest version numbers to vOlder version numbers
|
||||
print(f'Migrating changelog notes from v{source_branch_major_version} to v{target_branch_major_version}')
|
||||
process_changelog_for_backports(source_branch_major_version, target_branch_major_version)
|
||||
|
||||
# Amend the commit generated by `npm version` to update the CHANGELOG
|
||||
run_git('add', 'CHANGELOG.md')
|
||||
run_git('commit', '-m', f'{BACKPORT_COMMIT_MESSAGE}{version}')
|
||||
else:
|
||||
# If we're performing a standard release, there won't be any new commits on the target branch,
|
||||
# as these will have already been merged back into the source branch. Therefore we can just
|
||||
# start from the source branch.
|
||||
run_git('checkout', '-b', new_branch_name, f'{ORIGIN}/{source_branch}')
|
||||
|
||||
print('Updating changelog')
|
||||
update_changelog(version)
|
||||
|
||||
# Create a commit that updates the CHANGELOG
|
||||
run_git('add', 'CHANGELOG.md')
|
||||
run_git('commit', '-m', f'Update changelog for v{version}')
|
||||
|
||||
if not is_primary_release:
|
||||
if len(conflicted_files) == 0:
|
||||
print('Rebuilding the Action.')
|
||||
rebuild_action()
|
||||
else:
|
||||
print(f'Skipping automatic rebuild because the merge produced conflicts in {conflicted_files}.')
|
||||
|
||||
run_git('push', ORIGIN, new_branch_name)
|
||||
|
||||
# Open a PR to update the branch
|
||||
open_pr(
|
||||
repo,
|
||||
commits,
|
||||
source_branch_short_sha,
|
||||
new_branch_name,
|
||||
source_branch=source_branch,
|
||||
target_branch=target_branch,
|
||||
conductor=args.conductor,
|
||||
is_primary_release=is_primary_release,
|
||||
conflicted_files=conflicted_files
|
||||
)
|
||||
|
||||
if __name__ == '__main__':
|
||||
main()
|
||||
19
.github/workflows/__all-platform-bundle.yml
generated
vendored
19
.github/workflows/__all-platform-bundle.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -56,12 +61,14 @@ jobs:
|
||||
include:
|
||||
- os: ubuntu-latest
|
||||
version: nightly-latest
|
||||
- os: macos-latest
|
||||
- os: macos-latest-xlarge
|
||||
version: nightly-latest
|
||||
- os: windows-latest
|
||||
version: nightly-latest
|
||||
name: All-platform bundle
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -69,13 +76,13 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Install .NET
|
||||
uses: actions/setup-dotnet@26b0ec14cb23fa6904739307f278c14f94c95bf1 # v5.4.0
|
||||
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
|
||||
with:
|
||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||
- name: Install Go
|
||||
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||
cache: false
|
||||
|
||||
13
.github/workflows/__analysis-kinds.yml
generated
vendored
13
.github/workflows/__analysis-kinds.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -59,7 +64,9 @@ jobs:
|
||||
version: nightly-latest
|
||||
analysis-kinds: risk-assessment
|
||||
name: Analysis kinds
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -67,7 +74,7 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
|
||||
17
.github/workflows/__analyze-ref-input.yml
generated
vendored
17
.github/workflows/__analyze-ref-input.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -57,7 +62,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: default
|
||||
name: "Analyze: 'ref' and 'sha' from inputs"
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -65,13 +72,13 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Install .NET
|
||||
uses: actions/setup-dotnet@26b0ec14cb23fa6904739307f278c14f94c95bf1 # v5.4.0
|
||||
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
|
||||
with:
|
||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||
- name: Install Go
|
||||
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||
cache: false
|
||||
|
||||
15
.github/workflows/__autobuild-action.yml
generated
vendored
15
.github/workflows/__autobuild-action.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -51,7 +56,9 @@ jobs:
|
||||
- os: windows-latest
|
||||
version: linked
|
||||
name: autobuild-action
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -59,9 +66,9 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Install .NET
|
||||
uses: actions/setup-dotnet@26b0ec14cb23fa6904739307f278c14f94c95bf1 # v5.4.0
|
||||
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
|
||||
with:
|
||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||
- name: Prepare test
|
||||
|
||||
15
.github/workflows/__autobuild-direct-tracing-with-working-dir.yml
generated
vendored
15
.github/workflows/__autobuild-direct-tracing-with-working-dir.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -53,7 +58,9 @@ jobs:
|
||||
- os: windows-latest
|
||||
version: nightly-latest
|
||||
name: Autobuild direct tracing (custom working directory)
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -61,9 +68,9 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Install Java
|
||||
uses: actions/setup-java@0f481fcb613427c0f801b606911222b5b6f3083a # v5.5.0
|
||||
uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1
|
||||
with:
|
||||
java-version: ${{ inputs.java-version || '17' }}
|
||||
distribution: temurin
|
||||
|
||||
13
.github/workflows/__autobuild-working-dir.yml
generated
vendored
13
.github/workflows/__autobuild-working-dir.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -37,7 +42,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: linked
|
||||
name: Autobuild working directory
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -45,7 +52,7 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
|
||||
15
.github/workflows/__build-mode-autobuild.yml
generated
vendored
15
.github/workflows/__build-mode-autobuild.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -53,7 +58,9 @@ jobs:
|
||||
- os: windows-latest
|
||||
version: nightly-latest
|
||||
name: Build mode autobuild
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -61,9 +68,9 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Install Java
|
||||
uses: actions/setup-java@0f481fcb613427c0f801b606911222b5b6f3083a # v5.5.0
|
||||
uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1
|
||||
with:
|
||||
java-version: ${{ inputs.java-version || '17' }}
|
||||
distribution: temurin
|
||||
|
||||
17
.github/workflows/__build-mode-manual.yml
generated
vendored
17
.github/workflows/__build-mode-manual.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -57,7 +62,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: nightly-latest
|
||||
name: Build mode manual
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -65,13 +72,13 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Install .NET
|
||||
uses: actions/setup-dotnet@26b0ec14cb23fa6904739307f278c14f94c95bf1 # v5.4.0
|
||||
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
|
||||
with:
|
||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||
- name: Install Go
|
||||
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||
cache: false
|
||||
|
||||
13
.github/workflows/__build-mode-none.yml
generated
vendored
13
.github/workflows/__build-mode-none.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -39,7 +44,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: nightly-latest
|
||||
name: Build mode none
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -47,7 +54,7 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
|
||||
13
.github/workflows/__build-mode-rollback.yml
generated
vendored
13
.github/workflows/__build-mode-rollback.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -37,7 +42,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: nightly-latest
|
||||
name: Build mode rollback
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -45,7 +52,7 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
|
||||
13
.github/workflows/__bundle-from-nightly.yml
generated
vendored
13
.github/workflows/__bundle-from-nightly.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -37,7 +42,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: linked
|
||||
name: 'Bundle: From nightly'
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -45,7 +52,7 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
|
||||
13
.github/workflows/__bundle-from-toolcache.yml
generated
vendored
13
.github/workflows/__bundle-from-toolcache.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -37,7 +42,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: toolcache
|
||||
name: 'Bundle: From toolcache'
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -45,7 +52,7 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
|
||||
13
.github/workflows/__bundle-toolcache.yml
generated
vendored
13
.github/workflows/__bundle-toolcache.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -41,7 +46,9 @@ jobs:
|
||||
- os: windows-latest
|
||||
version: linked
|
||||
name: 'Bundle: Caching checks'
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -49,7 +56,7 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
|
||||
120
.github/workflows/__bundle-zstd.yml
generated
vendored
120
.github/workflows/__bundle-zstd.yml
generated
vendored
@@ -1,120 +0,0 @@
|
||||
# Warning: This file is generated automatically, and should not be modified.
|
||||
# Instead, please modify the template in the pr-checks directory and run:
|
||||
# pr-checks/sync.sh
|
||||
# to regenerate this file.
|
||||
|
||||
name: 'PR Check - Bundle: Zstandard checks'
|
||||
env:
|
||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
GO111MODULE: auto
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
schedule:
|
||||
- cron: '0 5 * * *'
|
||||
workflow_dispatch:
|
||||
inputs: {}
|
||||
workflow_call:
|
||||
inputs: {}
|
||||
defaults:
|
||||
run:
|
||||
shell: bash
|
||||
concurrency:
|
||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||
group: bundle-zstd-${{github.ref}}
|
||||
jobs:
|
||||
bundle-zstd:
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
include:
|
||||
- os: ubuntu-latest
|
||||
version: linked
|
||||
- os: macos-latest
|
||||
version: linked
|
||||
- os: windows-latest
|
||||
version: linked
|
||||
name: 'Bundle: Zstandard checks'
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
timeout-minutes: 45
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
with:
|
||||
version: ${{ matrix.version }}
|
||||
use-all-platform-bundle: 'false'
|
||||
setup-kotlin: 'true'
|
||||
- name: Remove CodeQL from toolcache
|
||||
uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0
|
||||
with:
|
||||
script: |
|
||||
const fs = require('fs');
|
||||
const path = require('path');
|
||||
const codeqlPath = path.join(process.env['RUNNER_TOOL_CACHE'], 'CodeQL');
|
||||
if (codeqlPath !== undefined) {
|
||||
fs.rmdirSync(codeqlPath, { recursive: true });
|
||||
}
|
||||
- id: init
|
||||
uses: ./../action/init
|
||||
with:
|
||||
languages: javascript
|
||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||
- uses: ./../action/analyze
|
||||
with:
|
||||
output: ${{ runner.temp }}/results
|
||||
upload-database: false
|
||||
- name: Upload SARIF
|
||||
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
||||
with:
|
||||
name: ${{ matrix.os }}-zstd-bundle.sarif
|
||||
path: ${{ runner.temp }}/results/javascript.sarif
|
||||
retention-days: 7
|
||||
- name: Check diagnostic with expected tools URL appears in SARIF
|
||||
uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0
|
||||
env:
|
||||
SARIF_PATH: ${{ runner.temp }}/results/javascript.sarif
|
||||
with:
|
||||
script: |
|
||||
const fs = require('fs');
|
||||
|
||||
const sarif = JSON.parse(fs.readFileSync(process.env['SARIF_PATH'], 'utf8'));
|
||||
const run = sarif.runs[0];
|
||||
|
||||
const toolExecutionNotifications = run.invocations[0].toolExecutionNotifications;
|
||||
const downloadTelemetryNotifications = toolExecutionNotifications.filter(n =>
|
||||
n.descriptor.id === 'codeql-action/bundle-download-telemetry'
|
||||
);
|
||||
if (downloadTelemetryNotifications.length !== 1) {
|
||||
core.setFailed(
|
||||
'Expected exactly one reporting descriptor in the ' +
|
||||
`'runs[].invocations[].toolExecutionNotifications[]' SARIF property, but found ` +
|
||||
`${downloadTelemetryNotifications.length}. All notification reporting descriptors: ` +
|
||||
`${JSON.stringify(toolExecutionNotifications)}.`
|
||||
);
|
||||
}
|
||||
|
||||
const toolsUrl = downloadTelemetryNotifications[0].properties.attributes.toolsUrl;
|
||||
console.log(`Found tools URL: ${toolsUrl}`);
|
||||
|
||||
const expectedExtension = process.env['RUNNER_OS'] === 'Windows' ? '.tar.gz' : '.tar.zst';
|
||||
|
||||
if (!toolsUrl.endsWith(expectedExtension)) {
|
||||
core.setFailed(
|
||||
`Expected the tools URL to be a ${expectedExtension} file, but found ${toolsUrl}.`
|
||||
);
|
||||
}
|
||||
env:
|
||||
CODEQL_ACTION_TEST_MODE: true
|
||||
13
.github/workflows/__cleanup-db-cluster-dir.yml
generated
vendored
13
.github/workflows/__cleanup-db-cluster-dir.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -37,7 +42,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: linked
|
||||
name: Clean up database cluster directory
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -45,7 +52,7 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
|
||||
13
.github/workflows/__config-export.yml
generated
vendored
13
.github/workflows/__config-export.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -39,7 +44,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: nightly-latest
|
||||
name: Config export
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -47,7 +54,7 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
|
||||
15
.github/workflows/__config-input.yml
generated
vendored
15
.github/workflows/__config-input.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -37,7 +42,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: linked
|
||||
name: Config input
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -45,9 +52,9 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Install Node.js
|
||||
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
|
||||
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
||||
with:
|
||||
node-version: 20.x
|
||||
cache: npm
|
||||
|
||||
13
.github/workflows/__cpp-deptrace-disabled.yml
generated
vendored
13
.github/workflows/__cpp-deptrace-disabled.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -41,7 +46,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: nightly-latest
|
||||
name: 'C/C++: disabling autoinstalling dependencies (Linux)'
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -49,7 +56,7 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
|
||||
13
.github/workflows/__cpp-deptrace-enabled-on-macos.yml
generated
vendored
13
.github/workflows/__cpp-deptrace-enabled-on-macos.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -39,7 +44,9 @@ jobs:
|
||||
- os: macos-latest
|
||||
version: nightly-latest
|
||||
name: 'C/C++: autoinstalling dependencies is skipped (macOS)'
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -47,7 +54,7 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
|
||||
13
.github/workflows/__cpp-deptrace-enabled.yml
generated
vendored
13
