mirror of
https://github.com/github/codeql-action.git
synced 2026-10-03 09:14:58 +00:00
165 lines
5.9 KiB
YAML
Generated
165 lines
5.9 KiB
YAML
Generated
# Warning: This file is generated automatically, and should not be modified.
|
|
# Instead, please modify the template in the pr-checks directory and run:
|
|
# pr-checks/sync.sh
|
|
# to regenerate this file.
|
|
|
|
name: PR Check - Per-language bundles
|
|
env:
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
GO111MODULE: auto
|
|
on:
|
|
push:
|
|
branches:
|
|
- main
|
|
- releases/v*
|
|
pull_request: {}
|
|
merge_group:
|
|
types:
|
|
- checks_requested
|
|
schedule:
|
|
- cron: '0 5 * * *'
|
|
workflow_dispatch:
|
|
inputs: {}
|
|
workflow_call:
|
|
inputs: {}
|
|
defaults:
|
|
run:
|
|
shell: bash
|
|
concurrency:
|
|
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
|
|
group: per-language-bundle-validation-${{github.ref}}
|
|
jobs:
|
|
per-language-bundle-validation:
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
include:
|
|
- language: actions
|
|
os: ubuntu-latest
|
|
version: nightly-latest
|
|
expected-extractors: actions javascript
|
|
- language: cpp
|
|
os: ubuntu-latest
|
|
version: nightly-latest
|
|
build-mode: manual
|
|
build-command: gcc -o main main.c
|
|
- language: csharp
|
|
os: ubuntu-latest
|
|
version: nightly-latest
|
|
build-mode: none
|
|
- language: go
|
|
os: ubuntu-latest
|
|
version: nightly-latest
|
|
build-mode: autobuild
|
|
- language: java
|
|
os: ubuntu-latest
|
|
version: nightly-latest
|
|
build-mode: none
|
|
- language: javascript
|
|
os: ubuntu-latest
|
|
version: nightly-latest
|
|
- language: python
|
|
os: ubuntu-latest
|
|
version: nightly-latest
|
|
- language: ruby
|
|
os: ubuntu-latest
|
|
version: nightly-latest
|
|
- language: rust
|
|
os: ubuntu-latest
|
|
version: nightly-latest
|
|
- language: swift
|
|
os: macos-latest-xlarge
|
|
version: nightly-latest
|
|
build-mode: autobuild
|
|
name: Per-language bundles
|
|
if: github.triggering_actor != 'dependabot[bot]'
|
|
permissions:
|
|
contents: read
|
|
security-events: read
|
|
timeout-minutes: 45
|
|
runs-on: ${{ matrix.os }}
|
|
steps:
|
|
- name: Check out repository
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
- name: Prepare test
|
|
id: prepare-test
|
|
uses: ./.github/actions/prepare-test
|
|
with:
|
|
version: ${{ matrix.version }}
|
|
use-all-platform-bundle: 'false'
|
|
setup-kotlin: 'true'
|
|
- uses: ./../action/init
|
|
id: init
|
|
with:
|
|
languages: ${{ matrix.language }}
|
|
build-mode: ${{ matrix['build-mode'] }}
|
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
|
- name: Check that the bundle contains only the expected extractors
|
|
env:
|
|
CODEQL_PATH: ${{ steps.init.outputs.codeql-path }}
|
|
LANGUAGE: ${{ matrix.language }}
|
|
EXPECTED_EXTRACTORS: ${{ matrix['expected-extractors'] || matrix.language }}
|
|
run: |
|
|
extractors="$("$CODEQL_PATH" resolve languages --format=json | jq -r 'keys[]')"
|
|
echo "Extractors in the bundle:"
|
|
echo "$extractors"
|
|
echo "Expected: $EXPECTED_EXTRACTORS"
|
|
|
|
for expected in $EXPECTED_EXTRACTORS; do
|
|
if ! echo "$extractors" | grep -qx "$expected"; then
|
|
echo "::error::The ${LANGUAGE} bundle does not contain the ${expected} extractor."
|
|
exit 1
|
|
fi
|
|
done
|
|
|
|
# If the bundle contained extractors beyond those the language needs, then it would not
|
|
# have been trimmed, and this job would be silently validating the combined bundle.
|
|
for other in actions cpp csharp go java javascript python ruby rust swift; do
|
|
if echo "$EXPECTED_EXTRACTORS" | grep -qw "$other"; then
|
|
continue
|
|
fi
|
|
if echo "$extractors" | grep -qx "$other"; then
|
|
echo "::error::The ${LANGUAGE} bundle also contains the ${other} extractor, so it is not trimmed."
|
|
exit 1
|
|
fi
|
|
done
|
|
- name: Check that the bundle was not added to the toolcache
|
|
env:
|
|
CODEQL_PATH: ${{ steps.init.outputs.codeql-path }}
|
|
run: |
|
|
# A bundle that is missing most of its extractors must never be left in the toolcache,
|
|
# where a later job analyzing a different language could pick it up. The runner image
|
|
# ships with its own CodeQL in the toolcache, so check where this bundle was extracted to
|
|
# rather than whether the toolcache contains CodeQL at all.
|
|
echo "CodeQL is at $CODEQL_PATH"
|
|
if [[ "$CODEQL_PATH" == "$RUNNER_TOOL_CACHE"/* ]]; then
|
|
echo "::error::The per-language bundle was added to the toolcache at $CODEQL_PATH."
|
|
exit 1
|
|
fi
|
|
if [[ "$CODEQL_PATH" != "$RUNNER_TEMP"/* ]]; then
|
|
echo "::error::Expected the per-language bundle to be extracted under $RUNNER_TEMP, but found it at $CODEQL_PATH."
|
|
exit 1
|
|
fi
|
|
- name: Build code
|
|
if: matrix['build-command']
|
|
run: ${{ matrix['build-command'] }}
|
|
- uses: ./../action/analyze
|
|
id: analysis
|
|
with:
|
|
upload-database: false
|
|
- name: Check that a database was created for the language
|
|
env:
|
|
DB_LOCATIONS: ${{ steps.analysis.outputs.db-locations }}
|
|
LANGUAGE: ${{ matrix.language }}
|
|
run: |
|
|
database="$(echo "$DB_LOCATIONS" | jq -r --arg lang "$LANGUAGE" '.[$lang] // empty')"
|
|
if [ -z "$database" ] || [ ! -d "$database" ]; then
|
|
echo "::error::No CodeQL database was created for ${LANGUAGE}."
|
|
echo "Databases: $DB_LOCATIONS"
|
|
exit 1
|
|
fi
|
|
echo "Created a ${LANGUAGE} database at ${database}."
|
|
env:
|
|
CODEQL_ACTION_PER_LANGUAGE_BUNDLES: true
|
|
CODEQL_ACTION_TEST_MODE: true
|