Merge pull request #4168 from github/update-v4.38.2-a6ef2c96f

Merge main into releases/v4
This commit is contained in:
Michael B. Gale
2026-09-24 11:26:28 +01:00
committed by GitHub
28 changed files with 490 additions and 235 deletions
+1 -1
View File
@@ -54,7 +54,7 @@ jobs:
use-all-platform-bundle: 'false'
setup-kotlin: 'true'
- name: Set up Ruby
uses: ruby/setup-ruby@95ef2b042f9d7a56d8268cba8559e2842e2ad01b # v1.321.0
uses: ruby/setup-ruby@984c0c890880bbf811283d6f09c4607c62d210a4 # v1.323.0
with:
ruby-version: 2.6
- name: Install Code Scanning integration
+4
View File
@@ -2,6 +2,10 @@
See the [releases page](https://github.com/github/codeql-action/releases) for the relevant changes to the CodeQL CLI and language packs.
## 4.38.2 - 24 Sept 2026
- Update default CodeQL bundle version to [2.27.1](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1). [#4160](https://github.com/github/codeql-action/pull/4160)
## 4.38.1 - 18 Sept 2026
- The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. [#4146](https://github.com/github/codeql-action/pull/4146)
+4 -4
View File
@@ -1,6 +1,6 @@
{
"bundleVersion": "codeql-bundle-v2.27.0",
"cliVersion": "2.27.0",
"priorBundleVersion": "codeql-bundle-v2.26.4",
"priorCliVersion": "2.26.4"
"bundleVersion": "codeql-bundle-v2.27.1",
"cliVersion": "2.27.1",
"priorBundleVersion": "codeql-bundle-v2.27.0",
"priorCliVersion": "2.27.0"
}
+38 -25
View File
@@ -144779,6 +144779,7 @@ function doubleQuoteWhitespaceOnly(layout) {
function applyForceQuotesOption(layout) {
if (!layout.presenterOptions.forceQuotes) return;
if (layout.isKey || layout.style !== SCALAR_STYLE.PLAIN) return;
if (layout.node.tag !== layout.presenterOptions.schema.defaultScalarTag.tagName) return;
layout.style = layout.node.value.includes("\n") ? SCALAR_STYLE.DOUBLE_QUOTED : _preferredQuotedStyle(layout);
}
function tryLongOrMultilineAsBlock(layout) {
@@ -146167,7 +146168,7 @@ function getDiffRangesJsonFilePath(env = getEnv()) {
return path2.join(getTemporaryDirectory(env), PR_DIFF_RANGE_JSON_FILENAME);
}
function getActionVersion() {
return "4.38.1";
return "4.38.2";
}
function getWorkflowEventName(env = getEnv()) {
return env.getRequired("GITHUB_EVENT_NAME" /* GITHUB_EVENT_NAME */);
@@ -147732,8 +147733,8 @@ var path6 = __toESM(require("path"));
var semver4 = __toESM(require_semver2());
// src/defaults.json
var bundleVersion = "codeql-bundle-v2.27.0";
var cliVersion = "2.27.0";
var bundleVersion = "codeql-bundle-v2.27.1";
var cliVersion = "2.27.1";
// src/overlay/index.ts
var fs5 = __toESM(require("fs"));
@@ -151255,7 +151256,7 @@ async function checkOverlayBaseDatabase(codeql, config, logger, warningPrefix) {
}
return true;
}
async function cleanupAndUploadOverlayBaseDatabaseToCache(codeql, config, logger) {
async function cleanupAndUploadOverlayBaseDatabaseToCache(codeql, config, logger, checkoutPath) {
const overlayDatabaseMode = config.overlayDatabaseMode;
if (overlayDatabaseMode !== "overlay-base" /* OverlayBase */) {
logger.debug(
@@ -151303,7 +151304,6 @@ async function cleanupAndUploadOverlayBaseDatabaseToCache(codeql, config, logger
return false;
}
const codeQlVersion = (await codeql.getVersion()).version;
const checkoutPath = getRequiredInput("checkout_path");
const cacheSaveKey = await getCacheSaveKey(
config,
codeQlVersion,
@@ -153248,6 +153248,7 @@ async function getCodeQLForCmd(logger, cmd, checkVersion) {
"--format=json",
`--language=${language}`,
"--extractor-include-aliases",
"-J-XX:-UsePerfData",
...getExtraOptionsFromEnv(["resolve", "extractor"])
],
{
@@ -153887,7 +153888,7 @@ async function finalizeDatabaseCreation(codeql, features, config, threadsFlag, m
trap_import_duration_ms: Math.round(trapImportTime)
};
}
async function setupDiffInformedQueryRun(logger) {
async function setupDiffInformedQueryRun(logger, checkoutPath) {
return await withGroupAsync(
"Generating diff range extension pack",
async () => {
@@ -153898,7 +153899,6 @@ async function setupDiffInformedQueryRun(logger) {
);
return void 0;
}
const checkoutPath = getRequiredInput("checkout_path");
const packDir = writeDiffRangeDataExtensionPack(
logger,
diffRanges,
@@ -154174,7 +154174,8 @@ async function warnIfGoInstalledAfterInit(config, logger) {
// src/database-upload.ts
var fs18 = __toESM(require("fs"));
async function cleanupAndUploadDatabases(repositoryNwo, codeql, config, apiDetails, features, logger) {
async function cleanupAndUploadDatabases(action, repositoryNwo, codeql, config, apiDetails, checkoutPath) {
const logger = action.logger;
if (getRequiredInput("upload-database") !== "true") {
logger.debug("Database upload disabled in workflow. Skipping upload.");
return [];
@@ -154197,7 +154198,7 @@ async function cleanupAndUploadDatabases(repositoryNwo, codeql, config, apiDetai
logger.debug("Not analyzing default branch. Skipping upload.");
return [];
}
const shouldUploadOverlayBase = config.overlayDatabaseMode === "overlay-base" /* OverlayBase */ && await features.getValue("upload_overlay_db_to_api" /* UploadOverlayDbToApi */, codeql);
const shouldUploadOverlayBase = config.overlayDatabaseMode === "overlay-base" /* OverlayBase */ && await action.features.getValue("upload_overlay_db_to_api" /* UploadOverlayDbToApi */, codeql);
const cleanupLevel = shouldUploadOverlayBase ? "overlay" /* Overlay */ : "clear" /* Clear */;
await withGroupAsync("Cleaning up databases", async () => {
await codeql.databaseCleanupCluster(config, cleanupLevel);
@@ -154210,9 +154211,7 @@ async function cleanupAndUploadDatabases(repositoryNwo, codeql, config, apiDetai
includeDiagnostics: false
});
bundledDbSize = fs18.statSync(bundledDb).size;
const commitOid = await getCommitOid(
getRequiredInput("checkout_path")
);
const commitOid = await getCommitOid(checkoutPath);
const maxAttempts = 4;
let uploadDurationMs;
for (let attempt = 1; attempt <= maxAttempts; attempt++) {
