Repository navigation
Expand file tree
/
Copy pathgenerate-code-scanning-query-lists.yml
More file actions
254 lines (210 loc) · 9.58 KB
/
Copy pathgenerate-code-scanning-query-lists.yml
File metadata and controls
254 lines (210 loc) · 9.58 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
name: Generate code scanning query lists
# Manual CodeQL CLI release runs, about every two weeks, generate query table reusables
# from github/codeql and open a pull request when they change.
on:
workflow_dispatch:
inputs:
SOURCE_BRANCH:
description: 'Branch to pull the source files from in the codeql repo (for example codeql-cli-2.x.x).'
type: string
required: true
default: 'main'
pull_request:
paths:
- .github/workflows/generate-code-scanning-query-lists.yml
- src/codeql-queries/scripts/generate-code-scanning-query-list.ts
- src/codeql-queries/scripts/generate-code-quality-query-list.ts
- .github/actions/install-cocofix/action.yml
permissions:
contents: read
jobs:
generate-security-query-lists:
if: github.repository == 'github/docs-internal'
runs-on: ubuntu-latest
steps:
- name: Checkout repository code
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: ./.github/actions/node-npm-setup
- name: Checkout codeql repo
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
repository: github/codeql
path: codeql
ref: ${{ inputs.SOURCE_BRANCH || 'main' }}
- name: Get the codeql SHA being synced
id: codeql
shell: bash
run: |
cd codeql
OPENAPI_COMMIT_SHA=$(git rev-parse HEAD)
echo "OPENAPI_COMMIT_SHA=$OPENAPI_COMMIT_SHA" >> $GITHUB_OUTPUT
echo "Copied files from github/codeql repo. Commit SHA: $OPENAPI_COMMIT_SHA"
- name: Download CodeQL CLI
# fetch-codeql lives in the checked-out github/codeql repository.
uses: ./codeql/.github/actions/fetch-codeql
- name: Test CodeQL CLI Download
shell: bash
run: codeql --version
# Start the CodeQL CLI server once so later CodeQL commands avoid repeated JVM initialization.
- name: Start CodeQL CLI server in the background
shell: bash
run: |
codeql execute cli-server &
sleep 3
codeql --version
- uses: ./.github/actions/install-cocofix
with:
# The Docs Engineering Bot app has repo-level Packages permission and cannot
# read org-scoped packages, so cocofix installation requires the PAT.
token: ${{ secrets.DOCS_BOT_PAT_BASE }}
- name: Build code scanning security query lists
shell: bash
run: |
for lang in "actions" "cpp" "csharp" "go" "java" "javascript" "python" "ruby" "rust" "swift"; do
echo "Generating code scanning query list for $lang"
npm run generate-code-scanning-query-list -- \
--verbose \
--codeql-path codeql \
--codeql-dir codeql \
-o data/reusables/code-scanning/codeql-query-tables/$lang.md \
$lang
done
- name: Upload security query lists
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0
with:
name: security-query-lists
path: data/reusables/code-scanning/codeql-query-tables/
generate-quality-query-lists:
if: github.repository == 'github/docs-internal'
runs-on: ubuntu-latest
steps:
- name: Checkout repository code
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: ./.github/actions/node-npm-setup
- name: Checkout codeql repo
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
repository: github/codeql
path: codeql
ref: ${{ inputs.SOURCE_BRANCH || 'main' }}
- name: Get the codeql SHA being synced
id: codeql
shell: bash
run: |
cd codeql
OPENAPI_COMMIT_SHA=$(git rev-parse HEAD)
echo "OPENAPI_COMMIT_SHA=$OPENAPI_COMMIT_SHA" >> $GITHUB_OUTPUT
echo "Copied files from github/codeql repo. Commit SHA: $OPENAPI_COMMIT_SHA"
