Files
codeql-action/pr-checks/checks/per-language-bundle.yml
Henry Mercer 8847921389 Look for the bundle we downloaded in the toolcache
The runner image ships with its own copy of CodeQL in the toolcache, so
checking whether the toolcache contains CodeQL at all does not tell us
anything about the bundle this test downloaded.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: d4c7b873-8278-4a36-b67c-6cc5ea3b2316
2026-09-09 12:53:24 +01:00

57 lines
2.5 KiB
YAML

name: "Per-language bundle"
description: "Tests that a CodeQL bundle containing only a single language can analyze that language"
versions:
- linked # Unused: this test pins `tools` to a specific per-language bundle.
# TODO: Remove once per-language bundles ship in a release, so that this check no longer needs to be
# exercised on a feature branch.
extraPushBranches:
- henrymercer/per-language-bundles
steps:
- id: init
uses: ./../action/init
with:
languages: actions
tools: https://github.com/dsp-testing/henrymercer-codeql-cli-binaries/releases/download/codeql-bundle-20260825/codeql-bundle-actions-linux64.tar.zst
- name: Check that the bundle contains only the Actions extractor
env:
CODEQL_PATH: ${{ steps.init.outputs.codeql-path }}
run: |
languages="$("$CODEQL_PATH" resolve languages --format=json | jq -r 'keys[]')"
echo "Extractors in the bundle:"
echo "$languages"
if ! echo "$languages" | grep -qx "actions"; then
echo "::error::The Actions bundle does not contain the Actions extractor."
exit 1
fi
# If the bundle still contained extractors for languages we did not ask for, then it would not
# have been trimmed, and this test would be silently exercising the combined bundle instead.
for language in cpp csharp go java python ruby rust swift; do
if echo "$languages" | grep -qx "$language"; then
echo "::error::The Actions bundle also contains the ${language} extractor, so it is not trimmed."
exit 1
fi
done
- name: Check that the bundle was not added to the toolcache
env:
CODEQL_PATH: ${{ steps.init.outputs.codeql-path }}
run: |
# A bundle that is missing most of its extractors must never be left in the toolcache, where
# a later job analyzing a different language could pick it up.
echo "CodeQL is at $CODEQL_PATH"
if [[ "$CODEQL_PATH" == "$RUNNER_TOOL_CACHE"/* ]]; then
echo "::error::The per-language bundle was added to the toolcache at $CODEQL_PATH."
exit 1
fi
# The runner image ships with its own CodeQL in the toolcache, so look for the version we
# downloaded rather than for CodeQL in general.
cached_version="$RUNNER_TOOL_CACHE/CodeQL/0.0.0-20260825"
if [ -d "$cached_version" ]; then
echo "::error::The per-language bundle was added to the toolcache at $cached_version."
exit 1
fi
- uses: ./../action/analyze
with:
upload-database: false