@@ -156547,7 +156546,11 @@ async function runAutobuildIfLegacyGoWorkflow(config, logger) {
);
await runAutobuild(config, "go" /* go */, logger);
}
async function run({ startedAt, logger }) {
async function run({
startedAt,
logger,
actions
}) {
let uploadResults = void 0;
let runStats = void 0;
let config = void 0;
@@ -156613,7 +156616,11 @@ async function run({ startedAt, logger }) {
getOptionalInput("ram") || process.env["CODEQL_RAM"],
logger
);
const diffRangePackDir = await setupDiffInformedQueryRun(logger);
const checkoutPath = actions.getRequiredInput("checkout_path");
const diffRangePackDir = await setupDiffInformedQueryRun(
logger,
checkoutPath
);
await warnIfGoInstalledAfterInit(config, logger);
await runAutobuildIfLegacyGoWorkflow(config, logger);
dbCreationTimings = await runFinalize(
@@ -156653,7 +156660,6 @@ async function run({ startedAt, logger }) {
getOptionalInput("upload")
);
if (runStats) {
const checkoutPath = getRequiredInput("checkout_path");
const category = getOptionalInput("category");
uploadResults = await postProcessAndUploadSarif(
logger,
@@ -156679,14 +156685,19 @@ async function run({ startedAt, logger }) {
} else {
logger.info("Not uploading results");
}
await cleanupAndUploadOverlayBaseDatabaseToCache(codeql, config, logger);
await cleanupAndUploadOverlayBaseDatabaseToCache(
codeql,
config,
logger,
checkoutPath
);
databaseUploadResults = await cleanupAndUploadDatabases(
{ logger, features },
repositoryNwo,
codeql,
config,
apiDetails,
features,
logger
checkoutPath
);
const trapCacheUploadStartTime = import_perf_hooks6.performance.now();
didUploadTrapCaches = await uploadTrapCaches(codeql, config, logger);
@@ -162239,8 +162250,8 @@ async function run3(actionState) {
apiDetails = {
auth: getRequiredInput("token"),
externalRepoAuth: getOptionalInput("external-repository-token"),
url: getRequiredEnvParam("GITHUB_SERVER_URL"),
apiURL: getRequiredEnvParam("GITHUB_API_URL")
url: actionState.env.getRequired("GITHUB_SERVER_URL" /* GITHUB_SERVER_URL */),
apiURL: actionState.env.getRequired("GITHUB_API_URL" /* GITHUB_API_URL */)
};
const gitHubVersion = await getGitHubVersion();
checkGitHubVersionInRange(gitHubVersion, logger);
@@ -162259,7 +162270,7 @@ async function run3(actionState) {
const repositoryProperties = repositoryPropertiesResult.orElse({});
core22.exportVariable("CODEQL_ACTION_INIT_HAS_RUN" /* INIT_ACTION_HAS_RUN */, "true");
sourceRoot = path25.resolve(
getRequiredEnvParam("GITHUB_WORKSPACE"),
actionState.env.getRequired("GITHUB_WORKSPACE" /* GITHUB_WORKSPACE */),
getOptionalInput("source-root") || ""
);
let analysisKinds;
@@ -162355,7 +162366,9 @@ async function run3(actionState) {
repository: repositoryNwo,
tempDir: getTemporaryDirectory(),
codeql,
workspacePath: getRequiredEnvParam("GITHUB_WORKSPACE"),
workspacePath: actionState.env.getRequired(
"GITHUB_WORKSPACE" /* GITHUB_WORKSPACE */
),
sourceRoot,
githubVersion: gitHubVersion,
apiDetails,
@@ -163254,8 +163267,8 @@ async function run6(actionState) {
const apiDetails = {
auth: getRequiredInput("token"),
externalRepoAuth: getOptionalInput("external-repository-token"),
url: getRequiredEnvParam("GITHUB_SERVER_URL"),
apiURL: getRequiredEnvParam("GITHUB_API_URL")
url: actionState.env.getRequired("GITHUB_SERVER_URL" /* GITHUB_SERVER_URL */),
apiURL: actionState.env.getRequired("GITHUB_API_URL" /* GITHUB_API_URL */)
};
const gitHubVersion = await getGitHubVersion();
checkGitHubVersionInRange(gitHubVersion, logger);
@@ -164473,7 +164486,7 @@ tmp/lib/tmp.js:
*)
js-yaml/dist/js-yaml.mjs:
(*! js-yaml 5.4.1 https://github.com/nodeca/js-yaml @license MIT *)
(*! js-yaml 5.4.2 https://github.com/nodeca/js-yaml @license MIT *)
long/index.js:
(**
+21 -15
View File
@@ -1,12 +1,12 @@
{
"name": "codeql",
"version": "4.38.1",
"version": "4.38.2",
"lockfileVersion": 3,
"requires": true,
"packages": {
"": {
"name": "codeql",
"version": "4.38.1",
"version": "4.38.2",
"license": "MIT",
"workspaces": [
"pr-checks"
@@ -31,7 +31,7 @@
"follow-redirects": "^1.16.0",
"get-folder-size": "^5.0.0",
"https-proxy-agent": "^7.0.6",
"js-yaml": "^5.4.1",
"js-yaml": "^5.4.2",
"jsonschema": "1.5.0",
"long": "^5.3.2",
"node-forge": "^1.4.0",
@@ -58,7 +58,7 @@
"eslint-import-resolver-typescript": "^4.4.5",
"eslint-plugin-github": "^6.1.2",
"eslint-plugin-import-x": "^4.17.1",
"eslint-plugin-jsdoc": "^64.3.8",
"eslint-plugin-jsdoc": "^64.5.2",
"eslint-plugin-no-async-foreach": "^0.1.1",
"glob": "^13.0.6",
"globals": "^17.12.0",
@@ -5348,9 +5348,9 @@
}
},
"node_modules/eslint-plugin-jsdoc": {
"version": "64.3.8",
"resolved": "https://registry.npmjs.org/eslint-plugin-jsdoc/-/eslint-plugin-jsdoc-64.3.8.tgz",
"integrity": "sha512-JXLYE2BVfmbqLrrslb9/vg3URg8okW5pMnppM+3EYwvPCbuOiSXGOJWaNK208wDx6xXawkIFGtRYgFgrW23dsg==",
"version": "64.5.2",
"resolved": "https://registry.npmjs.org/eslint-plugin-jsdoc/-/eslint-plugin-jsdoc-64.5.2.tgz",
"integrity": "sha512-GirLf/jpVQ/HSLVT98ztIrJ8GUlWWrrwExkofqzeIjjOxlqFtyqnpkRs30FLwEKh0xHEpgy35CU0qFn0I/Mh9w==",
"dev": true,
"license": "BSD-3-Clause",
"dependencies": {
@@ -5374,7 +5374,13 @@
"node": "^22.22.2 || >=24.15.0"
},
"peerDependencies": {
"eslint": "^7.0.0 || ^8.0.0 || ^9.0.0 || ^10.0.0"
"eslint": "^7.0.0 || ^8.0.0 || ^9.0.0 || ^10.0.0",
"typescript": "*"
},
"peerDependenciesMeta": {
"typescript": {
"optional": true
}
}
},
"node_modules/eslint-plugin-jsdoc/node_modules/debug": {
@@ -7091,9 +7097,9 @@
}
},
"node_modules/js-yaml": {
"version": "5.4.1",
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-5.4.1.tgz",
"integrity": "sha512-28R/k+NAjeuf7+CKlTxWZVExJGwVVLwY06DgEnOMz2gEpfNkDcD7QvyiVPT0xy0XXhU8vHsd4Ot42OOPdJG7dQ==",
"version": "5.4.2",
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-5.4.2.tgz",
"integrity": "sha512-m+aqu+LwO1O6sIopafj8HUVl5aawITwZQe/yHpMCKjaWBaA/d07B/QdMb3529REftiU+RMMHL3Vlsw3hON7vWg==",
