mirror of
https://github.com/github/codeql-action.git
synced 2026-10-03 17:41:28 +00:00
50 lines
1.8 KiB
YAML
50 lines
1.8 KiB
YAML
name: "Proxy test"
|
|
description: "Tests using a proxy specified by the https_proxy environment variable"
|
|
versions:
|
|
- linked
|
|
- nightly-latest
|
|
container:
|
|
image: ubuntu:22.04
|
|
options: --cap-add=NET_ADMIN
|
|
services:
|
|
squid-proxy:
|
|
image: ubuntu/squid:latest
|
|
ports:
|
|
- 3128:3128
|
|
env:
|
|
CODEQL_ACTION_TOLERATE_MISSING_GIT_VERSION: true
|
|
steps:
|
|
- name: Block direct internet access to force proxy usage
|
|
run: |
|
|
apt-get update -qq && apt-get install -y -qq iptables >/dev/null 2>&1
|
|
PROXY_IP=$(getent hosts squid-proxy | awk '{ print $1 }')
|
|
echo "Squid proxy IP: $PROXY_IP"
|
|
# Allow all traffic to the proxy container
|
|
iptables -A OUTPUT -d "$PROXY_IP" -j ACCEPT
|
|
# Allow DNS resolution
|
|
iptables -A OUTPUT -p udp --dport 53 -j ACCEPT
|
|
iptables -A OUTPUT -p tcp --dport 53 -j ACCEPT
|
|
# Allow loopback
|
|
iptables -A OUTPUT -o lo -j ACCEPT
|
|
# Allow already-established connections (from checkout/prepare-test)
|
|
iptables -A OUTPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
|
|
# Block all other outbound HTTP and HTTPS, ensuring direct access fails
|
|
iptables -A OUTPUT -p tcp --dport 80 -j REJECT --reject-with tcp-reset
|
|
iptables -A OUTPUT -p tcp --dport 443 -j REJECT --reject-with tcp-reset
|
|
echo "Direct HTTP/HTTPS access is now blocked - all traffic must go through the proxy"
|
|
|
|
- name: Set proxy environment variables
|
|
shell: bash
|
|
run: |
|
|
echo "http_proxy=http://squid-proxy:3128" >> $GITHUB_ENV
|
|
echo "HTTP_PROXY=http://squid-proxy:3128" >> $GITHUB_ENV
|
|
echo "https_proxy=http://squid-proxy:3128" >> $GITHUB_ENV
|
|
echo "HTTPS_PROXY=http://squid-proxy:3128" >> $GITHUB_ENV
|
|
|
|
- uses: ./../action/init
|
|
with:
|
|
languages: javascript
|
|
tools: ${{ steps.prepare-test.outputs.tools-url }}
|
|
|
|
- uses: ./../action/analyze
|