Skip to content

chore(deps): bump the security group across 2 directories with 2 updates #3937

chore(deps): bump the security group across 2 directories with 2 updates

chore(deps): bump the security group across 2 directories with 2 updates #3937

Workflow file for this run

# yaml-language-server: $schema=https://www.schemastore.org/github-workflow.json
---
name: CodeQL Advanced
on:
workflow_dispatch:
push:
branches: [main]
pull_request:
branches: [main]
types:
- opened
- reopened
- synchronize
- ready_for_review
# Revalidate the combined changes when a PR is queued in the merge queue.
# The required check is the always-run `check-codeql` (CodeQL) aggregator job.
merge_group:
branches: [main]
schedule:
# Runs at 05:15, only on Friday
- cron: 15 5 * * 5
permissions: {}
jobs:
changes:
name: Changes
runs-on: ubuntu-24.04
timeout-minutes: 5
permissions:
contents: read
pull-requests: read
outputs:
matrix: ${{ steps.set-matrix.outputs.matrix }}
steps:
- name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
fetch-depth: 0
persist-credentials: false
- name: Filter
id: filter
uses: tj-actions/changed-files@9426d40962ed5378910ee2e21d5f8c6fcbf2dd96 # v47.0.6
with:
json: true
escape_json: false
files_yaml: |
go:
- "**.go"
- "**.mod"
- "**.sum"
javascript:
- "typespec/**"
actions:
- ".github/workflows/**"
- ".github/actions/**"
- name: Set matrix
id: set-matrix
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
with:
script: |
const { default: script } = await import(
`${process.env.GITHUB_WORKSPACE}/.github/scripts/codeql-matrix.mjs`
);
await script({ context, github, core });
env:
INPUT_MODIFIED_KEYS: ${{ toJson(steps.filter.outputs.modified_keys) }}
codeql:
name: Analyze (${{ matrix.language }})
if: ${{ needs.changes.outputs.matrix != '{"include":[]}' && needs.changes.outputs.matrix != '' }}
runs-on: ${{ (matrix.language == 'swift' && 'macos-15') || 'ubuntu-24.04' }}
needs: changes
timeout-minutes: 30
permissions:
security-events: write # Needed for Code scanning upload
packages: read # required to fetch internal or private CodeQL packs
actions: read
contents: read
strategy:
fail-fast: false
matrix: ${{ fromJSON(needs.changes.outputs.matrix) }}
steps:
- name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false
- name: Setup Go
if: matrix.language == 'go'
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
with:
go-version-file: go.mod
cache: true
- name: Setup Node
if: matrix.language == 'javascript'
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version-file: .node-version
- name: Initialize CodeQL
if: ${{ !startsWith(matrix.language, 'custom-') }}
uses: github/codeql-action/init@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0
with:
config-file: .github/configs/.codeql.yml
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}
- name: Auto build
if: matrix.build-mode == 'autobuild'
uses: github/codeql-action/autobuild@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0
with:
working-directory: ${{ matrix.working-directory }}
- name: Build (${{ matrix.language }})
if: matrix.language == 'go' && matrix.build-mode == 'manual'
run: |
make build
working-directory: ${{ matrix.working-directory }}
- name: Perform GoSec Analysis
if: matrix.language == 'custom-gosec'
uses: securego/gosec@9e6a9843d7a4a6e3e9a8539b02612c8a4aa3f889 # v2.27.1
with:
args: -no-fail -fmt sarif -out gosec-results.sarif ./...
continue-on-error: true
# Skip the code-scanning upload in the merge queue: the ephemeral
# `refs/heads/gh-readonly-queue/...` ref is rejected by the SARIF upload
# API ("ref not found"). The analysis above still runs as the required gate;
# results are uploaded on `push`/`pull_request` against persistent refs.
- name: Upload GoSec result
if: ${{ always() && github.event_name != 'merge_group' && matrix.language == 'custom-gosec' }}
uses: github/codeql-action/upload-sarif@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0
with:
sarif_file: gosec-results.sarif
wait-for-processing: true
- name: Perform CodeQL Analysis
if: ${{ !startsWith(matrix.language, 'custom-') }}
uses: github/codeql-action/analyze@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0
id: codeql-analyze
with:
category: /language:${{matrix.language}}
upload: never
output: .codeql-results
# Skip the code-scanning upload in the merge queue: the ephemeral
# `refs/heads/gh-readonly-queue/...` ref is rejected by the SARIF upload
# API ("ref not found"). The analysis above still runs as the required gate;
# results are uploaded on `push`/`pull_request` against persistent refs.
- name: Upload CodeQL result
if: ${{ always() && github.event_name != 'merge_group' && !startsWith(matrix.language, 'custom-') }}
uses: github/codeql-action/upload-sarif@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0
with:
sarif_file: ${{ format('{0}/{1}.sarif', steps.codeql-analyze.outputs.sarif-output, matrix.language) }}
wait-for-processing: true
check-codeql:
if: always()
name: CodeQL
needs: codeql
runs-on: ubuntu-24.04
timeout-minutes: 5
steps:
- name: ✅ OK
if: ${{ !(contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled')) }}
run: exit 0
- name: 🛑 Failure
if: ${{ contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled') }}
run: exit 1