"funding": [
{
"type": "github",
@@ -10367,9 +10373,9 @@
}
},
"node_modules/yaml": {
"version": "2.9.0",
"resolved": "https://registry.npmjs.org/yaml/-/yaml-2.9.0.tgz",
"integrity": "sha512-2AvhNX3mb8zd6Zy7INTtSpl1F15HW6Wnqj0srWlkKLcpYl/gMIMJiyuGq2KeI2YFxUPjdlB+3Lc10seMLtL4cA==",
"version": "2.9.1",
"resolved": "https://registry.npmjs.org/yaml/-/yaml-2.9.1.tgz",
"integrity": "sha512-3NxN8+78OdzbT7C/WjGsyfPAtJaN3FNDsWxv7Y7mcDsT/oOmgW8BpyQQFFBnvZE3j9Y2Sdz1ULFLezL7Eb2yFw==",
"license": "ISC",
"bin": {
"yaml": "bin.mjs"
@@ -10460,7 +10466,7 @@
"lite-matter": "^0.1.2",
"mdast-util-from-markdown": "^2.0.3",
"semver": "^7.8.5",
"yaml": "^2.9.0"
"yaml": "^2.9.1"
},
"devDependencies": {
"@types/node": "^20.19.43",
+3 -3
View File
@@ -1,6 +1,6 @@
{
"name": "codeql",
"version": "4.38.1",
"version": "4.38.2",
"private": true,
"description": "CodeQL action",
"scripts": {
@@ -39,7 +39,7 @@
"follow-redirects": "^1.16.0",
"get-folder-size": "^5.0.0",
"https-proxy-agent": "^7.0.6",
"js-yaml": "^5.4.1",
"js-yaml": "^5.4.2",
"jsonschema": "1.5.0",
"long": "^5.3.2",
"node-forge": "^1.4.0",
@@ -66,7 +66,7 @@
"eslint-import-resolver-typescript": "^4.4.5",
"eslint-plugin-github": "^6.1.2",
"eslint-plugin-import-x": "^4.17.1",
"eslint-plugin-jsdoc": "^64.3.8",
"eslint-plugin-jsdoc": "^64.5.2",
"eslint-plugin-no-async-foreach": "^0.1.1",
"glob": "^13.0.6",
"globals": "^17.12.0",
+2 -2
View File
@@ -112,7 +112,7 @@ ${NO_CHANGES_STR}`;
describe("updateChangelog", async () => {
await it("removes `NO_CHANGES_STR` if present in [UNRELEASED] section", async () => {
const result = updateChangelog(EMPTY_CHANGELOG, "");
assert.ok(!result.includes(NO_CHANGES_STR.trim()));
assert.ok(!result.includes(NO_CHANGES_STR));
});
await it("doesn't remove `NO_CHANGES_STR` if present in versioned section", async () => {
@@ -120,7 +120,7 @@ describe("updateChangelog", async () => {
EMPTY_CHANGELOG.replace(UNRELEASED_PLACEHOLDER, "1.2.3"),
"",
);
assert.ok(result.includes(NO_CHANGES_STR.trim()));
assert.ok(result.includes(NO_CHANGES_STR));
});
await it("throws if there are no sections", async () => {
+99
View File
@@ -9,17 +9,46 @@ import * as fs from "node:fs";
import { describe, it } from "node:test";
import {
addBodyLinesToUnreleasedSection,
ChangelogSection,
EMPTY_CHANGELOG,
getHeader,
getReleaseDateString,
NO_CHANGES_STR,
parseChangelog,
processChangelogForBackports,
renderChangelog,
setVersionAndDate,
UNRELEASED_PLACEHOLDER,
} from "./changelog";
import { CHANGELOG_FILE } from "./config";
const testDate = new Date(2026, 7, 14);
describe("getHeader", async () => {
function Section(headerLine: string): ChangelogSection {
return {
headerLine,
bodyLines: [],
};
}
await it("returns non-headers unchanged", () => {
assert.equal("foo", getHeader(Section("foo")));
assert.equal("- bar", getHeader(Section("- bar")));
});
await it("strips octothorpes", async () => {
assert.equal("foo", getHeader(Section("# foo")));
assert.equal("foo", getHeader(Section("## foo")));
assert.equal("foo", getHeader(Section("### foo")));
assert.equal("foo", getHeader(Section("#### foo")));
assert.equal("foo", getHeader(Section("##### foo")));
assert.equal("foo", getHeader(Section("###### foo")));
});
await it("strips whitespace", async () => {
assert.equal("foo", getHeader(Section("# foo ")));
});
});
describe("getReleaseDateString", async () => {
await it("formats dates as expected", async () => {
assert.equal(getReleaseDateString(testDate), "14 Aug 2026");
@@ -70,3 +99,73 @@ describe("processChangelogForBackports", async () => {
assert.deepEqual(result.split("\n"), testChangelogResult.split("\n"));
});
});
describe("addBodyLinesToUnreleasedSection", async () => {
function newChangelogWithSections(sections: ChangelogSection[]) {
return {
preamble: [],
sections,
};
}
await it("throws error if '[UNRELEASED]' section is not first", async () => {
const invalidChangelog = newChangelogWithSections([
{
headerLine: "## Release 1.0.0",
bodyLines: [],
},
{
headerLine: `## ${UNRELEASED_PLACEHOLDER}`,
bodyLines: [],
},
]);
assert.throws(() =>
addBodyLinesToUnreleasedSection(invalidChangelog, ["foo"]),
);
});
await it("overwrites 'No user facing changes.'", async () => {
const changelog = newChangelogWithSections([
{
headerLine: `## ${UNRELEASED_PLACEHOLDER}`,
bodyLines: ["", NO_CHANGES_STR, ""],
},
]);
addBodyLinesToUnreleasedSection(changelog, ["- foo"]);
assert.equal(changelog.sections[0].bodyLines.length, 3);
assert.deepEqual(changelog.sections[0].bodyLines, ["", "- foo", ""]);
});
await it("does nothing if lines is empty", async () => {
const changelog = newChangelogWithSections([
{
headerLine: `## ${UNRELEASED_PLACEHOLDER}`,
bodyLines: ["", NO_CHANGES_STR, ""],
},
]);
const changelogClone = structuredClone(changelog);
addBodyLinesToUnreleasedSection(changelog, []);
assert.deepEqual(changelog, changelogClone);
});
await it("inserts a line", async () => {
const changelog = newChangelogWithSections([
{
headerLine: `## ${UNRELEASED_PLACEHOLDER}`,
bodyLines: ["", "- Added a new dependency.", ""],
},
]);
const lineToInsert = "- foo";
addBodyLinesToUnreleasedSection(changelog, [lineToInsert]);
assert.equal(changelog.sections[0].bodyLines.length, 4);
assert.ok(
changelog.sections[0].bodyLines.some((line) => line === lineToInsert),
);
});
});
+48 -3
View File
@@ -6,14 +6,16 @@ import { CHANGELOG_FILE, DryRunOption } from "./config";
export const UNRELEASED_PLACEHOLDER = "[UNRELEASED]";
/** The default contents for a section in the changelog. */
export const NO_CHANGES_STR = "No user facing changes.\n\n";
export const NO_CHANGES_STR = "No user facing changes.";
/** Placeholder changelog content for a new release. */
export const EMPTY_CHANGELOG = `# CodeQL Action Changelog
## ${UNRELEASED_PLACEHOLDER}
${NO_CHANGES_STR}`;
${NO_CHANGES_STR}
`;
/**
* Represents sections in a changelog.