.github/workflows/__cpp-deptrace-enabled.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -41,7 +46,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: nightly-latest
|
||||
name: 'C/C++: autoinstalling dependencies (Linux)'
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -49,7 +56,7 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
|
||||
13
.github/workflows/__diagnostics-export.yml
generated
vendored
13
.github/workflows/__diagnostics-export.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -39,7 +44,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: nightly-latest
|
||||
name: Diagnostic export
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -47,7 +54,7 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
|
||||
17
.github/workflows/__export-file-baseline-information.yml
generated
vendored
17
.github/workflows/__export-file-baseline-information.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -61,7 +66,9 @@ jobs:
|
||||
- os: windows-latest
|
||||
version: nightly-latest
|
||||
name: Export file baseline information
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -69,13 +76,13 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Install .NET
|
||||
uses: actions/setup-dotnet@26b0ec14cb23fa6904739307f278c14f94c95bf1 # v5.4.0
|
||||
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
|
||||
with:
|
||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||
- name: Install Go
|
||||
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||
cache: false
|
||||
|
||||
13
.github/workflows/__extractor-ram-threads.yml
generated
vendored
13
.github/workflows/__extractor-ram-threads.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -37,7 +42,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: linked
|
||||
name: Extractor ram and threads options test
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -45,7 +52,7 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
|
||||
43
.github/workflows/__global-proxy.yml
generated
vendored
43
.github/workflows/__global-proxy.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -39,7 +44,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: nightly-latest
|
||||
name: Proxy test
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -47,7 +54,7 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
@@ -55,17 +62,45 @@ jobs:
|
||||
version: ${{ matrix.version }}
|
||||
use-all-platform-bundle: 'false'
|
||||
setup-kotlin: 'false'
|
||||
- name: Block direct internet access to force proxy usage
|
||||
run: |
|
||||
apt-get update -qq && apt-get install -y -qq iptables >/dev/null 2>&1
|
||||
PROXY_IP=$(getent hosts squid-proxy | awk '{ print $1 }')
|
||||
echo "Squid proxy IP: $PROXY_IP"
|
||||
# Allow all traffic to the proxy container
|
||||
iptables -A OUTPUT -d "$PROXY_IP" -j ACCEPT
|
||||
# Allow DNS resolution
|
||||
iptables -A OUTPUT -p udp --dport 53 -j ACCEPT
|
||||
iptables -A OUTPUT -p tcp --dport 53 -j ACCEPT
|
||||
# Allow loopback
|
||||
iptables -A OUTPUT -o lo -j ACCEPT
|
||||
# Allow already-established connections (from checkout/prepare-test)
|
||||
iptables -A OUTPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
|
||||
# Block all other outbound HTTP and HTTPS, ensuring direct access fails
|
||||
iptables -A OUTPUT -p tcp --dport 80 -j REJECT --reject-with tcp-reset
|
||||
iptables -A OUTPUT -p tcp --dport 443 -j REJECT --reject-with tcp-reset
|
||||
echo "Direct HTTP/HTTPS access is now blocked - all traffic must go through the proxy"
|
||||
|
||||
- name: Set proxy environment variables
|
||||
shell: bash
|
||||
run: |
|
||||
echo "http_proxy=http://squid-proxy:3128" >> $GITHUB_ENV
|
||||
echo "HTTP_PROXY=http://squid-proxy:3128" >> $GITHUB_ENV
|
||||
echo "https_proxy=http://squid-proxy:3128" >> $GITHUB_ENV
|
||||
echo "HTTPS_PROXY=http://squid-proxy:3128" >> $GITHUB_ENV
|
||||
|
||||
- uses: ./../action/init
|
||||
with:
|
||||
languages: javascript
|
||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||
|
||||
- uses: ./../action/analyze
|
||||
env:
|
||||
https_proxy: http://squid-proxy:3128
|
||||
CODEQL_ACTION_TOLERATE_MISSING_GIT_VERSION: true
|
||||
CODEQL_ACTION_TEST_MODE: true
|
||||
container:
|
||||
image: ubuntu:22.04
|
||||
options: --cap-add=NET_ADMIN
|
||||
services:
|
||||
squid-proxy:
|
||||
image: ubuntu/squid:latest
|
||||
|
||||
17
.github/workflows/__go-custom-queries.yml
generated
vendored
17
.github/workflows/__go-custom-queries.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -59,7 +64,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: nightly-latest
|
||||
name: 'Go: Custom queries'
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -67,13 +74,13 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Install .NET
|
||||
uses: actions/setup-dotnet@26b0ec14cb23fa6904739307f278c14f94c95bf1 # v5.4.0
|
||||
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
|
||||
with:
|
||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||
- name: Install Go
|
||||
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||
cache: false
|
||||
|
||||
17
.github/workflows/__go-indirect-tracing-workaround-diagnostic.yml
generated
vendored
17
.github/workflows/__go-indirect-tracing-workaround-diagnostic.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -47,7 +52,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: default
|
||||
name: 'Go: diagnostic when Go is changed after init step'
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -55,9 +62,9 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Install Go
|
||||
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||
cache: false
|
||||
@@ -73,7 +80,7 @@ jobs:
|
||||
languages: go
|
||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||
# Deliberately change Go after the `init` step
|
||||
- uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
||||
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: '1.20'
|
||||
- name: Build code
|
||||
|
||||
15
.github/workflows/__go-indirect-tracing-workaround-no-file-program.yml
generated
vendored
15
.github/workflows/__go-indirect-tracing-workaround-no-file-program.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -47,7 +52,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: default
|
||||
name: 'Go: diagnostic when `file` is not installed'
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -55,9 +62,9 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Install Go
|
||||
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||
cache: false
|
||||
|
||||
15
.github/workflows/__go-indirect-tracing-workaround.yml
generated
vendored
15
.github/workflows/__go-indirect-tracing-workaround.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -47,7 +52,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: default
|
||||
name: 'Go: workaround for indirect tracing'
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -55,9 +62,9 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Install Go
|
||||
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||
cache: false
|
||||
|
||||
15
.github/workflows/__go-tracing-autobuilder.yml
generated
vendored
15
.github/workflows/__go-tracing-autobuilder.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -67,7 +72,9 @@ jobs:
|
||||
- os: macos-latest
|
||||
version: nightly-latest
|
||||
name: 'Go: tracing with autobuilder step'
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -75,9 +82,9 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Install Go
|
||||
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||
cache: false
|
||||
|
||||
15
.github/workflows/__go-tracing-custom-build-steps.yml
generated
vendored
15
.github/workflows/__go-tracing-custom-build-steps.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -67,7 +72,9 @@ jobs:
|
||||
- os: macos-latest
|
||||
version: nightly-latest
|
||||
name: 'Go: tracing with custom build steps'
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -75,9 +82,9 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Install Go
|
||||
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||
cache: false
|
||||
|
||||
15
.github/workflows/__go-tracing-legacy-workflow.yml
generated
vendored
15
.github/workflows/__go-tracing-legacy-workflow.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -67,7 +72,9 @@ jobs:
|
||||
- os: macos-latest
|
||||
version: nightly-latest
|
||||
name: 'Go: tracing with legacy workflow'
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -75,9 +82,9 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Install Go
|
||||
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||
cache: false
|
||||
|
||||
13
.github/workflows/__init-with-registries.yml
generated
vendored
13
.github/workflows/__init-with-registries.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -41,7 +46,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: nightly-latest
|
||||
name: 'Packaging: Download using registries'
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
packages: read
|
||||
@@ -49,7 +56,7 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
|
||||
13
.github/workflows/__javascript-source-root.yml
generated
vendored
13
.github/workflows/__javascript-source-root.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -41,7 +46,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: nightly-latest
|
||||
name: Custom source root
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -49,7 +56,7 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
|
||||
17
.github/workflows/__job-run-uuid-sarif.yml
generated
vendored
17
.github/workflows/__job-run-uuid-sarif.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -37,7 +42,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: nightly-latest
|
||||
name: Job run UUID added to SARIF
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -45,7 +52,7 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
@@ -71,8 +78,8 @@ jobs:
|
||||
run: |
|
||||
cd "$RUNNER_TEMP/results"
|
||||
actual=$(jq -r '.runs[0].properties.jobRunUuid' javascript.sarif)
|
||||
if [[ "$actual" != "$JOB_RUN_UUID" ]]; then
|
||||
echo "Expected SARIF output to contain job run UUID '$JOB_RUN_UUID', but found '$actual'."
|
||||
if [[ "$actual" != "$CODEQL_ACTION_JOB_RUN_UUID" ]]; then
|
||||
echo "Expected SARIF output to contain job run UUID '$CODEQL_ACTION_JOB_RUN_UUID', but found '$actual'."
|
||||
exit 1
|
||||
else
|
||||
echo "Found job run UUID '$actual'."
|
||||
|
||||
13
.github/workflows/__language-aliases.yml
generated
vendored
13
.github/workflows/__language-aliases.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -37,7 +42,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: linked
|
||||
name: Language aliases
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -45,7 +52,7 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
|
||||
113
.github/workflows/__linux-arm64.yml
generated
vendored
Normal file
113
.github/workflows/__linux-arm64.yml
generated
vendored
Normal file
@@ -0,0 +1,113 @@
|
||||
# Warning: This file is generated automatically, and should not be modified.
|
||||
# Instead, please modify the template in the pr-checks directory and run:
|
||||
# pr-checks/sync.sh
|
||||
# to regenerate this file.
|
||||
|
||||
name: PR Check - Linux Arm64
|
||||
env:
|
||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
GO111MODULE: auto
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
schedule:
|
||||
- cron: '0 5 * * *'
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
dotnet-version:
|
||||
type: string
|
||||
description: The version of .NET to install
|
||||
required: false
|
||||
default: 9.x
|
||||
go-version:
|
||||
type: string
|
||||
description: The version of Go to install
|
||||
required: false
|
||||
default: '>=1.21.0'
|
||||
workflow_call:
|
||||
inputs:
|
||||
dotnet-version:
|
||||
type: string
|
||||
description: The version of .NET to install
|
||||
required: false
|
||||
default: 9.x
|
||||
go-version:
|
||||
type: string
|
||||
description: The version of Go to install
|
||||
required: false
|
||||
default: '>=1.21.0'
|
||||
defaults:
|
||||
run:
|
||||
shell: bash
|
||||
concurrency:
|
||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||
group: linux-arm64-${{github.ref}}-${{inputs.dotnet-version}}-${{inputs.go-version}}
|
||||
jobs:
|
||||
linux-arm64:
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
include:
|
||||
- os: ubuntu-24.04-arm
|
||||
version: nightly-latest
|
||||
name: Linux Arm64
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
timeout-minutes: 45
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Install .NET
|
||||
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
|
||||
with:
|
||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||
- name: Install Go
|
||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||
cache: false
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
with:
|
||||
version: ${{ matrix.version }}
|
||||
use-all-platform-bundle: 'false'
|
||||
setup-kotlin: 'true'
|
||||
- uses: ./../action/init
|
||||
with:
|
||||
languages: ${{ env.LANGUAGES }}
|
||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||
- name: Build code
|
||||
run: ./build.sh
|
||||
- uses: ./../action/analyze
|
||||
with:
|
||||
upload-database: false
|
||||
- name: Assert databases exist
|
||||
run: |
|
||||
cd "$RUNNER_TEMP/codeql_databases"
|
||||
for lang in ${LANGUAGES//,/ }; do
|
||||
if [[ ! -d "$lang" ]]; then
|
||||
echo "Did not find a database for $lang"
|
||||
exit 1
|
||||
fi
|
||||
echo "Found database for $lang"
|
||||
done
|
||||
env:
|
||||
LANGUAGES: cpp,csharp,go,java,javascript,python,ruby
|
||||
CODEQL_ACTION_TEST_MODE: true
|
||||
17
.github/workflows/__local-bundle.yml
generated
vendored
17
.github/workflows/__local-bundle.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -57,7 +62,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: linked
|
||||
name: Local CodeQL bundle
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -65,13 +72,13 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Install .NET
|
||||
uses: actions/setup-dotnet@26b0ec14cb23fa6904739307f278c14f94c95bf1 # v5.4.0
|
||||
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
|
||||
with:
|
||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||
- name: Install Go
|
||||
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||
cache: false
|
||||
|
||||
20
.github/workflows/__multi-language-autodetect.yml
generated
vendored
20
.github/workflows/__multi-language-autodetect.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -91,7 +96,9 @@ jobs:
|
||||
- os: macos-latest-xlarge
|
||||
version: nightly-latest
|
||||
name: Multi-language repository
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -99,13 +106,13 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Install .NET
|
||||
uses: actions/setup-dotnet@26b0ec14cb23fa6904739307f278c14f94c95bf1 # v5.4.0
|
||||
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
|
||||
with:
|
||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||
- name: Install Go
|
||||
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||
cache: false
|
||||
@@ -120,7 +127,7 @@ jobs:
