Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion .github/scripts/codeql-matrix.sh
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,8 @@

set -euo pipefail

java_build_mode="${1:-autobuild}"

matrix_entries=""

has_files() {
Expand All @@ -22,7 +24,7 @@ if has_files '.github/workflows/*.yml' '.github/workflows/*.yaml'; then
fi

if has_files '*.java'; then
add_entry '{"language":"java-kotlin","build-mode":"autobuild"}'
add_entry "{\"language\":\"java-kotlin\",\"build-mode\":\"$java_build_mode\"}"
fi

if has_files '*.js' '*.jsx' '*.ts' '*.tsx' '*.mjs' '*.cjs' '*.vue' '*.html'; then
Expand Down
98 changes: 95 additions & 3 deletions .github/workflows/codeql-full.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,19 +15,21 @@ jobs:
detect:
name: Detect CodeQL languages
runs-on: ubuntu-latest
env:
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
outputs:
matrix: ${{ steps.matrix.outputs.matrix }}
steps:
- name: Checkout repository
uses: actions/checkout@v4
uses: actions/checkout@v6
with:
fetch-depth: 0

- name: Build matrix
id: matrix
shell: bash
run: |
matrix=$(bash .github/scripts/codeql-matrix.sh)
matrix=$(bash .github/scripts/codeql-matrix.sh manual)
printf 'matrix=%s\n' "$matrix" >> "$GITHUB_OUTPUT"

analyze:
Expand All @@ -40,7 +42,7 @@ jobs:

steps:
- name: Checkout repository
uses: actions/checkout@v4
uses: actions/checkout@v6
with:
fetch-depth: 0

Expand All @@ -63,7 +65,97 @@ jobs:
if: matrix.language == 'java-kotlin'
run: mvn -B clean test-compile -DskipTests -Dcheckstyle.skip=true -Dpmd.skip=true -Dspotbugs.skip=true -Dcpd.skip=true

- name: Prepare CodeQL SARIF directory
shell: bash
run: |
rm -rf codeql-sarif
mkdir -p codeql-sarif

- name: Perform CodeQL Analysis
id: codeql-analysis
uses: github/codeql-action/analyze@v4
with:
output: ${{ github.workspace }}/codeql-sarif
upload: always
category: "/codeql-full:${{ matrix.language }}"

- name: Summarize CodeQL SARIF report
id: sarif-summary
if: always()
shell: bash
run: |
set -euo pipefail

mkdir -p codeql-sarif
report_index="codeql-sarif/scan-files.txt"
sarif_count=0
invalid_sarif=0
violations=0

{
printf 'language=%s\n' '${{ matrix.language }}'
printf 'codeql_output=%s\n' '${{ github.workspace }}/codeql-sarif'
printf '\nGenerated SARIF files:\n'
} > "$report_index"

while IFS= read -r -d '' file; do
sarif_count=$((sarif_count + 1))
result_count=$(jq '[.runs[]?.results[]?] | length' "$file" 2>/dev/null || true)

if [[ "$result_count" =~ ^[0-9]+$ ]]; then
violations=$((violations + result_count))
printf '%s results=%s\n' "$file" "$result_count" >> "$report_index"
else
invalid_sarif=$((invalid_sarif + 1))
printf '%s results=invalid-sarif\n' "$file" >> "$report_index"
fi
done < <(find codeql-sarif -type f -name '*.sarif' -print0)

{
printf '\nSummary:\n'
printf 'sarif_count=%s\n' "$sarif_count"
printf 'invalid_sarif=%s\n' "$invalid_sarif"
printf 'violations=%s\n' "$violations"
} >> "$report_index"

printf 'sarif_count=%s\n' "$sarif_count" >> "$GITHUB_OUTPUT"
printf 'invalid_sarif=%s\n' "$invalid_sarif" >> "$GITHUB_OUTPUT"
printf 'violations=%s\n' "$violations" >> "$GITHUB_OUTPUT"

- name: Upload CodeQL SARIF report
if: always()
uses: actions/upload-artifact@v7
with:
name: codeql-full-sarif-${{ matrix.language }}
path: codeql-sarif
if-no-files-found: error
retention-days: 30

- name: Check CodeQL findings
if: always()
shell: bash
env:
SARIF_COUNT: ${{ steps.sarif-summary.outputs.sarif_count }}
INVALID_SARIF: ${{ steps.sarif-summary.outputs.invalid_sarif }}
VIOLATIONS: ${{ steps.sarif-summary.outputs.violations }}
run: |
sarif_count="${SARIF_COUNT:-0}"
invalid_sarif="${INVALID_SARIF:-0}"
violations="${VIOLATIONS:-0}"

if [[ "$sarif_count" -eq 0 ]]; then
echo "::error::CodeQL did not produce a SARIF report."
exit 1
fi

if [[ "$invalid_sarif" -ne 0 ]]; then
echo "::error::CodeQL produced $invalid_sarif invalid SARIF report(s)."
exit 1
fi

if [[ "$violations" -ne 0 ]]; then
echo "::error::CodeQL found $violations result(s)."
exit 1
fi

echo "CodeQL found no results."
2 changes: 1 addition & 1 deletion .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ jobs:
id: matrix
shell: bash
run: |
matrix=$(bash .github/scripts/codeql-matrix.sh)
matrix=$(bash .github/scripts/codeql-matrix.sh autobuild)
printf 'matrix=%s\n' "$matrix" >> "$GITHUB_OUTPUT"

analyze:
Expand Down
Loading