-
Notifications
You must be signed in to change notification settings - Fork 0
155 lines (144 loc) · 5.83 KB
/
Copy pathcodeql.yml
File metadata and controls
155 lines (144 loc) · 5.83 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
# SPDX-FileCopyrightText: 2026 INDUSTRIA DE DISEÑO TEXTIL S.A. (INDITEX S.A.)
# SPDX-License-Identifier: Apache-2.0
name: CodeQL
on:
push:
branches: [main, main-*, develop, develop-*]
pull_request:
branches: [main, main-*, develop, develop-*]
merge_group:
types: [checks_requested]
schedule:
- cron: '17 4 * * 1'
permissions:
contents: read
concurrency:
group: codeql-${{ github.repository }}-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
env:
WORKING_DIRECTORY: ${{ vars.WORKING_DIRECTORY }}
ASDF_BRANCH_VERSION: '0.18.0'
jobs:
scanning-availability:
name: Resolve code scanning availability
if: >-
github.event_name == 'schedule' ||
(
vars.DEVELOPMENT_FLOW == 'trunk-based-development' &&
(
(github.event_name == 'push' && (github.ref_name == 'main' || startsWith(github.ref_name, 'main-'))) ||
(github.event_name == 'pull_request' && (github.event.pull_request.base.ref == 'main' || startsWith(github.event.pull_request.base.ref, 'main-'))) ||
(github.event_name == 'merge_group' && (github.event.merge_group.base_ref == 'main' || startsWith(github.event.merge_group.base_ref, 'main-')))
)
) ||
(
vars.DEVELOPMENT_FLOW == 'git-flow' &&
(
(github.event_name == 'push' && (github.ref_name == 'develop' || startsWith(github.ref_name, 'develop-'))) ||
(github.event_name == 'pull_request' && (github.event.pull_request.base.ref == 'develop' || startsWith(github.event.pull_request.base.ref, 'develop-'))) ||
(github.event_name == 'merge_group' && (github.event.merge_group.base_ref == 'develop' || startsWith(github.event.merge_group.base_ref, 'develop-')))
)
)
runs-on: ubuntu-24.04
permissions:
contents: read
outputs:
enabled: ${{ steps.resolve.outputs.enabled }}
steps:
- name: Resolve availability
id: resolve
env:
GH_TOKEN: ${{ github.token }}
FORCE_ENABLED: ${{ vars.CODE_SCANNING_ENABLED }}
run: |
set -euo pipefail
visibility="$(gh api "/repos/${GITHUB_REPOSITORY}" --jq '.visibility' 2>/dev/null || echo unknown)"
seat="$(gh api "/repos/${GITHUB_REPOSITORY}" \
--jq '.security_and_analysis.advanced_security.status // "unknown"' 2>/dev/null || echo unknown)"
enabled=false
if [ "${visibility}" = "public" ]; then
enabled=true
elif [ "${seat}" = "enabled" ]; then
enabled=true
elif [ "${FORCE_ENABLED:-}" = "true" ]; then
enabled=true
fi
echo "Code scanning availability: visibility=${visibility} seat=${seat} enabled=${enabled}"
echo "enabled=${enabled}" >> "${GITHUB_OUTPUT}"
analyze:
name: Analyze (${{ matrix.language }})
needs: scanning-availability
if: needs.scanning-availability.outputs.enabled == 'true'
runs-on: ubuntu-24.04
permissions:
actions: read
contents: read
packages: read
security-events: write
strategy:
fail-fast: false
matrix:
include:
- language: actions
build-mode: none
- language: go
build-mode: autobuild
steps:
- name: Check out repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Read governed tool versions
id: tool-versions
if: matrix.language == 'go'
working-directory: ${{ env.WORKING_DIRECTORY }}
shell: bash
run: |
set -euo pipefail
resolved=""
if [[ -f .tool-versions ]]; then
if grep -vE '^[[:space:]]*(#|$)' .tool-versions | grep -qvE '^[a-zA-Z0-9_-]+ [a-zA-Z0-9._+-]+$'; then
echo "::error title=Invalid tool-versions::${WORKING_DIRECTORY}/.tool-versions is malformed."
exit 1
fi
resolved="$(grep -E '^golang ' .tool-versions || true)"
fi
if [[ -z "$resolved" ]]; then
if [[ ! -f go.mod ]]; then
echo "::error title=Missing go toolchain::${WORKING_DIRECTORY} has no golang pin in .tool-versions and no go.mod to derive one from."
exit 1
fi
version="$(sed -nE 's/^toolchain[[:space:]]+go([0-9]+\.[0-9]+(\.[0-9]+)?)[[:space:]]*$/\1/p' go.mod | head -n 1)"
if [[ -z "$version" ]]; then
version="$(sed -nE 's/^go[[:space:]]+([0-9]+\.[0-9]+(\.[0-9]+)?)[[:space:]]*$/\1/p' go.mod | head -n 1)"
fi
if [[ -z "$version" ]]; then
echo "::error title=Missing go toolchain::${WORKING_DIRECTORY}/go.mod declares no usable go version."
exit 1
fi
if [[ "$version" != *.*.* ]]; then
version="${version}.0"
fi
resolved="golang ${version}"
echo "::notice title=Derived go toolchain::Using ${resolved} from ${WORKING_DIRECTORY}/go.mod."
fi
{
echo "tool_versions<<EOF"
echo "$resolved"
echo "EOF"
} >> "$GITHUB_OUTPUT"
- name: Set up asdf-managed Go
if: matrix.language == 'go'
uses: asdf-vm/actions/install@b7bcd026f18772e44fe1026d729e1611cc435d47 # v4.0.1
with:
tool_versions: ${{ steps.tool-versions.outputs.tool_versions }}
asdf_version: ${{ env.ASDF_BRANCH_VERSION }}
- name: Initialize CodeQL
uses: github/codeql-action/init@db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 # v4
with:
build-mode: ${{ matrix.build-mode }}
languages: ${{ matrix.language }}
- name: Perform CodeQL analysis
uses: github/codeql-action/analyze@db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 # v4
with:
category: /language:${{ matrix.language }}