|
||||
# We need Python 3.13 for older CLI versions because they are not compatible with Python 3.14 or newer.
|
||||
# See https://github.com/github/codeql-action/pull/3212
|
||||
if: matrix.version != 'nightly-latest' && matrix.version != 'linked'
|
||||
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
||||
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
|
||||
with:
|
||||
python-version: '3.13'
|
||||
|
||||
@@ -191,5 +198,6 @@ jobs:
|
||||
exit 1
|
||||
fi
|
||||
env:
|
||||
CODEQL_ACTION_CLEANUP_TOOLCACHE_BUNDLES: true
|
||||
CODEQL_ACTION_RESOLVE_SUPPORTED_LANGUAGES_USING_CLI: true
|
||||
CODEQL_ACTION_TEST_MODE: true
|
||||
|
||||
13
.github/workflows/__overlay-init-fallback.yml
generated
vendored
13
.github/workflows/__overlay-init-fallback.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -39,7 +44,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: nightly-latest
|
||||
name: Overlay database init fallback
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -47,7 +54,7 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
|
||||
19
.github/workflows/__packaging-codescanning-config-inputs-js.yml
generated
vendored
19
.github/workflows/__packaging-codescanning-config-inputs-js.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -61,7 +66,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: nightly-latest
|
||||
name: 'Packaging: Config and input passed to the CLI'
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -69,18 +76,18 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Install .NET
|
||||
uses: actions/setup-dotnet@26b0ec14cb23fa6904739307f278c14f94c95bf1 # v5.4.0
|
||||
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
|
||||
with:
|
||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||
- name: Install Go
|
||||
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||
cache: false
|
||||
- name: Install Node.js
|
||||
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
|
||||
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
||||
with:
|
||||
node-version: 20.x
|
||||
cache: npm
|
||||
|
||||
19
.github/workflows/__packaging-config-inputs-js.yml
generated
vendored
19
.github/workflows/__packaging-config-inputs-js.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -61,7 +66,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: nightly-latest
|
||||
name: 'Packaging: Config and input'
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -69,18 +76,18 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Install .NET
|
||||
uses: actions/setup-dotnet@26b0ec14cb23fa6904739307f278c14f94c95bf1 # v5.4.0
|
||||
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
|
||||
with:
|
||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||
- name: Install Go
|
||||
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||
cache: false
|
||||
- name: Install Node.js
|
||||
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
|
||||
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
||||
with:
|
||||
node-version: 20.x
|
||||
cache: npm
|
||||
|
||||
19
.github/workflows/__packaging-config-js.yml
generated
vendored
19
.github/workflows/__packaging-config-js.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -61,7 +66,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: nightly-latest
|
||||
name: 'Packaging: Config file'
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -69,18 +76,18 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Install .NET
|
||||
uses: actions/setup-dotnet@26b0ec14cb23fa6904739307f278c14f94c95bf1 # v5.4.0
|
||||
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
|
||||
with:
|
||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||
- name: Install Go
|
||||
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||
cache: false
|
||||
- name: Install Node.js
|
||||
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
|
||||
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
||||
with:
|
||||
node-version: 20.x
|
||||
cache: npm
|
||||
|
||||
19
.github/workflows/__packaging-inputs-js.yml
generated
vendored
19
.github/workflows/__packaging-inputs-js.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -61,7 +66,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: nightly-latest
|
||||
name: 'Packaging: Action input'
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -69,18 +76,18 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Install .NET
|
||||
uses: actions/setup-dotnet@26b0ec14cb23fa6904739307f278c14f94c95bf1 # v5.4.0
|
||||
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
|
||||
with:
|
||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||
- name: Install Go
|
||||
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||
cache: false
|
||||
- name: Install Node.js
|
||||
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
|
||||
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
||||
with:
|
||||
node-version: 20.x
|
||||
cache: npm
|
||||
|
||||
17
.github/workflows/__remote-config.yml
generated
vendored
17
.github/workflows/__remote-config.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -59,7 +64,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: nightly-latest
|
||||
name: Remote config file
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -67,13 +74,13 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Install .NET
|
||||
uses: actions/setup-dotnet@26b0ec14cb23fa6904739307f278c14f94c95bf1 # v5.4.0
|
||||
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
|
||||
with:
|
||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||
- name: Install Go
|
||||
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||
cache: false
|
||||
|
||||
13
.github/workflows/__resolve-environment-action.yml
generated
vendored
13
.github/workflows/__resolve-environment-action.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -41,7 +46,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: nightly-latest
|
||||
name: Resolve environment
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -49,7 +56,7 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
|
||||
15
.github/workflows/__rubocop-multi-language.yml
generated
vendored
15
.github/workflows/__rubocop-multi-language.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -37,7 +42,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: default
|
||||
name: RuboCop multi-language
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -45,7 +52,7 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
@@ -54,7 +61,7 @@ jobs:
|
||||
use-all-platform-bundle: 'false'
|
||||
setup-kotlin: 'true'
|
||||
- name: Set up Ruby
|
||||
uses: ruby/setup-ruby@0dafeac902942906541bc140009cdbf32665b601 # v1.315.0
|
||||
uses: ruby/setup-ruby@95ef2b042f9d7a56d8268cba8559e2842e2ad01b # v1.321.0
|
||||
with:
|
||||
ruby-version: 2.6
|
||||
- name: Install Code Scanning integration
|
||||
|
||||
13
.github/workflows/__ruby.yml
generated
vendored
13
.github/workflows/__ruby.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -47,7 +52,9 @@ jobs:
|
||||
- os: macos-latest
|
||||
version: nightly-latest
|
||||
name: Ruby analysis
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -55,7 +62,7 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
|
||||
13
.github/workflows/__rust.yml
generated
vendored
13
.github/workflows/__rust.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -45,7 +50,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: nightly-latest
|
||||
name: Rust analysis
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -53,7 +60,7 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
|
||||
17
.github/workflows/__split-workflow.yml
generated
vendored
17
.github/workflows/__split-workflow.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -67,7 +72,9 @@ jobs:
|
||||
- os: macos-latest
|
||||
version: nightly-latest
|
||||
name: Split workflow
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -75,13 +82,13 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Install .NET
|
||||
uses: actions/setup-dotnet@26b0ec14cb23fa6904739307f278c14f94c95bf1 # v5.4.0
|
||||
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
|
||||
with:
|
||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||
- name: Install Go
|
||||
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||
cache: false
|
||||
|
||||
30
.github/workflows/__start-proxy.yml
generated
vendored
30
.github/workflows/__start-proxy.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -41,7 +46,9 @@ jobs:
|
||||
- os: windows-latest
|
||||
version: linked
|
||||
name: Start proxy
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -49,7 +56,7 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
@@ -57,15 +64,11 @@ jobs:
|
||||
version: ${{ matrix.version }}
|
||||
use-all-platform-bundle: 'false'
|
||||
setup-kotlin: 'true'
|
||||
- uses: ./../action/init
|
||||
with:
|
||||
languages: csharp
|
||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||
|
||||
- name: Setup proxy for registries
|
||||
id: proxy
|
||||
uses: ./../action/start-proxy
|
||||
with:
|
||||
language: java
|
||||
registry_secrets: |
|
||||
[
|
||||
{
|
||||
@@ -94,5 +97,16 @@ jobs:
|
||||
|| !contains(steps.proxy.outputs.proxy_urls, 'https://repo.maven.apache.org/maven2/')
|
||||
|| !contains(steps.proxy.outputs.proxy_urls, 'https://repo1.maven.org/maven2')
|
||||
run: exit 1
|
||||
|
||||
- uses: ./../action/init
|
||||
env:
|
||||
CODEQL_PROXY_HOST: ${{ steps.proxy.outputs.proxy_host }}
|
||||
CODEQL_PROXY_PORT: ${{ steps.proxy.outputs.proxy_port }}
|
||||
CODEQL_PROXY_CA_CERTIFICATE: ${{ steps.proxy.outputs.proxy_ca_certificate }}
|
||||
with:
|
||||
languages: java
|
||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||
config-file: codeql-action@main:tests/multi-language-repo/.github/codeql/custom-queries.yml
|
||||
env:
|
||||
CODEQL_ACTION_PROXY_API_REQUESTS: 'true'
|
||||
CODEQL_ACTION_TEST_MODE: true
|
||||
|
||||
15
.github/workflows/__submit-sarif-failure.yml
generated
vendored
15
.github/workflows/__submit-sarif-failure.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -41,7 +46,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: nightly-latest
|
||||
name: Submit SARIF after failure
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: write
|
||||
@@ -49,7 +56,7 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
@@ -57,7 +64,7 @@ jobs:
|
||||
version: ${{ matrix.version }}
|
||||
use-all-platform-bundle: 'false'
|
||||
setup-kotlin: 'true'
|
||||
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- uses: ./init
|
||||
with:
|
||||
languages: javascript
|
||||
|
||||
13
.github/workflows/__swift-autobuild.yml
generated
vendored
13
.github/workflows/__swift-autobuild.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -37,7 +42,9 @@ jobs:
|
||||
- os: macos-latest-xlarge
|
||||
version: nightly-latest
|
||||
name: Swift analysis using autobuild
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -45,7 +52,7 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
|
||||
23
.github/workflows/__swift-custom-build.yml
generated
vendored
23
.github/workflows/__swift-custom-build.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -54,14 +59,16 @@ jobs:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
include:
|
||||
- os: macos-latest
|
||||
- os: macos-latest-xlarge
|
||||
version: linked
|
||||
- os: macos-latest
|
||||
- os: macos-latest-xlarge
|
||||
version: default
|
||||
- os: macos-latest
|
||||
- os: macos-latest-xlarge
|
||||
version: nightly-latest
|
||||
name: Swift analysis using a custom build command
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -69,13 +76,13 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Install .NET
|
||||
uses: actions/setup-dotnet@26b0ec14cb23fa6904739307f278c14f94c95bf1 # v5.4.0
|
||||
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
|
||||
with:
|
||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||
- name: Install Go
|
||||
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||
cache: false
|
||||
|
||||
17
.github/workflows/__unset-environment.yml
generated
vendored
17
.github/workflows/__unset-environment.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -59,7 +64,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: nightly-latest
|
||||
name: Test unsetting environment variables
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -67,13 +74,13 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Install .NET
|
||||
uses: actions/setup-dotnet@26b0ec14cb23fa6904739307f278c14f94c95bf1 # v5.4.0
|
||||
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
|
||||
with:
|
||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||
- name: Install Go
|
||||
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||
cache: false
|
||||
|
||||
17
.github/workflows/__upload-ref-sha-input.yml
generated
vendored
17
.github/workflows/__upload-ref-sha-input.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -57,7 +62,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: default
|
||||
name: "Upload-sarif: 'ref' and 'sha' from inputs"
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -65,13 +72,13 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Install .NET
|
||||
uses: actions/setup-dotnet@26b0ec14cb23fa6904739307f278c14f94c95bf1 # v5.4.0
|
||||
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
|
||||
with:
|
||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||
- name: Install Go
|
||||
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||
cache: false
|
||||
|
||||
17
.github/workflows/__upload-sarif.yml
generated
vendored
17
.github/workflows/__upload-sarif.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -64,7 +69,9 @@ jobs:
|
||||
version: default
|
||||
analysis-kinds: code-scanning,code-quality
|
||||
name: Test different uses of `upload-sarif`
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -72,13 +79,13 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Install .NET
|
||||
uses: actions/setup-dotnet@26b0ec14cb23fa6904739307f278c14f94c95bf1 # v5.4.0
|
||||
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
|
||||
with:
|
||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||
- name: Install Go
|
||||
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||
cache: false
|
||||
|
||||
19
.github/workflows/__with-checkout-path.yml
generated
vendored
19
.github/workflows/__with-checkout-path.yml
generated
vendored
@@ -12,7 +12,12 @@ on:
|
||||
branches:
|
||||
- main
|
||||
- releases/v*
|
||||
pull_request: {}
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- labeled
|
||||
merge_group:
|
||||
types:
|
||||
- checks_requested
|
||||
@@ -57,7 +62,9 @@ jobs:
|
||||
- os: ubuntu-latest
|
||||
version: linked
|
||||
name: Use a custom `checkout_path`
|
||||
if: github.triggering_actor != 'dependabot[bot]'
|
||||
if: |-
|
||||
(github.event.action != 'labeled' && github.triggering_actor != 'dependabot[bot]') ||
|
||||
github.event.label.name == 'Rebuild: Unchanged'
|
||||
permissions:
|
||||
contents: read
|
||||
security-events: read
|
||||
@@ -66,13 +73,13 @@ jobs:
|
||||
steps:
