-
Notifications
You must be signed in to change notification settings - Fork 12
90 lines (84 loc) · 3.9 KB
/
Copy pathcodeql.yml
File metadata and controls
90 lines (84 loc) · 3.9 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
# CodeQL, on the pull request that introduces the finding.
#
# This repository ran CodeQL through GitHub's **default setup** on a weekly
# schedule: a finding landed on `main`, after merge, up to a week after the
# commit that made it. This runs the same analysis on the pull request that
# introduces it, so the alert is attached to that head commit and is there to
# read before anybody merges.
#
# **This job succeeding does not mean it found nothing.** `analyze` uploads the
# SARIF and exits 0 whatever is in it, so the workflow's status proves the
# analysis ran. What refuses the merge is GitHub's code-scanning merge
# protection, a rule on `main`'s ruleset - a repository setting, like the six
# required status checks beside it. `docs/branching.md` records both, and the
# other one this file needs:
#
# gh api -X DELETE repos/vstorm-co/agenticos/code-scanning/default-setup
#
# Default setup and an advanced workflow cannot both analyse one repository -
# GitHub refuses the advanced upload while default setup is configured - so this
# file **replaces** it rather than joining it.
#
# The weekly full run is kept here on `schedule`, because a query pack updated
# after a merge finds things no pull request could have.
#
# The language list is the one default setup had. `javascript` and `typescript`
# are aliases GitHub resolves to `javascript-typescript`, so they are named once;
# `rust` is the desktop shell (`desktop/src-tauri`), and `actions` is this
# directory, which is what `zizmor` in pre-commit reads from the other side.
name: CodeQL
on:
push:
branches: [main]
pull_request:
schedule:
# Monday 04:17 UTC. Off the hour on purpose: the top of an hour is when every
# cron-scheduled workflow on GitHub queues at once.
- cron: "17 4 * * 1"
# Same rule as `ci.yml`, and for the same reason: a pull request cancels its own
# superseded runs, a push to `main` gets a group of its own so no merge commit
# is left without an analysis.
concurrency:
group: codeql-${{ github.ref }}-${{ github.event_name == 'push' && github.run_id || 'pr' }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
permissions:
contents: read
jobs:
analyze:
name: analyze ${{ matrix.language }}
runs-on: ubuntu-latest
# Measured against default setup's own weekly runs, which finish the Python
# and JavaScript analyses in about six minutes each. Generous enough for a
# cold query-pack download, tight enough to end a stall - the same bargain
# `ci.yml` documents, and `backend/tests/test_codeql_workflow.py` holds the
# ceiling.
timeout-minutes: 20
permissions:
contents: read
# What the analysis upload needs. Declared per job rather than at the top
# so nothing else in this file can write a security event.
security-events: write
strategy:
fail-fast: false
matrix:
language: [actions, javascript-typescript, python, rust]
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Initialize CodeQL
uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
languages: ${{ matrix.language }}
# Every tree here is analysed from source. Naming it rather than
# leaving it to the default keeps a compiled language - `rust`, the
# desktop shell - from asking this job to reproduce its toolchain.
build-mode: none
# `security-extended` over the default pack: this is the analysis a
# client's security review asks about, and the extra queries are the
# ones that find the things a default pack calls style.
queries: security-extended
- name: Perform CodeQL analysis
uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
category: /language:${{ matrix.language }}