@@ -31,6 +33,13 @@ export interface Changelog {
sections: ChangelogSection[];
}
/**
* Returns the text of the header (without the '## ' prefix) of the given section.
* */
export function getHeader(section: ChangelogSection): string {
return section.headerLine.replace(/^#+\s+/, "").trimEnd();
}
/** Returns `date` formatted as `DD Mon YYYY`. */
export function getReleaseDateString(today: Date = new Date()): string {
return today.toLocaleDateString("en-GB", {
@@ -125,6 +134,42 @@ export function parseChangelog(content: string): Changelog {
return { preamble, sections };
}
/**
* Inserts the changenotes `lines` in the `[UNRELEASED]` section of `changelog`.
* If the section contains the stock message {@link NO_CHANGES_STR}, then
* `lines` will be inserted in place and the stock message will be deleted.
*
* @throws Error -- if the [UNRELEASED] section does not exist.
*
* @param changelog The CHANGELOG object to modify.
* @param lines The changenotes to insert.
*/
export function addBodyLinesToUnreleasedSection(
changelog: Changelog,
lines: string[],
) {
// Do nothing if there is nothing to insert.
if (lines.length === 0) return;
const unreleasedSection = changelog.sections[0];
if (getHeader(unreleasedSection) !== UNRELEASED_PLACEHOLDER) {
throw Error(
`'${UNRELEASED_PLACEHOLDER}' is not the first section of 'CHANGELOG.md'`,
);
}
if (unreleasedSection.bodyLines.includes(NO_CHANGES_STR)) {
unreleasedSection.bodyLines = ["", ...lines, ""];
return;
}
// The last body line should be a blank line (for spacing).
// Remove it so that we can add `lines` and then add the blank line back.
unreleasedSection.bodyLines.pop();
unreleasedSection.bodyLines.push(...lines);
unreleasedSection.bodyLines.push("");
}
/**
* Combines an array of lines into a single string by adding line breaks.
*/
@@ -204,7 +249,7 @@ export function processChangelogForBackports(
// Add an entry if we didn't keep any.
if (!foundContent) {
section.bodyLines.push(NO_CHANGES_STR.trim());
section.bodyLines.push(NO_CHANGES_STR);
}
}
-11
View File
@@ -119,14 +119,3 @@ export function isValidChangenoteFile(filename: string): boolean {
return isValid;
}
/**
* Validates the change-note files of the given list of file paths, ignoring ".gitkeep".
* @param filepaths A list of filepaths to validate
* @returns True if all the paths are valid, false otherwise.
*/
export function isValidAllChangenoteFiles(filepaths: string[]): boolean {
return filepaths
.filter((f) => f !== ".gitkeep")
.reduce((r, filePath) => r && isValidChangenoteFile(filePath), true);
}
+1 -40
View File
@@ -1,13 +1,10 @@
import assert from "node:assert/strict";
import * as fs from "node:fs";
import * as path from "node:path";
import { describe, it } from "node:test";
import { withTmpDir, withTmpFile } from "../../src/util";
import { withTmpFile } from "../../src/util";
import {
hasValidChangenoteCategory,
isValidAllChangenoteFiles,
isValidChangenoteContent,
isValidChangenoteFile,
isValidChangenoteFilename,
@@ -187,39 +184,3 @@ await describe("isValidChangenoteFile", async () => {
);
});
});
await describe("isValidAllChangenoteFiles", async () => {
await it("accepts list of file paths of valid change-notes", async () => {
await withTmpDir(async (tmpDir) => {
const fileName1 = path.join(tmpDir, "2026-01-01-fix-bug.md");
const fileName2 = path.join(tmpDir, "2026-01-02-add-feature.md");
fs.writeFileSync(fileName1, "---\ncategory: fix\n---\n- Fixed a bug\n");
fs.writeFileSync(
fileName2,
"---\ncategory: feature\n---\n- Added a feature\n",
);
assert.equal(isValidAllChangenoteFiles([fileName1, fileName2]), true);
});
});
await it("accepts the empty list", async () => {
assert.equal(isValidAllChangenoteFiles([]), true);
});
await it("accepts list of .gitkeep", async () => {
assert.equal(isValidAllChangenoteFiles([".gitkeep"]), true);
});
await it("rejects list containing a file path to an invalid change-note", async () => {
await withTmpDir(async (tmpDir) => {
const fileName1 = path.join(tmpDir, "2026-01-01-fix-bug.md");
const fileName2 = path.join(tmpDir, "2026-01-02-wrong-category.md");
fs.writeFileSync(fileName1, "---\ncategory: fix\n---\n- Fixed a bug\n");
fs.writeFileSync(
fileName2,
"---\ncategory: foobar\n---\n- Added a feature\n",
);
assert.equal(isValidAllChangenoteFiles([fileName1, fileName2]), false);
});
});
});
+89 -11
View File
@@ -3,21 +3,64 @@
import * as fs from "node:fs";
import { pathToFileURL } from "node:url";
import { parseArgs } from "node:util";
import path from "path";
import { isValidAllChangenoteFiles } from "./changelog/validate.mjs";
import { ExitCode } from "@actions/core";
import { matter } from "lite-matter";
import {
addBodyLinesToUnreleasedSection,
parseChangelog,
renderChangelog,
withChangelog,
} from "./changelog";
import { isValidChangenoteFile } from "./changelog/validate.mjs";
import { CHANGENOTES_DIR } from "./config";
/**
* Describes a changenote file, including its file path, frontmatter, and content.
*/
interface ChangenoteFile {
absolutePath: string;
data: Record<string, any>;
content: string;
}
/**
* Returns the absolute file paths of all files in
* {@link CHANGENOTES_DIR} (except ".gitkeep").
* */
function listUnreleasedChangenoteDir(): string[] {
return fs
.readdirSync(CHANGENOTES_DIR)
.filter((name) => name !== ".gitkeep")
.map((name) => path.join(CHANGENOTES_DIR, name));
}
/**
* Scans the {@link CHANGENOTES_DIR} directory for changenote files
* and returns a parsed listing of those changenote files.
*/
function getChangenotes(): ChangenoteFile[] {
return listUnreleasedChangenoteDir().map((absolutePath) => {
return {
absolutePath,
...matter(fs.readFileSync(absolutePath, "utf-8")),
};
});
}
const entryPoint = process.argv[1];
if (entryPoint && import.meta.url === pathToFileURL(entryPoint).href) {
try {
process.exit(main());
} catch (error) {
console.error(error);
process.exit(1);
process.exit(ExitCode.Failure);
}
}
function main(): number {
function main(): ExitCode {
const { positionals } = parseArgs({
allowPositionals: true,
strict: true,
@@ -27,24 +70,59 @@ function main(): number {
case undefined:
case "help":
return usage();
case "assemble":
return assemble();
case "validate":
return validate();
default:
console.error(`Unknown command: ${command}`);
return 1;
return ExitCode.Failure;
}
}
function usage(): number {
console.log(`Usage: changenotes.mts validate`);
return 0;
function usage(): ExitCode {
const message =
"Usage: changenotes.mts assemble\n" +
" changenotes.mts validate\n" +
" changenotes.mts help";
console.log(message);
return ExitCode.Success;
}
function validate(): number {
function assemble(): ExitCode {
try {
if (isValidAllChangenoteFiles(fs.readdirSync(CHANGENOTES_DIR))) {
const changenotes = getChangenotes();
const changenoteBodies = changenotes.map((c) => c.content);
const changenotePaths = changenotes.map((c) => c.absolutePath);
withChangelog((contents) => {
const changelog = parseChangelog(contents);
addBodyLinesToUnreleasedSection(changelog, changenoteBodies);
return renderChangelog(changelog);
}, {});
// Delete changenotes only after successful processing.