|
||||
# This ensures we don't accidentally use the original checkout for any part of the test.
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Install .NET
|
||||
uses: actions/setup-dotnet@26b0ec14cb23fa6904739307f278c14f94c95bf1 # v5.4.0
|
||||
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
|
||||
with:
|
||||
dotnet-version: ${{ inputs.dotnet-version || '9.x' }}
|
||||
- name: Install Go
|
||||
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
||||
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: ${{ inputs.go-version || '>=1.21.0' }}
|
||||
cache: false
|
||||
@@ -91,7 +98,7 @@ jobs:
|
||||
rm -rf ./* .github .git
|
||||
# Check out the actions repo again, but at a different location.
|
||||
# choose an arbitrary SHA so that we can later test that the commit_oid is not from main
|
||||
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
ref: 474bbf07f9247ffe1856c6a0f94aeeb10e7afee6
|
||||
path: x/y/z/some-path
|
||||
|
||||
@@ -23,7 +23,7 @@ jobs:
|
||||
|
||||
steps:
|
||||
- name: Checkout CodeQL Action
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Check Expected Release Files
|
||||
run: |
|
||||
bundle_version="$(cat "./src/defaults.json" | jq -r ".bundleVersion")"
|
||||
|
||||
7
.github/workflows/codeql.yml
vendored
7
.github/workflows/codeql.yml
vendored
@@ -32,7 +32,7 @@ jobs:
|
||||
security-events: read
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Set up default CodeQL bundle
|
||||
id: setup-default
|
||||
uses: ./setup-codeql
|
||||
@@ -84,7 +84,7 @@ jobs:
|
||||
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Initialize CodeQL
|
||||
uses: ./init
|
||||
id: init
|
||||
@@ -113,7 +113,6 @@ jobs:
|
||||
matrix:
|
||||
include:
|
||||
- language: actions
|
||||
- language: python
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
@@ -121,7 +120,7 @@ jobs:
|
||||
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Initialize CodeQL
|
||||
uses: ./init
|
||||
with:
|
||||
|
||||
@@ -54,10 +54,10 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
|
||||
- name: Set up Node.js
|
||||
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
|
||||
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
||||
with:
|
||||
node-version: 24
|
||||
cache: 'npm'
|
||||
|
||||
@@ -48,17 +48,17 @@ jobs:
|
||||
- name: Dump GitHub event
|
||||
run: cat "${GITHUB_EVENT_PATH}"
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
with:
|
||||
version: ${{ matrix.version }}
|
||||
- uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
||||
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: ^1.13.1
|
||||
- name: Install .NET
|
||||
uses: actions/setup-dotnet@26b0ec14cb23fa6904739307f278c14f94c95bf1 # v5.4.0
|
||||
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
|
||||
with:
|
||||
dotnet-version: '9.x'
|
||||
- name: Assert best-effort artifact scan completed
|
||||
|
||||
6
.github/workflows/debug-artifacts-safe.yml
vendored
6
.github/workflows/debug-artifacts-safe.yml
vendored
@@ -44,17 +44,17 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
with:
|
||||
version: ${{ matrix.version }}
|
||||
- uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
||||
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: ^1.13.1
|
||||
- name: Install .NET
|
||||
uses: actions/setup-dotnet@26b0ec14cb23fa6904739307f278c14f94c95bf1 # v5.4.0
|
||||
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
|
||||
with:
|
||||
dotnet-version: '9.x'
|
||||
- name: Assert best-effort artifact scan completed
|
||||
|
||||
12
.github/workflows/post-release-mergeback.yml
vendored
12
.github/workflows/post-release-mergeback.yml
vendored
@@ -44,16 +44,16 @@ jobs:
|
||||
GITHUB_CONTEXT: '${{ toJson(github) }}'
|
||||
run: echo "${GITHUB_CONTEXT}"
|
||||
|
||||
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
fetch-depth: 0 # ensure we have all tags and can push commits
|
||||
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
|
||||
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
||||
with:
|
||||
node-version: 24
|
||||
cache: 'npm'
|
||||
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
||||
with:
|
||||
python-version: '3.12'
|
||||
|
||||
- name: Install JavaScript dependencies
|
||||
run: npm ci
|
||||
|
||||
- name: Update git config
|
||||
run: |
|
||||
@@ -127,7 +127,7 @@ jobs:
|
||||
env:
|
||||
PARTIAL_CHANGELOG: "${{ runner.temp }}/partial_changelog.md"
|
||||
run: |
|
||||
python .github/workflows/script/prepare_changelog.py CHANGELOG.md > $PARTIAL_CHANGELOG
|
||||
npx tsx pr-checks/prepare-changelog.ts --output="$PARTIAL_CHANGELOG"
|
||||
|
||||
echo "::group::Partial CHANGELOG"
|
||||
cat $PARTIAL_CHANGELOG
|
||||
|
||||
44
.github/workflows/pr-checks.yml
vendored
44
.github/workflows/pr-checks.yml
vendored
@@ -39,10 +39,10 @@ jobs:
|
||||
if: runner.os == 'Windows'
|
||||
run: git config --global core.autocrlf false
|
||||
|
||||
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
|
||||
- name: Set up Node.js
|
||||
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
|
||||
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
||||
with:
|
||||
node-version: ${{ matrix.node-version }}
|
||||
cache: 'npm'
|
||||
@@ -67,11 +67,43 @@ jobs:
|
||||
|
||||
- name: Upload sarif
|
||||
uses: ./upload-sarif
|
||||
if: matrix.os == 'ubuntu-latest' && matrix.node-version == 24
|
||||
# The merge queue deletes its `gh-readonly-queue` ref as soon as the queue entry resolves,
|
||||
# so uploading against it races with that deletion. Both the `merge_group` run and the
|
||||
# paired `push` run that the queue branch creates use that ref, so gate on the ref itself
|
||||
# rather than the event. The same results are uploaded by the `pull_request` run and again
|
||||
# by the `push` run on `main`.
|
||||
if: matrix.os == 'ubuntu-latest' && matrix.node-version == 24 && !startsWith(github.ref, 'refs/heads/gh-readonly-queue/')
|
||||
with:
|
||||
sarif_file: eslint.sarif
|
||||
category: eslint
|
||||
|
||||
changetool-tests:
|
||||
name: changetool unit tests
|
||||
permissions:
|
||||
contents: read
|
||||
runs-on: ubuntu-slim
|
||||
timeout-minutes: 10
|
||||
|
||||
concurrency:
|
||||
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
||||
group: pr-checks-changetool-tests-${{ github.ref }}-${{ github.event_name }}
|
||||
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
|
||||
- name: Set up Node.js
|
||||
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
||||
with:
|
||||
node-version: 24
|
||||
cache: 'npm'
|
||||
|
||||
- name: Install dependencies
|
||||
run: npm ci
|
||||
|
||||
- name: Run changetool unit tests
|
||||
run: npm --workspace changetool test
|
||||
|
||||
# These checks do not need to be run as part of the same matrix that we use for the `unit-tests`
|
||||
# job.
|
||||
other-checks:
|
||||
@@ -88,10 +120,10 @@ jobs:
|
||||
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
|
||||
- name: Set up Node.js
|
||||
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
|
||||
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
||||
with:
|
||||
node-version: 24
|
||||
cache: 'npm'
|
||||
@@ -161,7 +193,7 @@ jobs:
|
||||
- name: 'Backport: Check out base ref'
|
||||
id: checkout-base
|
||||
if: ${{ startsWith(github.head_ref, 'backport-') }}
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
ref: ${{ github.base_ref }}
|
||||
|
||||
|
||||
2
.github/workflows/prepare-release.yml
vendored
2
.github/workflows/prepare-release.yml
vendored
@@ -44,7 +44,7 @@ jobs:
|
||||
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
fetch-depth: 0 # Need full history for calculation of diffs
|
||||
|
||||
|
||||
@@ -20,7 +20,7 @@ jobs:
|
||||
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
|
||||
- name: Publish immutable release
|
||||
id: publish
|
||||
|
||||
4
.github/workflows/python312-windows.yml
vendored
4
.github/workflows/python312-windows.yml
vendored
@@ -32,11 +32,11 @@ jobs:
|
||||
runs-on: windows-latest
|
||||
|
||||
steps:
|
||||
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
||||
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
|
||||
with:
|
||||
python-version: 3.12
|
||||
|
||||
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
|
||||
- name: Prepare test
|
||||
uses: ./.github/actions/prepare-test
|
||||
|
||||
4
.github/workflows/query-filters.yml
vendored
4
.github/workflows/query-filters.yml
vendored
@@ -30,10 +30,10 @@ jobs:
|
||||
contents: read # This permission is needed to allow the GitHub Actions workflow to read the contents of the repository.
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
|
||||
- name: Install Node.js
|
||||
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
|
||||
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
||||
with:
|
||||
node-version: 24
|
||||
cache: npm
|
||||
|
||||
17
.github/workflows/rebuild.yml
vendored
17
.github/workflows/rebuild.yml
vendored
@@ -24,16 +24,16 @@ jobs:
|
||||
pull-requests: write # needed to comment on the PR
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
fetch-depth: 0
|
||||
ref: ${{ env.HEAD_REF }}
|
||||
|
||||
- name: Set up Node.js
|
||||
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
|
||||
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
||||
with:
|
||||
node-version: 24
|
||||
cache: 'npm'
|
||||
cache: "npm"
|
||||
|
||||
- name: Remove label
|
||||
if: github.event_name == 'pull_request'
|
||||
@@ -145,3 +145,14 @@ jobs:
|
||||
echo "Pushed a commit to rebuild the Action." \
|
||||
"Please approve running the PR checks." |
|
||||
gh pr comment --body-file - --repo github/codeql-action "$PR_NUMBER"
|
||||
|
||||
- name: "Add 'Rebuild: Unchanged' label"
|
||||
if: >-
|
||||
github.event_name == 'pull_request' &&
|
||||
steps.push.outputs.changes != 'true'
|
||||
env:
|
||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
PR_NUMBER: ${{ github.event.pull_request.number }}
|
||||
run: |
|
||||
gh pr edit --repo github/codeql-action "$PR_NUMBER" \
|
||||
--add-label "Rebuild: Unchanged"
|
||||
|
||||
8
.github/workflows/rollback-release.yml
vendored
8
.github/workflows/rollback-release.yml
vendored
@@ -52,7 +52,7 @@ jobs:
|
||||
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
fetch-depth: 0 # Need full history for calculation of diffs
|
||||
|
||||
@@ -93,7 +93,7 @@ jobs:
|
||||
LATEST_TAG: ${{ needs.prepare.outputs.latest_tag }}
|
||||
VERSION: "${{ needs.prepare.outputs.version }}"
|
||||
run: |
|
||||
python .github/workflows/script/rollback_changelog.py \
|
||||
npx tsx pr-checks/rollback-changelog.ts \
|
||||
--target-version "${ROLLBACK_TAG:1}" \
|
||||
--rollback-version "${LATEST_TAG:1}" \
|
||||
--new-version "$VERSION" > $NEW_CHANGELOG
|
||||
@@ -128,7 +128,9 @@ jobs:
|
||||
NEW_CHANGELOG: "${{ runner.temp }}/new_changelog.md"
|
||||
PARTIAL_CHANGELOG: "${{ runner.temp }}/partial_changelog.md"
|
||||
run: |
|
||||
python .github/workflows/script/prepare_changelog.py $NEW_CHANGELOG > $PARTIAL_CHANGELOG
|
||||
npx tsx pr-checks/prepare-changelog.ts \
|
||||
--changelog="$NEW_CHANGELOG" \
|
||||
--output="$PARTIAL_CHANGELOG"
|
||||
|
||||
echo "::group::Partial CHANGELOG"
|
||||
cat $PARTIAL_CHANGELOG
|
||||
|
||||
23
.github/workflows/script/bundle_changelog.py
vendored
23
.github/workflows/script/bundle_changelog.py
vendored
@@ -1,23 +0,0 @@
|
||||
#!/usr/bin/env python3
|
||||
import os
|
||||
import re
|
||||
|
||||
cli_version = os.environ['CLI_VERSION']
|
||||
|
||||
# The GitHub Release for the new bundle version.
|
||||
bundle_release_url = f"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v{cli_version}"
|
||||
# Get the PR number from the PR URL.
|
||||
pr_number = os.environ['PR_URL'].split('/')[-1]
|
||||
changelog_note = f"- Update default CodeQL bundle version to [{cli_version}]({bundle_release_url}). [#{pr_number}]({os.environ['PR_URL']})"
|
||||
|
||||
# If the "[UNRELEASED]" section starts with "no user facing changes", remove that line.
|
||||
with open('CHANGELOG.md', 'r') as f:
|
||||
changelog = f.read()
|
||||
|
||||
changelog = changelog.replace('## [UNRELEASED]\n\nNo user facing changes.', '## [UNRELEASED]\n')
|
||||
|
||||
# Add the changelog note to the bottom of the "[UNRELEASED]" section.
|
||||
changelog = re.sub(r'\n## (\d+\.\d+\.\d+)', f'{changelog_note}\n\n## \\1', changelog, count=1)
|
||||
|
||||
with open('CHANGELOG.md', 'w') as f:
|
||||
f.write(changelog)
|
||||
35
.github/workflows/script/prepare_changelog.py
vendored
35
.github/workflows/script/prepare_changelog.py
vendored
@@ -1,35 +0,0 @@
|
||||
#!/usr/bin/env python3
|
||||
import os
|
||||
import sys
|
||||
|
||||
EMPTY_CHANGELOG = 'No changes.\n\n'