- name: Download CodeQL CLI
# fetch-codeql lives in the checked-out github/codeql repository.
uses: ./codeql/.github/actions/fetch-codeql
- name: Test CodeQL CLI Download
shell: bash
run: codeql --version
# Start the CodeQL CLI server once so later CodeQL commands avoid repeated JVM initialization.
- name: Start CodeQL CLI server in the background
shell: bash
run: |
codeql execute cli-server &
sleep 3
codeql --version
- name: Build code quality query lists
shell: bash
run: |
for lang in "csharp" "go" "java" "javascript" "python" "ruby"; do
echo "Generating code quality query list for $lang"
npm run generate-code-quality-query-list -- \
--verbose \
--codeql-path codeql \
--codeql-dir codeql \
-o data/reusables/code-quality/codeql-query-tables/$lang.md \
$lang
done
- name: Upload quality query lists
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0
with:
name: quality-query-lists
path: data/reusables/code-quality/codeql-query-tables/
create-pull-request:
if: github.repository == 'github/docs-internal'
runs-on: ubuntu-latest
permissions:
contents: write
pull-requests: write
needs: [generate-security-query-lists, generate-quality-query-lists]
steps:
- name: Checkout repository code
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- name: Checkout codeql repo
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
repository: github/codeql
path: codeql
ref: ${{ inputs.SOURCE_BRANCH || 'main' }}
- name: Get the codeql SHA being synced
id: codeql
shell: bash
run: |
cd codeql
OPENAPI_COMMIT_SHA=$(git rev-parse HEAD)
echo "OPENAPI_COMMIT_SHA=$OPENAPI_COMMIT_SHA" >> $GITHUB_OUTPUT
echo "Copied files from github/codeql repo. Commit SHA: $OPENAPI_COMMIT_SHA"
- name: Download security query lists
uses: actions/download-artifact@70fc10c6e5e1ce46ad2ea6f2b72d43f7d47b13c3 # v8.0.0
with:
name: security-query-lists
path: data/reusables/code-scanning/codeql-query-tables/
- name: Download quality query lists
uses: actions/download-artifact@70fc10c6e5e1ce46ad2ea6f2b72d43f7d47b13c3 # v8.0.0
with:
name: quality-query-lists
path: data/reusables/code-quality/codeql-query-tables/
- name: Insight into diff
shell: bash
run: |
git diff
- name: Create pull request
env:
GITHUB_TOKEN: ${{ secrets.DOCS_BOT_PAT_BASE }}
DRY_RUN: ${{ github.event_name == 'pull_request'}}
shell: bash
run: |
# Git status must only report generated query tables, so remove the
# checked-out CodeQL repository.
rm -fr ./codeql
changes=$(git diff --name-only | wc -l)
untracked=$(git status --untracked-files --short | wc -l)
if [[ $changes -eq 0 ]] && [[ $untracked -eq 0 ]]; then
echo "There are no changes to commit after running the generation and conversion scripts. Exiting..."
exit 0
fi
git config --global user.name "docs-bot"
git config --global user.email "77750099+docs-bot@users.noreply.github.com"
branchname=codeql-query-tables-${{ steps.codeql.outputs.OPENAPI_COMMIT_SHA }}
# Query the remote because actions/checkout with fetch-depth 1 omits other remote-tracking branches.
branchExists=$(git ls-remote --heads origin refs/heads/$branchname | wc -l)
# Pull request runs validate generated files without pushing branches.
if [ "$DRY_RUN" = "true" ]; then
echo "Dry-run mode when run in a pull request"
echo "See the 'Insight into diff' step for the changes it would create PR about."
exit 0
fi
if [ $branchExists -ne 0 ]; then
echo "Branch $branchname already exists in the remote repository."
exit 0
else
git checkout -b $branchname
fi
git add data/reusables/code-scanning/codeql-query-tables
git add data/reusables/code-quality/codeql-query-tables
git commit -m "Update CodeQL query tables"
git push -u origin $branchname
echo "Creating pull request..."
gh pr create \
--title "Update CodeQL query tables" \
--repo github/docs-internal \
--label "codeql-query-tables,skip FR board,ready-for-doc-review,workflow-generated" \
--body '👋 humans. This PR updates the **CodeQL query table reusables** with the latest changes in preparation for the next **CodeQL CLI** release. (Synced from codeql@${{ steps.codeql.outputs.OPENAPI_COMMIT_SHA }})
No action is required from the first responder for the Docs content team. This PR is automatically added to the Docs content review board. Any writer can review this by checking that the PR looks sensible. If CI does not pass or other problems arise, contact #technical-content on slack.
When the DRI for the CodeQL CLI release is ready to publish, they will ask us to merge this PR in #docs-content.
_Generated by the [Generate code scanning query lists](${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}) workflow run._'