for (const p of changenotePaths) {
fs.unlinkSync(p);
}
return ExitCode.Success;
} catch (e) {
console.error("Failed to assemble changenotes to 'CHANGELOG.md'", e);
}
return ExitCode.Failure;
}
function validate(): ExitCode {
try {
const allChangenotesValid = getChangenotes().reduce(
(r, changenote) => r && isValidChangenoteFile(changenote.absolutePath),
true,
);
if (allChangenotesValid) {
console.log(`All changenotes in '${CHANGENOTES_DIR}' are valid.`);
return 0;
return ExitCode.Success;
}
} catch (error) {
console.error(
@@ -52,5 +130,5 @@ function validate(): number {
error,
);
}
return 1;
return ExitCode.Failure;
}
+1 -1
View File
@@ -5,7 +5,7 @@ versions:
- default
steps:
- name: Set up Ruby
uses: ruby/setup-ruby@95ef2b042f9d7a56d8268cba8559e2842e2ad01b # v1.321.0
uses: ruby/setup-ruby@984c0c890880bbf811283d6f09c4607c62d210a4 # v1.323.0
with:
ruby-version: 2.6
- name: Install Code Scanning integration
+1 -1
View File
@@ -10,7 +10,7 @@
"lite-matter": "^0.1.2",
"mdast-util-from-markdown": "^2.0.3",
"semver": "^7.8.5",
"yaml": "^2.9.0"
"yaml": "^2.9.1"
},
"devDependencies": {
"@types/node": "^20.19.43",
+19 -6
View File
@@ -212,7 +212,11 @@ async function runAutobuildIfLegacyGoWorkflow(config: Config, logger: Logger) {
await runAutobuild(config, BuiltInLanguage.go, logger);
}
async function run({ startedAt, logger }: ActionState<["Base", "Logger"]>) {
async function run({
startedAt,
logger,
actions,
}: ActionState<["Base", "Logger", "Actions"]>) {
// To capture errors appropriately, keep as much code within the try-catch as
// possible, and only use safe functions outside.
@@ -307,8 +311,13 @@ async function run({ startedAt, logger }: ActionState<["Base", "Logger"]>) {
logger,
);
const checkoutPath = actions.getRequiredInput("checkout_path");
// Setup diff informed analysis if needed (based on whether init created the file)
const diffRangePackDir = await setupDiffInformedQueryRun(logger);
const diffRangePackDir = await setupDiffInformedQueryRun(
logger,
checkoutPath,
);
await warnIfGoInstalledAfterInit(config, logger);
await runAutobuildIfLegacyGoWorkflow(config, logger);
@@ -354,7 +363,6 @@ async function run({ startedAt, logger }: ActionState<["Base", "Logger"]>) {
actionsUtil.getOptionalInput("upload"),
);
if (runStats) {
const checkoutPath = actionsUtil.getRequiredInput("checkout_path");
const category = actionsUtil.getOptionalInput("category");
uploadResults = await postProcessAndUploadSarif(
@@ -388,18 +396,23 @@ async function run({ startedAt, logger }: ActionState<["Base", "Logger"]>) {
// Possibly upload the overlay-base database to actions cache.
// Note: Take care with the ordering of this call since databases may be cleaned up
// at the `overlay` level.
await cleanupAndUploadOverlayBaseDatabaseToCache(codeql, config, logger);
await cleanupAndUploadOverlayBaseDatabaseToCache(
codeql,
config,
logger,
checkoutPath,
);
// Possibly upload the database bundles for remote queries.
// Note: Take care with the ordering of this call since databases may be cleaned up
// at the `overlay` or `clear` level.
databaseUploadResults = await cleanupAndUploadDatabases(
{ logger, features },
repositoryNwo,
codeql,
config,
apiDetails,
features,
logger,
checkoutPath,
);
// Possibly upload the TRAP caches for later re-use
+2 -2
View File
@@ -5,7 +5,7 @@ import { performance } from "perf_hooks";
import * as io from "@actions/io";
import * as yaml from "js-yaml";
import { getTemporaryDirectory, getRequiredInput } from "./actions-util";
import { getTemporaryDirectory } from "./actions-util";
import * as analyses from "./analyses";
import { setupCppAutobuild } from "./autobuild";
import { type CodeQL } from "./codeql";
@@ -233,6 +233,7 @@ async function finalizeDatabaseCreation(
*/
export async function setupDiffInformedQueryRun(
logger: Logger,
checkoutPath: string,
): Promise<string | undefined> {
return await withGroupAsync(
"Generating diff range extension pack",
@@ -245,7 +246,6 @@ export async function setupDiffInformedQueryRun(
return undefined;
}
const checkoutPath = getRequiredInput("checkout_path");
const packDir = writeDiffRangeDataExtensionPack(
logger,
diffRanges,
+1
View File
@@ -937,6 +937,7 @@ async function getCodeQLForCmd(
"--format=json",
`--language=${language}`,
"--extractor-include-aliases",
"-J-XX:-UsePerfData",
...getExtraOptionsFromEnv(["resolve", "extractor"]),
],
{
+79 -55
View File
@@ -20,8 +20,9 @@ import {
checkExpectedLogMessages,
createFeatures,
createTestConfig,
getRecordingLogger,
LoggedMessage,
getTestEnv,
initAllState,
RecordingLogger,
setupActionsVars,
setupTests,
} from "./testing-utils";
@@ -90,23 +91,24 @@ test.serial(
"Abort database upload if 'upload-database' input set to false",
async (t) => {
await withTmpDir(async (tmpDir) => {
setupActionsVars(tmpDir, tmpDir);
const env = getTestEnv();
setupActionsVars(tmpDir, tmpDir, {}, env);
sinon
.stub(actionsUtil, "getRequiredInput")
.withArgs("upload-database")
.returns("false");
sinon.stub(gitUtils, "isAnalyzingDefaultBranch").resolves(true);
const loggedMessages: LoggedMessage[] = [];
const logger = new RecordingLogger();
await cleanupAndUploadDatabases(
initAllState({ env, logger }),
testRepoName,
getCodeQL(),
getTestConfig(tmpDir),
testApiDetails,
createFeatures([]),
getRecordingLogger(loggedMessages),
"",
);
checkExpectedLogMessages(t, loggedMessages, [
checkExpectedLogMessages(t, logger.messages, [
"Database upload disabled in workflow. Skipping upload.",
]);
});
@@ -117,7 +119,8 @@ test.serial(
"Abort database upload if 'analysis-kinds: code-scanning' is not enabled",
async (t) => {
await withTmpDir(async (tmpDir) => {
setupActionsVars(tmpDir, tmpDir);
const env = getTestEnv();
setupActionsVars(tmpDir, tmpDir, {}, env);
sinon
.stub(actionsUtil, "getRequiredInput")
.withArgs("upload-database")
@@ -126,8 +129,9 @@ test.serial(
await mockHttpRequests(201);
const loggedMessages: LoggedMessage[] = [];
const logger = new RecordingLogger();
await cleanupAndUploadDatabases(
initAllState({ env, logger }),
testRepoName,
getCodeQL(),
{
@@ -135,10 +139,9 @@ test.serial(
analysisKinds: [AnalysisKind.CodeQuality],
},
testApiDetails,
createFeatures([]),
getRecordingLogger(loggedMessages),
"",
);
checkExpectedLogMessages(t, loggedMessages, [
checkExpectedLogMessages(t, logger.messages, [
"Not uploading database because 'analysis-kinds: code-scanning' is not enabled.",
]);
});
@@ -147,7 +150,8 @@ test.serial(
test.serial("Abort database upload if running against GHES", async (t) => {
await withTmpDir(async (tmpDir) => {
setupActionsVars(tmpDir, tmpDir);
const env = getTestEnv();
setupActionsVars(tmpDir, tmpDir, {}, env);
sinon
.stub(actionsUtil, "getRequiredInput")
.withArgs("upload-database")