|
||||
|
||||
# Prepare the changelog for the new release
|
||||
# This function will extract the part of the changelog that
|
||||
# we want to include in the new release.
|
||||
def extract_changelog_snippet(changelog_file):
|
||||
output = ''
|
||||
if (not os.path.exists(changelog_file)):
|
||||
output = EMPTY_CHANGELOG
|
||||
|
||||
else:
|
||||
with open(changelog_file, 'r') as f:
|
||||
lines = f.readlines()
|
||||
|
||||
# Include only the contents of the first section
|
||||
found_first_section = False
|
||||
for line in lines:
|
||||
if line.startswith('## '):
|
||||
if found_first_section:
|
||||
break
|
||||
found_first_section = True
|
||||
elif found_first_section:
|
||||
output += line
|
||||
|
||||
return output.strip()
|
||||
|
||||
|
||||
if len(sys.argv) < 2:
|
||||
raise Exception('Expecting argument: changelog_file')
|
||||
changelog_file = sys.argv[1]
|
||||
print(extract_changelog_snippet(changelog_file))
|
||||
62
.github/workflows/script/rollback_changelog.py
vendored
62
.github/workflows/script/rollback_changelog.py
vendored
@@ -1,62 +0,0 @@
|
||||
import datetime
|
||||
import os
|
||||
import argparse
|
||||
|
||||
EMPTY_CHANGELOG = """# CodeQL Action Changelog
|
||||
|
||||
"""
|
||||
|
||||
def get_today_string():
|
||||
today = datetime.datetime.today()
|
||||
return '{:%d %b %Y}'.format(today)
|
||||
|
||||
# Include everything up to and after the first heading,
|
||||
# but not the first heading and body.
|
||||
def drop_unreleased_section(lines: list[str]):
|
||||
before_first_section = ''
|
||||
after_first_section = ''
|
||||
found_first_section = False
|
||||
skipped_first_section = False
|
||||
|
||||
for i, line in enumerate(lines):
|
||||
if line.startswith('## ') and not found_first_section:
|
||||
found_first_section = True
|
||||
elif line.startswith('## ') and found_first_section:
|
||||
skipped_first_section = True
|
||||
|
||||
if not found_first_section:
|
||||
before_first_section += line
|
||||
if skipped_first_section:
|
||||
after_first_section += line
|
||||
|
||||
return (before_first_section, after_first_section)
|
||||
|
||||
def update_changelog(target_version, rollback_version, new_version):
|
||||
before_first_section = EMPTY_CHANGELOG
|
||||
after_first_section = ''
|
||||
|
||||
if (os.path.exists('CHANGELOG.md')):
|
||||
with open('CHANGELOG.md', 'r') as f:
|
||||
(before_first_section, after_first_section) = drop_unreleased_section(f.readlines())
|
||||
|
||||
newHeader = f'## {new_version} - {get_today_string()}\n'
|
||||
|
||||
print(before_first_section, end="")
|
||||
print(newHeader)
|
||||
print(f"This release rolls back {rollback_version} due to issues with that release. It is identical to {target_version}.\n")
|
||||
print(after_first_section)
|
||||
|
||||
# We expect three version strings as input:
|
||||
#
|
||||
# - target_version: the version that we are re-releasing as `new_version`
|
||||
# - rollback_version: the version that we are rolling back, typically the one that followed `target_version`
|
||||
# - new_version: the new version that we are releasing `target_version` as, typically the one that follows `rollback_version`
|
||||
#
|
||||
# Example: python3 .github/workflows/script/rollback_changelog.py --target-version "1.2.3" --rollback-version "1.2.4" --new-version "1.2.5"
|
||||
parser = argparse.ArgumentParser(description="Update CHANGELOG.md for a rollback release.")
|
||||
parser.add_argument("--target-version", "-t", required=True, help="Version to re-release as new_version.")
|
||||
parser.add_argument("--rollback-version", "-r", required=True, help="Version being rolled back.")
|
||||
parser.add_argument("--new-version", "-n", required=True, help="New version to publish for target_version.")
|
||||
args = parser.parse_args()
|
||||
|
||||
update_changelog(args.target_version, args.rollback_version, args.new_version)
|
||||
4
.github/workflows/test-codeql-bundle-all.yml
vendored
4
.github/workflows/test-codeql-bundle-all.yml
vendored
@@ -38,7 +38,7 @@ jobs:
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- name: Prepare test
|
||||
id: prepare-test
|
||||
uses: ./.github/actions/prepare-test
|
||||
@@ -46,7 +46,7 @@ jobs:
|
||||
version: ${{ matrix.version }}
|
||||
use-all-platform-bundle: true
|
||||
- name: Install .NET
|
||||
uses: actions/setup-dotnet@26b0ec14cb23fa6904739307f278c14f94c95bf1 # v5.4.0
|
||||
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
|
||||
with:
|
||||
dotnet-version: '9.x'
|
||||
- id: init
|
||||
|
||||
11
.github/workflows/update-bundle.yml
vendored
11
.github/workflows/update-bundle.yml
vendored
@@ -33,20 +33,15 @@ jobs:
|
||||
GITHUB_CONTEXT: '${{ toJson(github) }}'
|
||||
run: echo "$GITHUB_CONTEXT"
|
||||
|
||||
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
|
||||
- name: Update git config
|
||||
run: |
|
||||
git config --global user.email "41898282+github-actions[bot]@users.noreply.github.com"
|
||||
git config --global user.name "github-actions[bot]"
|
||||
|
||||
- name: Set up Python
|
||||
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
||||
with:
|
||||
python-version: '3.12'
|
||||
|
||||
- name: Set up Node.js
|
||||
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
|
||||
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
||||
with:
|
||||
node-version: 24
|
||||
cache: 'npm'
|
||||
@@ -120,7 +115,7 @@ jobs:
|
||||
|
||||
- name: Create changelog note
|
||||
run: |
|
||||
python .github/workflows/script/bundle_changelog.py
|
||||
npx tsx pr-checks/bundle-changelog.ts
|
||||
|
||||
- name: Push changelog note
|
||||
run: |
|
||||
|
||||
8
.github/workflows/update-release-branch.yml
vendored
8
.github/workflows/update-release-branch.yml
vendored
@@ -38,7 +38,7 @@ jobs:
|
||||
contents: write # needed to push commits
|
||||
pull-requests: write # needed to create pull request
|
||||
steps:
|
||||
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
fetch-depth: 0 # Need full history for calculation of diffs
|
||||
- uses: ./.github/actions/release-initialise
|
||||
@@ -69,7 +69,7 @@ jobs:
|
||||
run: |
|
||||
echo SOURCE_BRANCH=${REF_NAME}
|
||||
echo TARGET_BRANCH=releases/${MAJOR_VERSION}
|
||||
python .github/update-release-branch.py \
|
||||
npx tsx ./pr-checks/update-release-branch.ts \
|
||||
--repository-nwo ${{ github.repository }} \
|
||||
--source-branch '${{ env.REF_NAME }}' \
|
||||
--target-branch 'releases/${{ env.MAJOR_VERSION }}' \
|
||||
@@ -101,7 +101,7 @@ jobs:
|
||||
private-key: ${{ secrets.AUTOMATION_PRIVATE_KEY }}
|
||||
|
||||
- name: Checkout
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
fetch-depth: 0 # Need full history for calculation of diffs
|
||||
token: ${{ steps.app-token.outputs.token }}
|
||||
@@ -113,7 +113,7 @@ jobs:
|
||||
run: |
|
||||
echo SOURCE_BRANCH=${SOURCE_BRANCH}
|
||||
echo TARGET_BRANCH=${TARGET_BRANCH}
|
||||
python .github/update-release-branch.py \
|
||||
npx tsx ./pr-checks/update-release-branch.ts \
|
||||
--repository-nwo ${{ github.repository }} \
|
||||
--source-branch ${SOURCE_BRANCH} \
|
||||
--target-branch ${TARGET_BRANCH} \
|
||||
|
||||
@@ -22,16 +22,11 @@ jobs:
|
||||
pull-requests: write # needed to create pull request
|
||||
|
||||
steps:
|
||||
- name: Setup Python
|
||||
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
||||
with:
|
||||
python-version: "3.13"
|
||||
|
||||
- name: Checkout CodeQL Action
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
|
||||
- name: Set up Node.js
|
||||
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
|
||||
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
||||
with:
|
||||
node-version: 24
|
||||
cache: 'npm'
|
||||
@@ -40,10 +35,10 @@ jobs:
|
||||
run: npm ci
|
||||
|
||||
- name: Checkout Enterprise Releases
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
repository: github/enterprise-releases
|
||||
token: ${{ secrets.ENTERPRISE_RELEASE_TOKEN }}
|
||||
token: ${{ secrets.CODEQL_CI_ENTERPRISE_RELEASE_PAT }}
|
||||
path: ${{ github.workspace }}/enterprise-releases/
|
||||
sparse-checkout: releases.json
|
||||
|
||||
|
||||
45
CHANGELOG.md
45
CHANGELOG.md
@@ -4,7 +4,52 @@ See the [releases page](https://github.com/github/codeql-action/releases) for th
|
||||
|
||||
## [UNRELEASED]
|
||||
|
||||
No user facing changes.
|
||||
|
||||
## 4.38.0 - 09 Sept 2026
|
||||
|
||||
- On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. [#4124](https://github.com/github/codeql-action/pull/4124)
|
||||
- The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native `linux-arm64` CodeQL bundle when available. [#4072](https://github.com/github/codeql-action/pull/4072)
|
||||
- Update default CodeQL bundle version to [2.27.0](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0). [#4129](https://github.com/github/codeql-action/pull/4129)
|
||||
|
||||
## 4.37.9 - 26 Aug 2026
|
||||
|
||||
- Update default CodeQL bundle version to [2.26.4](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4). [#4106](https://github.com/github/codeql-action/pull/4106)
|
||||
|
||||
## 4.37.8 - 21 Aug 2026
|
||||
|
||||
No user facing changes.
|
||||
|
||||
## 4.37.7 - 13 Aug 2026
|
||||
|
||||
- Update default CodeQL bundle version to [2.26.3](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3). [#4085](https://github.com/github/codeql-action/pull/4085)
|
||||
|
||||
## 4.37.6 - 04 Aug 2026
|
||||
|
||||
- Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to `.github/codeql-config.yml` to align it with the suggested path that is used elsewhere. [#4070](https://github.com/github/codeql-action/pull/4070)
|
||||
|
||||
## 4.37.5 - 03 Aug 2026
|
||||
|
||||
- Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the `init` Action instead of falling back to downloading the bundle before extracting it. [#4061](https://github.com/github/codeql-action/pull/4061)
|
||||
|
||||
## 4.37.4 - 29 Jul 2026
|
||||
|
||||
- This version of the CodeQL Action adds support for the `tools` input for the `codeql-action/init` step to be specified using a `github-codeql-tools` [repository property](https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization). This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to `toolcache` to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for `tools` in the workflow definition always takes precedence unless the value of the repository property starts with `!`. [#4037](https://github.com/github/codeql-action/pull/4037)
|
||||
- Update default CodeQL bundle version to [2.26.2](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2). [#4051](https://github.com/github/codeql-action/pull/4051)
|
||||
|
||||
## 4.37.3 - 22 Jul 2026
|
||||
|
||||
No user facing changes.
|
||||
|
||||
## 4.37.2 - 21 Jul 2026
|
||||
|
||||
- The new address format for the `config-file` input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the `remote=` prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. [#4023](https://github.com/github/codeql-action/pull/4023)
|
||||
- The CodeQL Action can now make use of [configured private registries](https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries) in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. [#4007](https://github.com/github/codeql-action/pull/4007)
|
||||
|
||||
## 4.37.1 - 16 Jul 2026
|
||||
|
||||
- _Upcoming breaking change_: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. [#3956](https://github.com/github/codeql-action/pull/3956)
|
||||
- Update default CodeQL bundle version to [2.26.1](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1). [#4019](https://github.com/github/codeql-action/pull/4019)
|
||||
|
||||
## 4.37.0 - 08 Jul 2026
|
||||
|
||||
|
||||
@@ -60,10 +60,13 @@ Here are a few things you can do that will increase the likelihood of your pull
|
||||
This workflow goes through the pull requests that have been merged to `main` since the last release, creates a changelog, then opens a pull request to merge the changes since the last release into the `releases/v3` release branch.
|
||||
|
||||
You can start a release by triggering this workflow via [workflow dispatch](https://github.com/github/codeql-action/actions/workflows/update-release-branch.yml).
|
||||
1. The workflow run will open a pull request titled "Merge main into releases/v3". Follow the steps on the checklist in the pull request. Once you've checked off all but the last two of these, approve the PR and automerge it.
|
||||
1. The workflow run will open a pull request titled "Merge main into releases/v3". Follow the steps on the checklist in the pull request. Once you've checked off all but the last two of these, approve the PR and automerge it **with a merge commit** (`gh pr merge --merge`).
|
||||
1. When the "Merge main into releases/v3" pull request is merged into the `releases/v3` branch, a mergeback pull request to `main` will be automatically created. This mergeback pull request incorporates the changelog updates into `main`, tags the release using the merge commit of the "Merge main into releases/v3" pull request, and bumps the patch version of the CodeQL Action.
