Skip to content

CodeQL Advanced

CodeQL Advanced #6300

Workflow file for this run

# yaml-language-server: $schema=https://www.schemastore.org/github-workflow.json
---
name: CodeQL Advanced
on:
workflow_dispatch:
push:
branches: [main]
pull_request:
branches: [main]
types:
- opened
- reopened
- synchronize
- ready_for_review
# Revalidate the combined changes when a PR is queued in the merge queue.
# The required check is the always-run `check-codeql` (CodeQL) aggregator job.
merge_group:
branches: [main]
schedule:
# Runs at 05:15, only on Friday
- cron: 15 5 * * 5
permissions: {}
jobs:
changes:
name: Changes
runs-on: ubuntu-24.04
timeout-minutes: 5
permissions:
contents: read
pull-requests: read
outputs:
matrix: ${{ steps.set-matrix.outputs.matrix }}
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
persist-credentials: false
- name: Filter
id: filter
uses: tj-actions/changed-files@9426d40962ed5378910ee2e21d5f8c6fcbf2dd96 # v47.0.6
with:
json: true
escape_json: false
files_yaml: |
go:
- "**.go"
- "**.mod"
- "**.sum"
javascript:
- "typespec/**"
actions:
- ".github/workflows/**"
- ".github/actions/**"
- name: Set matrix
id: set-matrix
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
with:
script: |
const { default: script } = await import(
`${process.env.GITHUB_WORKSPACE}/.github/scripts/codeql-matrix.mjs`
);
await script({ context, github, core });
env:
INPUT_MODIFIED_KEYS: ${{ toJson(steps.filter.outputs.modified_keys) }}
codeql:
name: Analyze (${{ matrix.language }})
if: ${{ needs.changes.outputs.matrix != '{"include":[]}' && needs.changes.outputs.matrix != '' }}
runs-on: ${{ (matrix.language == 'swift' && 'macos-15') || 'ubuntu-24.04' }}
needs: changes
timeout-minutes: 30
permissions:
security-events: write # Needed for Code scanning upload
packages: read # required to fetch internal or private CodeQL packs
actions: read
contents: read
strategy:
fail-fast: false
matrix: ${{ fromJSON(needs.changes.outputs.matrix) }}
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Setup Go
if: matrix.language == 'go'
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: go.mod
cache: true
- name: Setup Node
if: matrix.language == 'javascript'
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version-file: .node-version
- name: Initialize CodeQL
if: ${{ !startsWith(matrix.language, 'custom-') }}
uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0
with:
config-file: .github/configs/.codeql.yml
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}
analysis-kinds: code-scanning,code-quality
- name: Build Go
if: matrix.language == 'go'
run: make build
working-directory: ${{ matrix.working-directory }}
- name: Perform GoSec Analysis
if: matrix.language == 'custom-gosec'
uses: securego/gosec@deb54465fea23d19a77f037e11e6589021f8501d # v2.29.0
with:
args: -no-fail -fmt sarif -out gosec-results.sarif ./...
continue-on-error: true
# Skip the code-scanning upload in the merge queue: the ephemeral
# `refs/heads/gh-readonly-queue/...` ref is rejected by the SARIF upload
# API ("ref not found"). The analysis above still runs as the required gate;
# results are uploaded on `push`/`pull_request` against persistent refs.
- name: Upload GoSec result
if: ${{ always() && github.event_name != 'merge_group' && matrix.language == 'custom-gosec' }}
uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0
with:
category: /language:go/tool:gosec
sarif_file: gosec-results.sarif
wait-for-processing: true
- name: Perform CodeQL Analysis
if: ${{ !startsWith(matrix.language, 'custom-') }}
uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0
id: codeql-analyze
with:
category: /language:${{matrix.language}}
upload: never
output: .codeql-results
# Skip the code-scanning upload in the merge queue: the ephemeral
# `refs/heads/gh-readonly-queue/...` ref is rejected by the SARIF upload
# API ("ref not found"). The analysis above still runs as the required gate;
# results are uploaded on `push`/`pull_request` against persistent refs.
- name: Upload CodeQL result
if: ${{ always() && github.event_name != 'merge_group' && !startsWith(matrix.language, 'custom-') }}
uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0
with:
sarif_file: ${{ format('{0}/{1}.sarif', steps.codeql-analyze.outputs.sarif-output, matrix.language) }}
wait-for-processing: true
# Code quality results land in a separate `<language>.quality.sarif`, which only
# exists for languages that ship quality queries.
- name: Upload CodeQL code quality result
if: >-
${{ always() && github.event_name != 'merge_group' &&
!startsWith(matrix.language, 'custom-') &&
hashFiles(format('.codeql-results/{0}.quality.sarif', matrix.language)) != '' }}
uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0
with:
sarif_file: ${{ format('{0}/{1}.quality.sarif', steps.codeql-analyze.outputs.sarif-output, matrix.language) }}
wait-for-processing: true
check-codeql:
if: always()
name: CodeQL
needs: codeql
runs-on: ubuntu-24.04
timeout-minutes: 5
steps:
- name: ✅ OK
if: ${{ !(contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled')) }}
run: exit 0
- name: 🛑 Failure
if: ${{ contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled') }}
run: exit 1