@@ -157,16 +161,16 @@ test.serial("Abort database upload if running against GHES", async (t) => {
const config = getTestConfig(tmpDir);
config.gitHubVersion = { type: GitHubVariant.GHES, version: "3.0" };
const loggedMessages: LoggedMessage[] = [];
const logger = new RecordingLogger();
await cleanupAndUploadDatabases(
initAllState({ env, logger }),
testRepoName,
getCodeQL(),
config,
testApiDetails,
createFeatures([]),
getRecordingLogger(loggedMessages),
"",
);
checkExpectedLogMessages(t, loggedMessages, [
checkExpectedLogMessages(t, logger.messages, [
"Not running against github.com or GHEC-DR. Skipping upload.",
]);
});
@@ -176,23 +180,24 @@ test.serial(
"Abort database upload if not analyzing default branch",
async (t) => {
await withTmpDir(async (tmpDir) => {
setupActionsVars(tmpDir, tmpDir);
const env = getTestEnv();
setupActionsVars(tmpDir, tmpDir, {}, env);
sinon
.stub(actionsUtil, "getRequiredInput")
.withArgs("upload-database")
.returns("true");
sinon.stub(gitUtils, "isAnalyzingDefaultBranch").resolves(false);
const loggedMessages: LoggedMessage[] = [];
const logger = new RecordingLogger();
await cleanupAndUploadDatabases(
initAllState({ env, logger }),
testRepoName,
getCodeQL(),
getTestConfig(tmpDir),
testApiDetails,
createFeatures([]),
getRecordingLogger(loggedMessages),
"",
);
checkExpectedLogMessages(t, loggedMessages, [
checkExpectedLogMessages(t, logger.messages, [
"Not analyzing default branch. Skipping upload.",
]);
});
@@ -203,7 +208,8 @@ test.serial(
"Don't crash if uploading a database fails with a non-retryable error",
async (t) => {
await withTmpDir(async (tmpDir) => {
setupActionsVars(tmpDir, tmpDir);
const env = getTestEnv();
setupActionsVars(tmpDir, tmpDir, {}, env);
sinon
.stub(actionsUtil, "getRequiredInput")
.withArgs("upload-database")
@@ -212,17 +218,17 @@ test.serial(
const databaseUploadSpy = await mockHttpRequests(422);
const loggedMessages: LoggedMessage[] = [];
const logger = new RecordingLogger();
await cleanupAndUploadDatabases(
initAllState({ env, logger }),
testRepoName,
getCodeQL(),
getTestConfig(tmpDir),
testApiDetails,
createFeatures([]),
getRecordingLogger(loggedMessages),
"",
);
checkExpectedLogMessages(t, loggedMessages, [
checkExpectedLogMessages(t, logger.messages, [
"Failed to upload database for javascript: some error message",
]);
@@ -236,7 +242,8 @@ test.serial(
"Don't crash if uploading a database fails with a retryable error",
async (t) => {
await withTmpDir(async (tmpDir) => {
setupActionsVars(tmpDir, tmpDir);
const env = getTestEnv();
setupActionsVars(tmpDir, tmpDir, {}, env);
sinon
.stub(actionsUtil, "getRequiredInput")
.withArgs("upload-database")
@@ -251,17 +258,17 @@ test.serial(
.stub(global, "setTimeout")
.callsFake((fn: () => void) => originalSetTimeout(fn, 0));
const loggedMessages: LoggedMessage[] = [];
const logger = new RecordingLogger();
await cleanupAndUploadDatabases(
initAllState({ env, logger }),
testRepoName,
getCodeQL(),
getTestConfig(tmpDir),
testApiDetails,
createFeatures([]),
getRecordingLogger(loggedMessages),
"",
);
checkExpectedLogMessages(t, loggedMessages, [
checkExpectedLogMessages(t, logger.messages, [
"Failed to upload database for javascript: some error message",
]);
@@ -279,7 +286,8 @@ test.serial(
test.serial("Successfully uploading a database to github.com", async (t) => {
await withTmpDir(async (tmpDir) => {
setupActionsVars(tmpDir, tmpDir);
const env = getTestEnv();
setupActionsVars(tmpDir, tmpDir, {}, env);
sinon
.stub(actionsUtil, "getRequiredInput")
.withArgs("upload-database")
@@ -288,16 +296,16 @@ test.serial("Successfully uploading a database to github.com", async (t) => {
await mockHttpRequests(201);
const loggedMessages: LoggedMessage[] = [];
const logger = new RecordingLogger();
await cleanupAndUploadDatabases(
initAllState({ env, logger }),
testRepoName,
getCodeQL(),
getTestConfig(tmpDir),
testApiDetails,
createFeatures([]),
getRecordingLogger(loggedMessages),
"",
);
checkExpectedLogMessages(t, loggedMessages, [
checkExpectedLogMessages(t, logger.messages, [
"Successfully uploaded database for javascript",
]);
});
@@ -305,7 +313,8 @@ test.serial("Successfully uploading a database to github.com", async (t) => {
test.serial("Successfully uploading a database to GHEC-DR", async (t) => {
await withTmpDir(async (tmpDir) => {
setupActionsVars(tmpDir, tmpDir);
const env = getTestEnv();
setupActionsVars(tmpDir, tmpDir, {}, env);
sinon
.stub(actionsUtil, "getRequiredInput")
.withArgs("upload-database")
@@ -314,8 +323,9 @@ test.serial("Successfully uploading a database to GHEC-DR", async (t) => {
const databaseUploadSpy = await mockHttpRequests(201);
const loggedMessages: LoggedMessage[] = [];
const logger = new RecordingLogger();
await cleanupAndUploadDatabases(
initAllState({ env, logger }),
testRepoName,
getCodeQL(),
getTestConfig(tmpDir),
@@ -324,10 +334,9 @@ test.serial("Successfully uploading a database to GHEC-DR", async (t) => {
url: "https://tenant.ghe.com",
apiURL: undefined,
},
createFeatures([]),
getRecordingLogger(loggedMessages),
"",
);
checkExpectedLogMessages(t, loggedMessages, [
checkExpectedLogMessages(t, logger.messages, [
"Successfully uploaded database for javascript",
]);
t.assert(
@@ -343,7 +352,8 @@ test.serial(
"Records overlay and clear cleanup sizes when uploading an overlay-base database",
async (t) => {
await withTmpDir(async (tmpDir) => {
setupActionsVars(tmpDir, tmpDir);
const env = getTestEnv();
setupActionsVars(tmpDir, tmpDir, {}, env);
sinon
.stub(actionsUtil, "getRequiredInput")
.withArgs("upload-database")
@@ -375,14 +385,16 @@ test.serial(
const config = getTestConfig(tmpDir);
config.overlayDatabaseMode = OverlayDatabaseMode.OverlayBase;
const loggedMessages: LoggedMessage[] = [];
const results = await cleanupAndUploadDatabases(
initAllState({
env,
features: createFeatures([Feature.UploadOverlayDbToApi]),
}),
testRepoName,
codeql,
config,
testApiDetails,
createFeatures([Feature.UploadOverlayDbToApi]),
getRecordingLogger(loggedMessages),
"",
);
// The database should be cleaned up at the `overlay` level for the upload
@@ -402,7 +414,8 @@ test.serial(
"Does not measure clear cleanup size for a regular (non-overlay-base) upload",
async (t) => {
await withTmpDir(async (tmpDir) => {
setupActionsVars(tmpDir, tmpDir);
const env = getTestEnv();
setupActionsVars(tmpDir, tmpDir, {}, env);
sinon
.stub(actionsUtil, "getRequiredInput")
.withArgs("upload-database")
@@ -422,12 +435,15 @@ test.serial(
});
const results = await cleanupAndUploadDatabases(
initAllState({
env,
features: createFeatures([Feature.UploadOverlayDbToApi]),
}),
testRepoName,
codeql,
getTestConfig(tmpDir),
testApiDetails,
createFeatures([Feature.UploadOverlayDbToApi]),
getRecordingLogger([]),
"",
);
// A regular upload is cleaned only once, at the `clear` level.