|
||||
1. If a backport to an older major version is required, a pull request targeting that version's branch will also be automatically created.
|
||||
1. Approve the mergeback and backport pull request (if applicable) and automerge them.
|
||||
1. Approve the mergeback and backport pull request (if applicable) and automerge them **with a merge commit** (`gh pr merge --merge`).
|
||||
|
||||
> [!NOTE]
|
||||
> The release, mergeback, and backport pull requests must always be merged with a merge commit — **never squash or rebase**. The mergeback tags the release using the merge commit of the "Merge main into releases/v3" pull request, so squashing or rebasing breaks tagging and the branch linkage the release automation relies on.
|
||||
|
||||
Once the mergeback and backport pull request have been merged, the release is complete.
|
||||
|
||||
|
||||
@@ -209,4 +209,18 @@ export default [
|
||||
],
|
||||
},
|
||||
},
|
||||
{
|
||||
files: ["scripts/changetool/**/*.ts"],
|
||||
|
||||
languageOptions: {
|
||||
parserOptions: {
|
||||
project: "./scripts/changetool/tsconfig.json",
|
||||
},
|
||||
},
|
||||
|
||||
rules: {
|
||||
"no-console": "off",
|
||||
"import/extensions": "off",
|
||||
},
|
||||
},
|
||||
];
|
||||
|
||||
@@ -164,6 +164,13 @@ inputs:
|
||||
[Internal] The ID of the check run, as provided by the Actions runtime environment. Do not set this value manually.
|
||||
default: ${{ job.check_run_id }}
|
||||
required: false
|
||||
job-status:
|
||||
description: >-
|
||||
[Internal] The status of the job, as provided by the Actions runtime environment. This is how the
|
||||
post step learns whether the job as a whole succeeded, failed, or was cancelled. Do not set this
|
||||
value manually.
|
||||
default: ${{ job.status }}
|
||||
required: false
|
||||
outputs:
|
||||
codeql-path:
|
||||
description: The path of the CodeQL binary used for analysis
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"bundleVersion": "codeql-bundle-v2.26.0",
|
||||
"cliVersion": "2.26.0",
|
||||
"priorBundleVersion": "codeql-bundle-v2.25.6",
|
||||
"priorCliVersion": "2.25.6"
|
||||
"bundleVersion": "codeql-bundle-v2.27.0",
|
||||
"cliVersion": "2.27.0",
|
||||
"priorBundleVersion": "codeql-bundle-v2.26.4",
|
||||
"priorCliVersion": "2.26.4"
|
||||
}
|
||||
|
||||
7077
lib/entry-points.js
generated
7077
lib/entry-points.js
generated
File diff suppressed because it is too large
Load Diff
2043
package-lock.json
generated
2043
package-lock.json
generated
File diff suppressed because it is too large
Load Diff
39
package.json
39
package.json
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "codeql",
|
||||
"version": "4.37.1",
|
||||
"version": "4.38.1",
|
||||
"private": true,
|
||||
"description": "CodeQL action",
|
||||
"scripts": {
|
||||
@@ -17,12 +17,13 @@
|
||||
},
|
||||
"license": "MIT",
|
||||
"workspaces": [
|
||||
"pr-checks"
|
||||
"pr-checks",
|
||||
"scripts/changetool"
|
||||
],
|
||||
"dependencies": {
|
||||
"@actions/artifact": "^5.0.3",
|
||||
"@actions/artifact-legacy": "npm:@actions/artifact@^1.1.2",
|
||||
"@actions/cache": "^5.1.0",
|
||||
"@actions/cache": "^5.2.0",
|
||||
"@actions/core": "^2.0.3",
|
||||
"@actions/exec": "^2.0.0",
|
||||
"@actions/github": "^8.0.1",
|
||||
@@ -30,46 +31,50 @@
|
||||
"@actions/http-client": "^3.0.0",
|
||||
"@actions/io": "^2.0.0",
|
||||
"@actions/tool-cache": "^3.0.1",
|
||||
"@octokit/plugin-retry": "^8.1.0",
|
||||
"@octokit/core": "^7.0.8",
|
||||
"@octokit/plugin-paginate-rest": "^15.0.0",
|
||||
"@octokit/plugin-rest-endpoint-methods": "^18.0.0",
|
||||
"@octokit/plugin-retry": "^8.1.1",
|
||||
"archiver": "^8.0.0",
|
||||
"fast-deep-equal": "^3.1.3",
|
||||
"follow-redirects": "^1.16.0",
|
||||
"get-folder-size": "^5.0.0",
|
||||
"https-proxy-agent": "^7.0.6",
|
||||
"js-yaml": "^5.2.0",
|
||||
"js-yaml": "^5.4.1",
|
||||
"jsonschema": "1.5.0",
|
||||
"long": "^5.3.2",
|
||||
"node-forge": "^1.4.0",
|
||||
"semver": "^7.8.5",
|
||||
"uuid": "^14.0.1"
|
||||
"uuid": "^14.0.2",
|
||||
"undici": "^6.28.0"
|
||||
},
|
||||
"devDependencies": {
|
||||
"@ava/typescript": "6.0.0",
|
||||
"@eslint/compat": "^2.1.0",
|
||||
"@microsoft/eslint-formatter-sarif": "^3.1.0",
|
||||
"@octokit/types": "^16.0.0",
|
||||
"@octokit/types": "^17.0.0",
|
||||
"@types/archiver": "^8.0.0",
|
||||
"@types/follow-redirects": "^1.14.4",
|
||||
"@types/js-yaml": "^4.0.9",
|
||||
"@types/node": "^20.19.43",
|
||||
"@types/node-forge": "^1.3.14",
|
||||
"@types/sarif": "^2.1.7",
|
||||
"@types/semver": "^7.7.1",
|
||||
"@types/semver": "^7.8.0",
|
||||
"@types/sinon": "^22.0.0",
|
||||
"ava": "^6.4.1",
|
||||
"esbuild": "^0.28.1",
|
||||
"eslint": "^9.39.4",
|
||||
"esbuild": "^0.28.2",
|
||||
"eslint": "^9.39.5",
|
||||
"eslint-import-resolver-typescript": "^4.4.5",
|
||||
"eslint-plugin-github": "^6.0.0",
|
||||
"eslint-plugin-github": "^6.1.2",
|
||||
"eslint-plugin-import-x": "^4.17.1",
|
||||
"eslint-plugin-jsdoc": "^62.9.0",
|
||||
"eslint-plugin-jsdoc": "^64.3.4",
|
||||
"eslint-plugin-no-async-foreach": "^0.1.1",
|
||||
"glob": "^13.0.6",
|
||||
"globals": "^17.7.0",
|
||||
"nock": "^14.0.16",
|
||||
"sinon": "^22.0.0",
|
||||
"globals": "^17.12.0",
|
||||
"nock": "^14.0.17",
|
||||
"sinon": "^22.1.0",
|
||||
"typescript": "^6.0.3",
|
||||
"typescript-eslint": "^8.62.1"
|
||||
"typescript-eslint": "^8.69.0"
|
||||
},
|
||||
"overrides": {
|
||||
"@actions/tool-cache": {
|
||||
@@ -91,6 +96,6 @@
|
||||
"semver": ">=6.3.1"
|
||||
},
|
||||
"glob": "^13.0.6",
|
||||
"undici": "^6.24.0"
|
||||
"undici": "^6.28.0"
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,10 +1,7 @@
|
||||
import * as githubUtils from "@actions/github/lib/utils";
|
||||
import { type Octokit } from "@octokit/core";
|
||||
import { type PaginateInterface } from "@octokit/plugin-paginate-rest";
|
||||
import { type Api } from "@octokit/plugin-rest-endpoint-methods";
|
||||
|
||||
/** The type of the Octokit client. */
|
||||
export type ApiClient = Octokit & Api & { paginate: PaginateInterface };
|
||||
export type ApiClient = InstanceType<typeof githubUtils.GitHub>;
|
||||
|
||||
/** Constructs an `ApiClient` using `token` for authentication. */
|
||||
export function getApiClient(token: string): ApiClient {
|
||||
|
||||
142
pr-checks/bundle-changelog.test.ts
Normal file
142
pr-checks/bundle-changelog.test.ts
Normal file
@@ -0,0 +1,142 @@
|
||||
/**
|
||||
* Tests for `bundle-changelog.ts`.
|
||||
*/
|
||||
|
||||
import * as assert from "node:assert/strict";
|
||||
import * as fs from "node:fs";
|
||||
import * as os from "node:os";
|
||||
import * as path from "node:path";
|
||||
import { afterEach, beforeEach, describe, it } from "node:test";
|
||||
|
||||
import {
|
||||
CLI_VERSION_ENV_VAR,
|
||||
getCLIVersion,
|
||||
getPRNumber,
|
||||
getPRUrl,
|
||||
PR_URL_ENV_VAR,
|
||||
updateChangelog,
|
||||
} from "./bundle-changelog";
|
||||
import {
|
||||
EMPTY_CHANGELOG,
|
||||
NO_CHANGES_STR,
|
||||
UNRELEASED_PLACEHOLDER,
|
||||
} from "./changelog";
|
||||
|
||||
let testDir: string;
|
||||
|
||||
beforeEach(() => {
|
||||
// Set up a temporary directory for testing
|
||||
testDir = fs.mkdtempSync(path.join(os.tmpdir(), "bundle-changelog-test-"));
|
||||
});
|
||||
|
||||
afterEach(() => {
|
||||
/** Clean up temporary directories. */
|
||||
fs.rmSync(testDir, { recursive: true, force: true });
|
||||
});
|
||||
|
||||
describe("getCLIVersion", async () => {
|
||||
await it("throws if the environment variable is not set", async () => {
|
||||
delete process.env[CLI_VERSION_ENV_VAR];
|
||||
assert.throws(() => getCLIVersion());
|
||||
});
|
||||
|
||||
await it("throws if the environment variable is empty", async () => {
|
||||
process.env[CLI_VERSION_ENV_VAR] = " ";
|
||||
assert.throws(() => getCLIVersion());
|
||||
});
|
||||
|
||||
await it("returns value of the environment variable if set", async () => {
|
||||
const testValue = "1.2.3";
|
||||
process.env[CLI_VERSION_ENV_VAR] = testValue;
|
||||
assert.deepEqual(getCLIVersion(), testValue);
|
||||
});
|
||||
});
|
||||
|
||||
const testPrUrl = "https://github.com/github/codeql-action/pulls/42";
|
||||
|
||||
describe("getPRUrl", async () => {
|
||||
await it("throws if the environment variable is not set", async () => {
|
||||
delete process.env[PR_URL_ENV_VAR];
|
||||
assert.throws(() => getPRUrl());
|
||||
});
|
||||
|
||||
await it("throws if the environment variable is empty", async () => {
|
||||
process.env[PR_URL_ENV_VAR] = " ";
|
||||
assert.throws(() => getPRUrl());
|
||||
});
|
||||
|
||||
await it("returns value of the environment variable if set", async () => {
|
||||
process.env[PR_URL_ENV_VAR] = testPrUrl;
|
||||
assert.deepEqual(getPRUrl(), testPrUrl);
|
||||
});
|
||||
});
|
||||
|
||||
describe("getPRNumber", async () => {
|
||||
await it("throws if the last part of the input is not a number", async () => {
|
||||
assert.throws(() => getPRNumber(`${testPrUrl}/foo`));
|
||||
});
|
||||
|
||||
await it("throws if the last part of the input is not a positive number", async () => {
|
||||
assert.throws(() => getPRNumber(`${testPrUrl}/-100`));
|
||||
});
|
||||
|
||||
await it("returns the PR number from an URL", async () => {
|
||||
assert.equal(getPRNumber(testPrUrl), 42);
|
||||
});
|
||||
});
|
||||
|
||||
const testChangelog = `${EMPTY_CHANGELOG.trimEnd()}
|
||||
|
||||
## 4.23.7
|
||||
|
||||
- Other change
|
||||
|
||||
## 4.23.6
|
||||
|
||||
${NO_CHANGES_STR}`;
|
||||
|
||||
const expectedChangelog = `# CodeQL Action Changelog
|
||||
|
||||
## ${UNRELEASED_PLACEHOLDER}
|
||||
|
||||
- Update default CodeQL bundle version to
|
||||
|
||||
## 4.23.7
|
||||
|
||||
- Other change
|
||||
|
||||
## 4.23.6
|
||||
|
||||
${NO_CHANGES_STR}`;
|
||||
|
||||
describe("updateChangelog", async () => {
|
||||
await it("removes `NO_CHANGES_STR` if present in [UNRELEASED] section", async () => {
|
||||
const result = updateChangelog(EMPTY_CHANGELOG, "");
|
||||
assert.ok(!result.includes(NO_CHANGES_STR.trim()));
|
||||
});
|
||||
|
||||
await it("doesn't remove `NO_CHANGES_STR` if present in versioned section", async () => {
|
||||
const result = updateChangelog(
|
||||
EMPTY_CHANGELOG.replace(UNRELEASED_PLACEHOLDER, "1.2.3"),
|
||||
"",
|
||||
);
|
||||
assert.ok(result.includes(NO_CHANGES_STR.trim()));
|
||||
});
|
||||
|
||||
await it("throws if there are no sections", async () => {
|
||||
assert.throws(() => {
|
||||
updateChangelog(
|
||||
"# CodeQL Action Changelog",
|
||||
"- Update default CodeQL bundle version to",
|
||||
);
|
||||
});
|
||||
});
|
||||
|
||||
await it("adds note at the end of the first section", async () => {
|
||||
const result = updateChangelog(
|
||||
testChangelog,
|
||||
"- Update default CodeQL bundle version to",
|
||||
);
|
||||
assert.deepEqual(result, expectedChangelog);
|
||||
});
|
||||
});
|
||||
127
pr-checks/bundle-changelog.ts
Executable file
127
pr-checks/bundle-changelog.ts
Executable file
@@ -0,0 +1,127 @@
|
||||
#!/usr/bin/env npx tsx
|
||||
|
||||
/**
|
||||
* Updates the changelog with a change note for an updated CodeQL CLI bundle.
