chore(deps): bump the security group across 2 directories with 2 updates #3937
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # yaml-language-server: $schema=https://www.schemastore.org/github-workflow.json | |
| --- | |
| name: CodeQL Advanced | |
| on: | |
| workflow_dispatch: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| types: | |
| - opened | |
| - reopened | |
| - synchronize | |
| - ready_for_review | |
| # Revalidate the combined changes when a PR is queued in the merge queue. | |
| # The required check is the always-run `check-codeql` (CodeQL) aggregator job. | |
| merge_group: | |
| branches: [main] | |
| schedule: | |
| # Runs at 05:15, only on Friday | |
| - cron: 15 5 * * 5 | |
| permissions: {} | |
| jobs: | |
| changes: | |
| name: Changes | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 5 | |
| permissions: | |
| contents: read | |
| pull-requests: read | |
| outputs: | |
| matrix: ${{ steps.set-matrix.outputs.matrix }} | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| with: | |
| fetch-depth: 0 | |
| persist-credentials: false | |
| - name: Filter | |
| id: filter | |
| uses: tj-actions/changed-files@9426d40962ed5378910ee2e21d5f8c6fcbf2dd96 # v47.0.6 | |
| with: | |
| json: true | |
| escape_json: false | |
| files_yaml: | | |
| go: | |
| - "**.go" | |
| - "**.mod" | |
| - "**.sum" | |
| javascript: | |
| - "typespec/**" | |
| actions: | |
| - ".github/workflows/**" | |
| - ".github/actions/**" | |
| - name: Set matrix | |
| id: set-matrix | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| with: | |
| script: | | |
| const { default: script } = await import( | |
| `${process.env.GITHUB_WORKSPACE}/.github/scripts/codeql-matrix.mjs` | |
| ); | |
| await script({ context, github, core }); | |
| env: | |
| INPUT_MODIFIED_KEYS: ${{ toJson(steps.filter.outputs.modified_keys) }} | |
| codeql: | |
| name: Analyze (${{ matrix.language }}) | |
| if: ${{ needs.changes.outputs.matrix != '{"include":[]}' && needs.changes.outputs.matrix != '' }} | |
| runs-on: ${{ (matrix.language == 'swift' && 'macos-15') || 'ubuntu-24.04' }} | |
| needs: changes | |
| timeout-minutes: 30 | |
| permissions: | |
| security-events: write # Needed for Code scanning upload | |
| packages: read # required to fetch internal or private CodeQL packs | |
| actions: read | |
| contents: read | |
| strategy: | |
| fail-fast: false | |
| matrix: ${{ fromJSON(needs.changes.outputs.matrix) }} | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| with: | |
| persist-credentials: false | |
| - name: Setup Go | |
| if: matrix.language == 'go' | |
| uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0 | |
| with: | |
| go-version-file: go.mod | |
| cache: true | |
| - name: Setup Node | |
| if: matrix.language == 'javascript' | |
| uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 | |
| with: | |
| node-version-file: .node-version | |
| - name: Initialize CodeQL | |
| if: ${{ !startsWith(matrix.language, 'custom-') }} | |
| uses: github/codeql-action/init@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0 | |
| with: | |
| config-file: .github/configs/.codeql.yml | |
| languages: ${{ matrix.language }} | |
| build-mode: ${{ matrix.build-mode }} | |
| - name: Auto build | |
| if: matrix.build-mode == 'autobuild' | |
| uses: github/codeql-action/autobuild@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0 | |
| with: | |
| working-directory: ${{ matrix.working-directory }} | |
| - name: Build (${{ matrix.language }}) | |
| if: matrix.language == 'go' && matrix.build-mode == 'manual' | |
| run: | | |
| make build | |
| working-directory: ${{ matrix.working-directory }} | |
| - name: Perform GoSec Analysis | |
| if: matrix.language == 'custom-gosec' | |
| uses: securego/gosec@9e6a9843d7a4a6e3e9a8539b02612c8a4aa3f889 # v2.27.1 | |
| with: | |
| args: -no-fail -fmt sarif -out gosec-results.sarif ./... | |
| continue-on-error: true | |
| # Skip the code-scanning upload in the merge queue: the ephemeral | |
| # `refs/heads/gh-readonly-queue/...` ref is rejected by the SARIF upload | |
| # API ("ref not found"). The analysis above still runs as the required gate; | |
| # results are uploaded on `push`/`pull_request` against persistent refs. | |
| - name: Upload GoSec result | |
| if: ${{ always() && github.event_name != 'merge_group' && matrix.language == 'custom-gosec' }} | |
| uses: github/codeql-action/upload-sarif@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0 | |
| with: | |
| sarif_file: gosec-results.sarif | |
| wait-for-processing: true | |
| - name: Perform CodeQL Analysis | |
| if: ${{ !startsWith(matrix.language, 'custom-') }} | |
| uses: github/codeql-action/analyze@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0 | |
| id: codeql-analyze | |
| with: | |
| category: /language:${{matrix.language}} | |
| upload: never | |
| output: .codeql-results | |
| # Skip the code-scanning upload in the merge queue: the ephemeral | |
| # `refs/heads/gh-readonly-queue/...` ref is rejected by the SARIF upload | |
| # API ("ref not found"). The analysis above still runs as the required gate; | |
| # results are uploaded on `push`/`pull_request` against persistent refs. | |
| - name: Upload CodeQL result | |
| if: ${{ always() && github.event_name != 'merge_group' && !startsWith(matrix.language, 'custom-') }} | |
| uses: github/codeql-action/upload-sarif@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0 | |
| with: | |
| sarif_file: ${{ format('{0}/{1}.sarif', steps.codeql-analyze.outputs.sarif-output, matrix.language) }} | |
| wait-for-processing: true | |
| check-codeql: | |
| if: always() | |
| name: CodeQL | |
| needs: codeql | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 5 | |
| steps: | |
| - name: ✅ OK | |
| if: ${{ !(contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled')) }} | |
| run: exit 0 | |
| - name: 🛑 Failure | |
| if: ${{ contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled') }} | |
| run: exit 1 |