@@ -441,7 +457,8 @@ test.serial(
test.serial("Does not measure clear cleanup size in debug mode", async (t) => {
await withTmpDir(async (tmpDir) => {
setupActionsVars(tmpDir, tmpDir);
const env = getTestEnv();
setupActionsVars(tmpDir, tmpDir, {}, env);
sinon
.stub(actionsUtil, "getRequiredInput")
.withArgs("upload-database")
@@ -465,12 +482,15 @@ test.serial("Does not measure clear cleanup size in debug mode", async (t) => {
config.debugMode = true;
const results = await cleanupAndUploadDatabases(
initAllState({
env,
features: createFeatures([Feature.UploadOverlayDbToApi]),
}),
testRepoName,
codeql,
config,
testApiDetails,
createFeatures([Feature.UploadOverlayDbToApi]),
getRecordingLogger([]),
"",
);
// In debug mode we clean up at the `overlay` level for the upload but skip
@@ -486,7 +506,8 @@ test.serial(
"Does not record a clear cleanup duration when the clear cleanup fails",
async (t) => {
await withTmpDir(async (tmpDir) => {
setupActionsVars(tmpDir, tmpDir);
const env = getTestEnv();
setupActionsVars(tmpDir, tmpDir, {}, env);
sinon
.stub(actionsUtil, "getRequiredInput")
.withArgs("upload-database")
@@ -510,12 +531,15 @@ test.serial(
config.overlayDatabaseMode = OverlayDatabaseMode.OverlayBase;
const results = await cleanupAndUploadDatabases(
initAllState({
env,
features: createFeatures([Feature.UploadOverlayDbToApi]),
}),
testRepoName,
codeql,
config,
testApiDetails,
createFeatures([Feature.UploadOverlayDbToApi]),
getRecordingLogger([]),
"",
);
// When the `clear` cleanup fails, no size is measured, so we should not
+8 -7
View File
@@ -1,5 +1,6 @@
import * as fs from "fs";
import { ActionState } from "./action-common";
import * as actionsUtil from "./actions-util";
import { AnalysisKind } from "./analyses";
import {
@@ -9,7 +10,7 @@ import {
} from "./api-client";
import { type CodeQL } from "./codeql";
import { Config } from "./config-utils";
import { Feature, FeatureEnablement } from "./feature-flags";
import { Feature } from "./feature-flags";
import * as gitUtils from "./git-utils";
import { Logger, withGroupAsync } from "./logging";
import { OverlayDatabaseMode } from "./overlay/overlay-database-mode";
@@ -45,13 +46,15 @@ export interface DatabaseUploadResult {
}
export async function cleanupAndUploadDatabases(
action: ActionState<["Logger", "FeatureFlags"]>,
repositoryNwo: RepositoryNwo,
codeql: CodeQL,
config: Config,
apiDetails: GitHubApiDetails,
features: FeatureEnablement,
logger: Logger,
checkoutPath: string,
): Promise<DatabaseUploadResult[]> {
const logger = action.logger;
if (actionsUtil.getRequiredInput("upload-database") !== "true") {
logger.debug("Database upload disabled in workflow. Skipping upload.");
return [];
@@ -87,7 +90,7 @@ export async function cleanupAndUploadDatabases(
// If config.overlayDatabaseMode is OverlayBase, then we have overlay base databases for all languages.
const shouldUploadOverlayBase =
config.overlayDatabaseMode === OverlayDatabaseMode.OverlayBase &&
(await features.getValue(Feature.UploadOverlayDbToApi, codeql));
(await action.features.getValue(Feature.UploadOverlayDbToApi, codeql));
const cleanupLevel = shouldUploadOverlayBase
? CleanupLevel.Overlay
: CleanupLevel.Clear;
@@ -110,9 +113,7 @@ export async function cleanupAndUploadDatabases(
includeDiagnostics: false,
});
bundledDbSize = fs.statSync(bundledDb).size;
const commitOid = await gitUtils.getCommitOid(
actionsUtil.getRequiredInput("checkout_path"),
);
const commitOid = await gitUtils.getCommitOid(checkoutPath);
// Upload with manual retry logic. We disable Octokit's built-in retries
// because the request body is a ReadStream, which can only be consumed
// once.