|
||||
*/
|
||||
|
||||
import * as fs from "node:fs";
|
||||
|
||||
import {
|
||||
parseChangelog,
|
||||
renderChangelog,
|
||||
UNRELEASED_PLACEHOLDER,
|
||||
} from "./changelog";
|
||||
import { CHANGELOG_FILE, CLI_BUNDLE_RELEASE_URL_PREFIX } from "./config";
|
||||
import { getErrorMessage } from "./util";
|
||||
|
||||
export const CLI_VERSION_ENV_VAR = "CLI_VERSION";
|
||||
export const PR_URL_ENV_VAR = "PR_URL";
|
||||
|
||||
/** Gets the CLI version from the environment. */
|
||||
export function getCLIVersion() {
|
||||
const cliVersion = process.env[CLI_VERSION_ENV_VAR];
|
||||
|
||||
if (cliVersion === undefined || cliVersion.trim() === "") {
|
||||
throw new Error(`No CLI version was set in '${CLI_VERSION_ENV_VAR}'.`);
|
||||
}
|
||||
|
||||
return cliVersion;
|
||||
}
|
||||
|
||||
/** Gets the PR URL from the environment. */
|
||||
export function getPRUrl() {
|
||||
const prUrl = process.env[PR_URL_ENV_VAR];
|
||||
|
||||
if (prUrl === undefined || prUrl.trim() === "") {
|
||||
throw new Error(`No PR URL was set in '${PR_URL_ENV_VAR}'.`);
|
||||
}
|
||||
|
||||
return prUrl;
|
||||
}
|
||||
|
||||
/**
|
||||
* Gets the PR number from something like a PR URL.
|
||||
*/
|
||||
export function getPRNumber(prUrl: string) {
|
||||
const prUrlParts = prUrl.split("/");
|
||||
const prNumberStr = prUrlParts[prUrlParts.length - 1];
|
||||
|
||||
const prNumber = Number.parseInt(prNumberStr, 10);
|
||||
|
||||
if (!Number.isInteger(prNumber) || prNumber <= 0) {
|
||||
throw new Error(
|
||||
`Invalid PR URL '${prUrl}': last part is not a positive number`,
|
||||
);
|
||||
}
|
||||
|
||||
return prNumber;
|
||||
}
|
||||
|
||||
/**
|
||||
* Updates `changelog` by adding `changelogNote` to the first section.
|
||||
*
|
||||
* @param contents The existing changelog contents.
|
||||
* @param changelogNote The note to add to the first section.
|
||||
*/
|
||||
export function updateChangelog(contents: string, changelogNote: string) {
|
||||
// If the "[UNRELEASED]" section starts with "no user facing changes", remove that line.
|
||||
contents = contents.replace(
|
||||
`## ${UNRELEASED_PLACEHOLDER}\n\nNo user facing changes.`,
|
||||
`## ${UNRELEASED_PLACEHOLDER}\n`,
|
||||
);
|
||||
|
||||
const changelog = parseChangelog(contents);
|
||||
|
||||
if (changelog.sections.length === 0) {
|
||||
throw new Error("The changelog contains no existing sections.");
|
||||
}
|
||||
|
||||
// Add the changelog note to the bottom of the first section.
|
||||
const firstSection = changelog.sections[0];
|
||||
const lastLine = firstSection.bodyLines.pop();
|
||||
|
||||
if (lastLine !== undefined && lastLine.trim() !== "") {
|
||||
// We expect the last line to be empty. If it isn't for some reason,
|
||||
// add it back.
|
||||
firstSection.bodyLines.push(lastLine);
|
||||
}
|
||||
|
||||
firstSection.bodyLines.push(changelogNote);
|
||||
|
||||
// If the last line is empty as expected, then add it back in after the new note.
|
||||
if (lastLine?.trim() === "") {
|
||||
firstSection.bodyLines.push(lastLine);
|
||||
}
|
||||
|
||||
return renderChangelog(changelog);
|
||||
}
|
||||
|
||||
function main() {
|
||||
try {
|
||||
const cliVersion = getCLIVersion();
|
||||
const prUrl = getPRUrl();
|
||||
|
||||
// The GitHub Release for the new bundle version.
|
||||
const bundleReleaseUrl = `${CLI_BUNDLE_RELEASE_URL_PREFIX}${cliVersion}`;
|
||||
|
||||
// Get the PR number from the PR URL.
|
||||
const prNumber = getPRNumber(prUrl);
|
||||
const changelogNote = `- Update default CodeQL bundle version to [${cliVersion}](${bundleReleaseUrl}). [#${prNumber}](${prUrl})`;
|
||||
|
||||
let changelog = fs.readFileSync(CHANGELOG_FILE, "utf-8");
|
||||
|
||||
changelog = updateChangelog(changelog, changelogNote);
|
||||
|
||||
fs.writeFileSync(CHANGELOG_FILE, changelog);
|
||||
|
||||
return 0;
|
||||
} catch (err) {
|
||||
console.error(`Failed to bundle changelog: ${getErrorMessage(err)}`);
|
||||
return -1;
|
||||
}
|
||||
}
|
||||
|
||||
// Only call `main` if this script was run directly.
|
||||
if (require.main === module) {
|
||||
process.exit(main());
|
||||
}
|
||||
72
pr-checks/changelog.test.ts
Executable file
72
pr-checks/changelog.test.ts
Executable file
@@ -0,0 +1,72 @@
|
||||
#!/usr/bin/env npx tsx
|
||||
|
||||
/**
|
||||
* Tests for `changelog.ts`.
|
||||
*/
|
||||
|
||||
import * as assert from "node:assert/strict";
|
||||
import * as fs from "node:fs";
|
||||
import { describe, it } from "node:test";
|
||||
|
||||
import {
|
||||
EMPTY_CHANGELOG,
|
||||
getReleaseDateString,
|
||||
parseChangelog,
|
||||
processChangelogForBackports,
|
||||
renderChangelog,
|
||||
setVersionAndDate,
|
||||
} from "./changelog";
|
||||
import { CHANGELOG_FILE } from "./config";
|
||||
|
||||
const testDate = new Date(2026, 7, 14);
|
||||
|
||||
describe("getReleaseDateString", async () => {
|
||||
await it("formats dates as expected", async () => {
|
||||
assert.equal(getReleaseDateString(testDate), "14 Aug 2026");
|
||||
});
|
||||
});
|
||||
|
||||
const emptyChangelogExpected = `# CodeQL Action Changelog
|
||||
|
||||
## 9.99.9 - 14 Aug 2026
|
||||
|
||||
No user facing changes.
|
||||
|
||||
`;
|
||||
|
||||
describe("setVersionAndDate", async () => {
|
||||
await it("replaces the placeholder", async () => {
|
||||
const result = setVersionAndDate("9.99.9", EMPTY_CHANGELOG, testDate);
|
||||
assert.equal(result, emptyChangelogExpected);
|
||||
});
|
||||
});
|
||||
|
||||
describe("parseChangelog + renderChangelog", async () => {
|
||||
await it("renderChangelog(parseChangelog(c)) == c", async () => {
|
||||
const actualChangelog = fs.readFileSync(CHANGELOG_FILE, "utf-8");
|
||||
const roundtrip = renderChangelog(parseChangelog(actualChangelog));
|
||||
assert.deepEqual(roundtrip.split("\n"), actualChangelog.split("\n"));
|
||||
});
|
||||
});
|
||||
|
||||
const testChangelog = `# CodeQL Action Changelog
|
||||
|
||||
## 4.12.3 - 14 Aug 2026
|
||||
|
||||
No user facing changes.
|
||||
`;
|
||||
|
||||
const testChangelogResult: string = `# CodeQL Action Changelog
|
||||
|
||||
## 3.12.3 - 14 Aug 2026
|
||||
|
||||
No user facing changes.
|
||||
`;
|
||||
|
||||
describe("processChangelogForBackports", async () => {
|
||||
await it("replaces major versions", async () => {
|
||||
const result = processChangelogForBackports("4", "3", testChangelog);
|
||||
|
||||
assert.deepEqual(result.split("\n"), testChangelogResult.split("\n"));
|
||||
});
|
||||
});
|
||||
212
pr-checks/changelog.ts
Normal file
212
pr-checks/changelog.ts
Normal file
@@ -0,0 +1,212 @@
|
||||
import * as fs from "node:fs";
|
||||
|
||||
import { CHANGELOG_FILE, DryRunOption } from "./config";
|
||||
|
||||
/** The placeholder in the header for unreleased changes. */
|
||||
export const UNRELEASED_PLACEHOLDER = "[UNRELEASED]";
|
||||
|
||||
/** The default contents for a section in the changelog. */
|
||||
export const NO_CHANGES_STR = "No user facing changes.\n\n";
|
||||
|
||||
/** Placeholder changelog content for a new release. */
|
||||
export const EMPTY_CHANGELOG = `# CodeQL Action Changelog
|
||||
|
||||
## ${UNRELEASED_PLACEHOLDER}
|
||||
|
||||
${NO_CHANGES_STR}`;
|
||||
|
||||
/**
|
||||
* Represents sections in a changelog.
|
||||
*/
|
||||
export interface ChangelogSection {
|
||||
headerLine: string;
|
||||
bodyLines: string[];
|
||||
}
|
||||
|
||||
/**
|
||||
* Represents a changelog.
|
||||
*/
|
||||
export interface Changelog {
|
||||
preamble: string[];
|
||||
sections: ChangelogSection[];
|
||||
}
|
||||
|
||||
/** Returns `date` formatted as `DD Mon YYYY`. */
|
||||
export function getReleaseDateString(today: Date = new Date()): string {
|
||||
return today.toLocaleDateString("en-GB", {
|
||||
day: "2-digit",
|
||||
month: "short",
|
||||
year: "numeric",
|
||||
});
|
||||
}
|
||||
|
||||
export interface OpenChangelogOptions {
|
||||
initChangelog?: boolean;
|
||||
}
|
||||
|
||||
export function withChangelog(
|
||||
transformer: (contents: string) => string,
|
||||
options: DryRunOption & OpenChangelogOptions,
|
||||
): void {
|
||||
let content: string;
|
||||
|
||||
if (options.initChangelog && !fs.existsSync(CHANGELOG_FILE)) {
|
||||
content = EMPTY_CHANGELOG;
|
||||
} else {
|
||||
content = fs.readFileSync(CHANGELOG_FILE, "utf8");
|
||||
}
|
||||
|
||||
if (!options.dryRun) {
|
||||
fs.writeFileSync(CHANGELOG_FILE, transformer(content), "utf8");
|
||||
} else {
|
||||
console.info(`[DRY RUN] Would have written updated changelog.`);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Updates the `[UNRELEASED]` marker in `CHANGELOG.md` with the given version
|
||||
* and today's date.
|
||||
*/
|
||||
export function setVersionAndDate(
|
||||
version: string,
|
||||
content: string,
|
||||
date: Date = new Date(),
|
||||
): string {
|
||||
const versionAndDate = `${version} - ${getReleaseDateString(date)}`;
|
||||
return content.replace(UNRELEASED_PLACEHOLDER, versionAndDate);
|
||||
}
|
||||
|
||||
/**
|
||||
* Parses `content` into a structured representation of a changelog.
|
||||
*
|
||||
* @param content The contents of the changelog file.
|
||||
*/
|
||||
export function parseChangelog(content: string): Changelog {
|
||||
const lines = content.split("\n");
|
||||
let i = 0;
|
||||
|
||||
const preamble: string[] = [];
|
||||
const sections: ChangelogSection[] = [];
|
||||
let currentSection: ChangelogSection | undefined = undefined;
|
||||
|
||||
// Process all lines of the input file.
|
||||
while (i < lines.length) {
|
||||
const line = lines[i];
|
||||
|
||||
// Sections of the changelog start with `## `.
|
||||
if (line.startsWith("## ")) {
|
||||
// We have discovered a new section. If `currentSection` is already defined,
|
||||
// then this marks the end of that section. Push it to the array of sections
|
||||
// in the changelog.
