Repository navigation
CodeQL Advanced #6300
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # yaml-language-server: $schema=https://www.schemastore.org/github-workflow.json | |
| --- | |
| name: CodeQL Advanced | |
| on: | |
| workflow_dispatch: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| types: | |
| - opened | |
| - reopened | |
| - synchronize | |
| - ready_for_review | |
| # Revalidate the combined changes when a PR is queued in the merge queue. | |
| # The required check is the always-run `check-codeql` (CodeQL) aggregator job. | |
| merge_group: | |
| branches: [main] | |
| schedule: | |
| # Runs at 05:15, only on Friday | |
| - cron: 15 5 * * 5 | |
| permissions: {} | |
| jobs: | |
| changes: | |
| name: Changes | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 5 | |
| permissions: | |
| contents: read | |
| pull-requests: read | |
| outputs: | |
| matrix: ${{ steps.set-matrix.outputs.matrix }} | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 0 | |
| persist-credentials: false | |
| - name: Filter | |
| id: filter | |
| uses: tj-actions/changed-files@9426d40962ed5378910ee2e21d5f8c6fcbf2dd96 # v47.0.6 | |
| with: | |
| json: true | |
| escape_json: false | |
| files_yaml: | | |
| go: | |
| - "**.go" | |
| - "**.mod" | |
| - "**.sum" | |
| javascript: | |
| - "typespec/**" | |
| actions: | |
| - ".github/workflows/**" | |
| - ".github/actions/**" | |
| - name: Set matrix | |
| id: set-matrix | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| with: | |
| script: | | |
| const { default: script } = await import( | |
| `${process.env.GITHUB_WORKSPACE}/.github/scripts/codeql-matrix.mjs` | |
| ); | |
| await script({ context, github, core }); | |
| env: | |
| INPUT_MODIFIED_KEYS: ${{ toJson(steps.filter.outputs.modified_keys) }} | |
| codeql: | |
| name: Analyze (${{ matrix.language }}) | |
| if: ${{ needs.changes.outputs.matrix != '{"include":[]}' && needs.changes.outputs.matrix != '' }} | |
| runs-on: ${{ (matrix.language == 'swift' && 'macos-15') || 'ubuntu-24.04' }} | |
| needs: changes | |
| timeout-minutes: 30 | |
| permissions: | |
| security-events: write # Needed for Code scanning upload | |
| packages: read # required to fetch internal or private CodeQL packs | |
| actions: read | |
| contents: read | |
| strategy: | |
| fail-fast: false | |
| matrix: ${{ fromJSON(needs.changes.outputs.matrix) }} | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Setup Go | |
| if: matrix.language == 'go' | |
| uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 | |
| with: | |
| go-version-file: go.mod | |
| cache: true | |
| - name: Setup Node | |
| if: matrix.language == 'javascript' | |
| uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version-file: .node-version | |
| - name: Initialize CodeQL | |
| if: ${{ !startsWith(matrix.language, 'custom-') }} | |
| uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 | |
| with: | |
| config-file: .github/configs/.codeql.yml | |
| languages: ${{ matrix.language }} | |
| build-mode: ${{ matrix.build-mode }} | |
| analysis-kinds: code-scanning,code-quality | |
| - name: Build Go | |
| if: matrix.language == 'go' | |
| run: make build | |
| working-directory: ${{ matrix.working-directory }} | |
| - name: Perform GoSec Analysis | |
| if: matrix.language == 'custom-gosec' | |
| uses: securego/gosec@deb54465fea23d19a77f037e11e6589021f8501d # v2.29.0 | |
| with: | |
| args: -no-fail -fmt sarif -out gosec-results.sarif ./... | |
| continue-on-error: true | |
| # Skip the code-scanning upload in the merge queue: the ephemeral | |
| # `refs/heads/gh-readonly-queue/...` ref is rejected by the SARIF upload | |
| # API ("ref not found"). The analysis above still runs as the required gate; | |
| # results are uploaded on `push`/`pull_request` against persistent refs. | |
| - name: Upload GoSec result | |
| if: ${{ always() && github.event_name != 'merge_group' && matrix.language == 'custom-gosec' }} | |
| uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 | |
| with: | |
| category: /language:go/tool:gosec | |
| sarif_file: gosec-results.sarif | |
| wait-for-processing: true | |
| - name: Perform CodeQL Analysis | |
| if: ${{ !startsWith(matrix.language, 'custom-') }} | |
| uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 | |
| id: codeql-analyze | |
| with: | |
| category: /language:${{matrix.language}} | |
| upload: never | |
| output: .codeql-results | |
| # Skip the code-scanning upload in the merge queue: the ephemeral | |
| # `refs/heads/gh-readonly-queue/...` ref is rejected by the SARIF upload | |
| # API ("ref not found"). The analysis above still runs as the required gate; | |
| # results are uploaded on `push`/`pull_request` against persistent refs. | |
| - name: Upload CodeQL result | |
| if: ${{ always() && github.event_name != 'merge_group' && !startsWith(matrix.language, 'custom-') }} | |
| uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 | |
| with: | |
| sarif_file: ${{ format('{0}/{1}.sarif', steps.codeql-analyze.outputs.sarif-output, matrix.language) }} | |
| wait-for-processing: true | |
| # Code quality results land in a separate `<language>.quality.sarif`, which only | |
| # exists for languages that ship quality queries. | |
| - name: Upload CodeQL code quality result | |
| if: >- | |
| ${{ always() && github.event_name != 'merge_group' && | |
| !startsWith(matrix.language, 'custom-') && | |
| hashFiles(format('.codeql-results/{0}.quality.sarif', matrix.language)) != '' }} | |
| uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 | |
| with: | |
| sarif_file: ${{ format('{0}/{1}.quality.sarif', steps.codeql-analyze.outputs.sarif-output, matrix.language) }} | |
| wait-for-processing: true | |
| check-codeql: | |
| if: always() | |
| name: CodeQL | |
| needs: codeql | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 5 | |
| steps: | |
| - name: ✅ OK | |
| if: ${{ !(contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled')) }} | |
| run: exit 0 | |
| - name: 🛑 Failure | |
| if: ${{ contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled') }} | |
| run: exit 1 |