|
||||
if (currentSection !== undefined) {
|
||||
sections.push(currentSection);
|
||||
}
|
||||
|
||||
// Initialise the new section.
|
||||
currentSection = { headerLine: line, bodyLines: [] };
|
||||
} else if (currentSection !== undefined) {
|
||||
// Add lines between the section header and the next to the current section.
|
||||
currentSection.bodyLines.push(line);
|
||||
} else {
|
||||
// This is neither a section header nor are we in a section already,
|
||||
// so this line is part of the preamble.
|
||||
preamble.push(line);
|
||||
}
|
||||
|
||||
i++;
|
||||
}
|
||||
|
||||
// Push the current section to the array of completed sections, if there is
|
||||
// still one unfinished.
|
||||
if (currentSection !== undefined) {
|
||||
sections.push(currentSection);
|
||||
}
|
||||
|
||||
return { preamble, sections };
|
||||
}
|
||||
|
||||
/**
|
||||
* Combines an array of lines into a single string by adding line breaks.
|
||||
*/
|
||||
export function unlines(lines: string[]): string {
|
||||
return `${lines.join("\n")}`;
|
||||
}
|
||||
|
||||
/**
|
||||
* Renders a given changelog to a string.
|
||||
*/
|
||||
export function renderChangelog(changelog: Changelog): string {
|
||||
let result = unlines(changelog.preamble);
|
||||
|
||||
for (const section of changelog.sections) {
|
||||
result += `\n${section.headerLine}\n${unlines(section.bodyLines)}`;
|
||||
}
|
||||
|
||||
return result;
|
||||
}
|
||||
|
||||
/**
|
||||
* Processes changelog entries for a backport, converting version references
|
||||
* from the source major version to the target major version and filtering
|
||||
* entries that only apply to newer versions.
|
||||
*/
|
||||
export function processChangelogForBackports(
|
||||
sourceBranchMajorVersion: string,
|
||||
targetBranchMajorVersion: string,
|
||||
content: string,
|
||||
): string {
|
||||
// Changelog entries can use the following format to indicate
|
||||
// that they only apply to newer versions
|
||||
const someVersionsOnlyRegex = /\[v(\d+)\+ only\]/;
|
||||
|
||||
// Parse the changelog.
|
||||
const changelog = parseChangelog(content);
|
||||
|
||||
if (changelog.sections.length === 0) {
|
||||
throw new Error("Could not find any change sections in CHANGELOG.md");
|
||||
}
|
||||
|
||||
// Filter out changelog entries that only apply to newer versions and
|
||||
// update the section headings with the backport major version for
|
||||
// sections we keep.
|
||||
for (const section of changelog.sections) {
|
||||
// Update the section headings with the backport major version.
|
||||
section.headerLine = section.headerLine.replace(
|
||||
`## ${sourceBranchMajorVersion}`,
|
||||
`## ${targetBranchMajorVersion}`,
|
||||
);
|
||||
|
||||
const filteredEntries: string[] = [];
|
||||
let foundContent = false;
|
||||
|
||||
for (const line of section.bodyLines) {
|
||||
// Skip the entry if `someVersionsOnlyRegex` matches and the major version
|
||||
// of the target branch is smaller than the required version.
|
||||
const match = someVersionsOnlyRegex.exec(line);
|
||||
if (
|
||||
match &&
|
||||
Number.parseInt(targetBranchMajorVersion) < Number.parseInt(match[1])
|
||||
) {
|
||||
continue;
|
||||
}
|
||||
|
||||
// Keep the line.
|
||||
filteredEntries.push(line);
|
||||
|
||||
// Set `foundContent` to `true` if the line is not empty.
|
||||
if (line.trim() !== "") {
|
||||
foundContent = true;
|
||||
}
|
||||
}
|
||||
|
||||
// Update the section with the retained entries.
|
||||
section.bodyLines = filteredEntries;
|
||||
|
||||
// Add an entry if we didn't keep any.
|
||||
if (!foundContent) {
|
||||
section.bodyLines.push(NO_CHANGES_STR.trim());
|
||||
}
|
||||
}
|
||||
|
||||
return renderChangelog(changelog);
|
||||
}
|
||||
@@ -2,7 +2,8 @@ name: "All-platform bundle"
|
||||
description: "Tests using an all-platform CodeQL Bundle"
|
||||
operatingSystems:
|
||||
- ubuntu
|
||||
- macos
|
||||
- os: macos
|
||||
runner-image: macos-latest-xlarge
|
||||
- windows
|
||||
versions:
|
||||
- nightly-latest
|
||||
|
||||
@@ -1,68 +0,0 @@
|
||||
name: "Bundle: Zstandard checks"
|
||||
description: "A Zstandard CodeQL bundle should be extracted on supported operating systems"
|
||||
versions:
|
||||
- linked
|
||||
operatingSystems:
|
||||
- ubuntu
|
||||
- macos
|
||||
- windows
|
||||
steps:
|
||||
- name: Remove CodeQL from toolcache
|
||||
uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0
|
||||
with:
|
||||
script: |
|
||||
const fs = require('fs');
|
||||
const path = require('path');
|
||||
const codeqlPath = path.join(process.env['RUNNER_TOOL_CACHE'], 'CodeQL');
|
||||
if (codeqlPath !== undefined) {
|
||||
fs.rmdirSync(codeqlPath, { recursive: true });
|
||||
}
|
||||
- id: init
|
||||
uses: ./../action/init
|
||||
with:
|
||||
languages: javascript
|
||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||
- uses: ./../action/analyze
|
||||
with:
|
||||
output: ${{ runner.temp }}/results
|
||||
upload-database: false
|
||||
- name: Upload SARIF
|
||||
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
||||
with:
|
||||
name: ${{ matrix.os }}-zstd-bundle.sarif
|
||||
path: ${{ runner.temp }}/results/javascript.sarif
|
||||
retention-days: 7
|
||||
- name: Check diagnostic with expected tools URL appears in SARIF
|
||||
uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0
|
||||
env:
|
||||
SARIF_PATH: ${{ runner.temp }}/results/javascript.sarif
|
||||
with:
|
||||
script: |
|
||||
const fs = require('fs');
|
||||
|
||||
const sarif = JSON.parse(fs.readFileSync(process.env['SARIF_PATH'], 'utf8'));
|
||||
const run = sarif.runs[0];
|
||||
|
||||
const toolExecutionNotifications = run.invocations[0].toolExecutionNotifications;
|
||||
const downloadTelemetryNotifications = toolExecutionNotifications.filter(n =>
|
||||
n.descriptor.id === 'codeql-action/bundle-download-telemetry'
|
||||
);
|
||||
if (downloadTelemetryNotifications.length !== 1) {
|
||||
core.setFailed(
|
||||
'Expected exactly one reporting descriptor in the ' +
|
||||
`'runs[].invocations[].toolExecutionNotifications[]' SARIF property, but found ` +
|
||||
`${downloadTelemetryNotifications.length}. All notification reporting descriptors: ` +
|
||||
`${JSON.stringify(toolExecutionNotifications)}.`
|
||||
);
|
||||
}
|
||||
|
||||
const toolsUrl = downloadTelemetryNotifications[0].properties.attributes.toolsUrl;
|
||||
console.log(`Found tools URL: ${toolsUrl}`);
|
||||
|
||||
const expectedExtension = process.env['RUNNER_OS'] === 'Windows' ? '.tar.gz' : '.tar.zst';
|
||||
|
||||
if (!toolsUrl.endsWith(expectedExtension)) {
|
||||
core.setFailed(
|
||||
`Expected the tools URL to be a ${expectedExtension} file, but found ${toolsUrl}.`
|
||||
);
|
||||
}
|
||||
@@ -5,17 +5,45 @@ versions:
|
||||
- nightly-latest
|
||||
container:
|
||||
image: ubuntu:22.04
|
||||
options: --cap-add=NET_ADMIN
|
||||
services:
|
||||
squid-proxy:
|
||||
image: ubuntu/squid:latest
|
||||
ports:
|
||||
- 3128:3128
|
||||
env:
|
||||
https_proxy: http://squid-proxy:3128
|
||||
CODEQL_ACTION_TOLERATE_MISSING_GIT_VERSION: true
|
||||
steps:
|
||||
- name: Block direct internet access to force proxy usage
|
||||
run: |
|
||||
apt-get update -qq && apt-get install -y -qq iptables >/dev/null 2>&1
|
||||
PROXY_IP=$(getent hosts squid-proxy | awk '{ print $1 }')
|
||||
echo "Squid proxy IP: $PROXY_IP"
|
||||
# Allow all traffic to the proxy container
|
||||
iptables -A OUTPUT -d "$PROXY_IP" -j ACCEPT
|
||||
# Allow DNS resolution
|
||||
iptables -A OUTPUT -p udp --dport 53 -j ACCEPT
|
||||
iptables -A OUTPUT -p tcp --dport 53 -j ACCEPT
|
||||
# Allow loopback
|
||||
iptables -A OUTPUT -o lo -j ACCEPT
|
||||
# Allow already-established connections (from checkout/prepare-test)
|
||||
iptables -A OUTPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
|
||||
# Block all other outbound HTTP and HTTPS, ensuring direct access fails
|
||||
iptables -A OUTPUT -p tcp --dport 80 -j REJECT --reject-with tcp-reset
|
||||
iptables -A OUTPUT -p tcp --dport 443 -j REJECT --reject-with tcp-reset
|
||||
echo "Direct HTTP/HTTPS access is now blocked - all traffic must go through the proxy"
|
||||
|
||||
- name: Set proxy environment variables
|
||||
shell: bash
|
||||
run: |
|
||||
echo "http_proxy=http://squid-proxy:3128" >> $GITHUB_ENV
|
||||
echo "HTTP_PROXY=http://squid-proxy:3128" >> $GITHUB_ENV
|
||||
echo "https_proxy=http://squid-proxy:3128" >> $GITHUB_ENV
|
||||
echo "HTTPS_PROXY=http://squid-proxy:3128" >> $GITHUB_ENV
|
||||
|
||||
- uses: ./../action/init
|
||||
with:
|
||||
languages: javascript
|
||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||
|
||||
- uses: ./../action/analyze
|
||||
|
||||
@@ -12,7 +12,7 @@ steps:
|
||||
languages: go
|
||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||
# Deliberately change Go after the `init` step
|
||||
- uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
||||
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
||||
with:
|
||||
go-version: "1.20"
|
||||
- name: Build code
|
||||
|
||||
@@ -21,8 +21,8 @@ steps:
|
||||
run: |
|
||||
cd "$RUNNER_TEMP/results"
|
||||
actual=$(jq -r '.runs[0].properties.jobRunUuid' javascript.sarif)
|
||||
if [[ "$actual" != "$JOB_RUN_UUID" ]]; then
|
||||
echo "Expected SARIF output to contain job run UUID '$JOB_RUN_UUID', but found '$actual'."
|
||||
if [[ "$actual" != "$CODEQL_ACTION_JOB_RUN_UUID" ]]; then
|
||||
echo "Expected SARIF output to contain job run UUID '$CODEQL_ACTION_JOB_RUN_UUID', but found '$actual'."
|
||||
exit 1
|
||||
else
|
||||
echo "Found job run UUID '$actual'."
|
||||
|
||||
35
pr-checks/checks/linux-arm64.yml
Normal file
35
pr-checks/checks/linux-arm64.yml
Normal file
@@ -0,0 +1,35 @@
|
||||
name: "Linux Arm64"
|
||||
description: "An end-to-end integration test running on a Linux Arm64 runner, checking that the native linux-arm64 CodeQL bundle is downloaded and can analyze interpreted and compiled code"
|
||||
operatingSystems:
|
||||
- os: ubuntu
|
||||
runner-image: ubuntu-24.04-arm
|
||||
# The native linux-arm64 CodeQL bundle is only available in recent CLI releases, so we restrict this
|
||||
# check to `nightly-latest`, which is guaranteed to ship it. Older stable versions do not have an
|
||||
# arm64 asset, and `prepare-test` would resolve an x64 bundle URL for them on this runner.
|
||||
versions:
|
||||
- nightly-latest
|
||||
installGo: true
|
||||
installDotNet: true
|
||||
# The set of languages CodeQL supports on this platform, excluding Swift (macOS only).
|
||||
env:
|
||||
LANGUAGES: cpp,csharp,go,java,javascript,python,ruby
|
||||
steps:
|
||||
- uses: ./../action/init
|
||||
with:
|
||||
languages: ${{ env.LANGUAGES }}
|
||||
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
||||
- name: Build code
|
||||
run: ./build.sh
|
||||
- uses: ./../action/analyze
|
||||
with:
|
||||
upload-database: false
|
||||
- name: Assert databases exist
|
||||
run: |
|
||||
cd "$RUNNER_TEMP/codeql_databases"
|
||||
for lang in ${LANGUAGES//,/ }; do
|
||||
if [[ ! -d "$lang" ]]; then
|
||||
echo "Did not find a database for $lang"
|
||||
exit 1
|
||||
fi
|
||||
echo "Found database for $lang"
|
||||
done
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user