+4 -4
View File
@@ -1,6 +1,6 @@
{
"bundleVersion": "codeql-bundle-v2.27.0",
"cliVersion": "2.27.0",
"priorBundleVersion": "codeql-bundle-v2.26.4",
"priorCliVersion": "2.26.4"
"bundleVersion": "codeql-bundle-v2.27.1",
"cliVersion": "2.27.1",
"priorBundleVersion": "codeql-bundle-v2.27.0",
"priorCliVersion": "2.27.0"
}
+25 -6
View File
@@ -29,10 +29,13 @@ test.serial(
process.env["GITHUB_SHA"] = currentSha;
const callback = sinon.stub(gitUtils, "getCommitOid");
callback.withArgs("HEAD").resolves(currentSha);
callback.withArgs(sinon.match.string, "HEAD").resolves(currentSha);
const actualRef = await gitUtils.getRef();
t.deepEqual(actualRef, expectedRef);
t.is(callback.callCount, 1);
t.true(callback.calledOnceWith(tmpDir, "HEAD"));
});
},
);
@@ -48,11 +51,17 @@ test.serial(
const sha = "a".repeat(40);
const callback = sinon.stub(gitUtils, "getCommitOid");
callback.withArgs("refs/remotes/pull/1/merge").resolves(sha);
callback.withArgs("HEAD").resolves(sha);
callback
.withArgs(sinon.match.string, "refs/remotes/pull/1/merge")
.resolves(sha);
callback.withArgs(sinon.match.any, "HEAD").resolves(sha);
const actualRef = await gitUtils.getRef();
t.deepEqual(actualRef, expectedRef);
t.is(callback.callCount, 2);
t.true(callback.calledWith(tmpDir, "HEAD"));
t.true(callback.calledWith(tmpDir, "refs/remotes/pull/1/merge"));
});
},
);
@@ -66,11 +75,18 @@ test.serial(
process.env["GITHUB_SHA"] = "a".repeat(40);
const callback = sinon.stub(gitUtils, "getCommitOid");
callback.withArgs(tmpDir, "refs/pull/1/merge").resolves("a".repeat(40));
callback
.withArgs(tmpDir, "refs/remotes/pull/1/merge")
.resolves("a".repeat(40));
callback.withArgs(tmpDir, "HEAD").resolves("b".repeat(40));
callback.throws(new Error("Unexpected getCommitOid call in test."));
const actualRef = await gitUtils.getRef();
t.deepEqual(actualRef, "refs/pull/1/head");
t.is(callback.callCount, 2);
t.true(callback.calledWith(tmpDir, "refs/remotes/pull/1/merge"));
t.true(callback.calledWith(tmpDir, "HEAD"));
});
},
);
@@ -92,11 +108,14 @@ test.serial(
process.env["GITHUB_SHA"] = "a".repeat(40);
const callback = sinon.stub(gitUtils, "getCommitOid");
callback.withArgs("refs/pull/1/merge").resolves("b".repeat(40));
callback.withArgs("HEAD").resolves("b".repeat(40));
callback.withArgs(tmpDir, "refs/pull/1/merge").resolves("b".repeat(40));
callback.withArgs(sinon.match.any, "HEAD").resolves("b".repeat(40));
const actualRef = await gitUtils.getRef();
t.deepEqual(actualRef, "refs/pull/2/merge");
// getCommitOid shouldn't be called, because the ref should be taken from the input
t.is(callback.callCount, 0);
});
},
);
+7 -6
View File
@@ -38,7 +38,7 @@ import {
makeDiagnostic,
makeTelemetryDiagnostic,
} from "./diagnostics";
import { EnvVar } from "./environment";
import { ActionsEnvVars, EnvVar } from "./environment";
import { Feature, FeatureEnablement, initFeatures } from "./feature-flags";
import { loadRepositoryProperties } from "./feature-flags/properties";
import {
@@ -81,7 +81,6 @@ import {
DEFAULT_DEBUG_ARTIFACT_NAME,
DEFAULT_DEBUG_DATABASE_NAME,
getCodeQLMemoryLimit,
getRequiredEnvParam,
getThreadsFlagValue,
initializeEnvironment,
ConfigurationError,
@@ -225,8 +224,8 @@ async function run(
apiDetails = {
auth: getRequiredInput("token"),
externalRepoAuth: getOptionalInput("external-repository-token"),
url: getRequiredEnvParam("GITHUB_SERVER_URL"),
apiURL: getRequiredEnvParam("GITHUB_API_URL"),
url: actionState.env.getRequired(ActionsEnvVars.GITHUB_SERVER_URL),
apiURL: actionState.env.getRequired(ActionsEnvVars.GITHUB_API_URL),
};
const gitHubVersion = await getGitHubVersion();
@@ -255,7 +254,7 @@ async function run(
// source-root is relative, it is relative to the GITHUB_WORKSPACE. If
// source-root is absolute, it is used as given.
sourceRoot = path.resolve(
getRequiredEnvParam("GITHUB_WORKSPACE"),
actionState.env.getRequired(ActionsEnvVars.GITHUB_WORKSPACE),
getOptionalInput("source-root") || "",
);
@@ -383,7 +382,9 @@ async function run(
repository: repositoryNwo,
tempDir: getTemporaryDirectory(),
codeql,
workspacePath: getRequiredEnvParam("GITHUB_WORKSPACE"),
workspacePath: actionState.env.getRequired(
ActionsEnvVars.GITHUB_WORKSPACE,
),
sourceRoot,
githubVersion: gitHubVersion,
apiDetails,
+4 -7
View File
@@ -3,11 +3,7 @@ import * as fs from "fs";
import * as actionsCache from "@actions/cache";
import * as semver from "semver";
import {
getRequiredInput,
getWorkflowRunAttempt,
getWorkflowRunID,
} from "../actions-util";
import { getWorkflowRunAttempt, getWorkflowRunID } from "../actions-util";
import { getAutomationID, listActionsCaches } from "../api-client";
import { createCacheKeyHash } from "../caching-utils";
import { type CodeQL } from "../codeql";
@@ -107,12 +103,13 @@ async function checkOverlayBaseDatabase(
* Uploads the overlay-base database to the GitHub Actions cache. If conditions
* for uploading are not met, the function does nothing and returns false.
*
* This function uses the `checkout_path` input to determine the repository path
* This function uses the `checkoutPath` to determine the repository path
* and works only when called from `analyze` or `upload-sarif`.
*
* @param codeql The CodeQL instance
* @param config The configuration object
* @param logger The logger instance
* @param checkoutPath The path at which the repository is checked out at.
* @returns A promise that resolves to true if the upload was performed and
* successfully completed, or false otherwise
*/
@@ -120,6 +117,7 @@ export async function cleanupAndUploadOverlayBaseDatabaseToCache(
codeql: CodeQL,
config: Config,
logger: Logger,
checkoutPath: string,
): Promise<boolean> {
const overlayDatabaseMode = config.overlayDatabaseMode;
if (overlayDatabaseMode !== OverlayDatabaseMode.OverlayBase) {
@@ -180,7 +178,6 @@ export async function cleanupAndUploadOverlayBaseDatabaseToCache(
}
const codeQlVersion = (await codeql.getVersion()).version;
const checkoutPath = getRequiredInput("checkout_path");
const cacheSaveKey = await getCacheSaveKey(
config,
codeQlVersion,
-2
View File
@@ -38,7 +38,6 @@ async function checkEligibility(
[ActionsEnvVars.RUNNER_ENVIRONMENT]: "github-hosted",
}),
features: createFeatures([Feature.PerLanguageBundles]),
logger: getRecordingLogger([], { logToConsole: false }),
...stateOverrides,
}),
{ ...ELIGIBLE_OPTIONS, ...overrides },
@@ -134,7 +133,6 @@ test("getPerLanguageBundleLanguage explains a disabled feature before checking e
const messages: LoggedMessage[] = [];
const language = await getPerLanguageBundleLanguage(
initAllState({
env: getTestEnv(),
features: createFeatures([]),
logger: getRecordingLogger(messages, { logToConsole: false }),
}),
+5 -2
View File
@@ -102,8 +102,11 @@ export async function getPerLanguageBundleLanguage(
return explain("the job is not running on a GitHub-hosted runner");
}
// Check whether per-language bundles are published for the requested CLI version.
// Latest-nightly selection skips this release-version check, but not the other eligibility checks.
// Nightly releases are identified by dates rather than versions. If
// `isLatestNightly` is `true`, the latest nightly is requested with
// `tools: nightly` and we don't yet have the corresponding tag at this point.
// Therefore, we skip the version check and don't have an equivalent.
// We can safely assume that the latest nightly will have per-language bundles.
if (!isLatestNightly) {
if (cliVersion === undefined) {
return explain("the requested CLI version is unknown");
+3 -4
View File
@@ -12,7 +12,7 @@ import { getGitHubVersion } from "./api-client";
import { CodeQL } from "./codeql";
import { ComputedInput, getToolsInput } from "./config/inputs";
import { getRawLanguagesNoAutodetect } from "./config-utils";
import { EnvVar } from "./environment";
import { ActionsEnvVars, EnvVar } from "./environment";
import { initFeatures } from "./feature-flags";
import { loadRepositoryProperties } from "./feature-flags/properties";
import { initCodeQL } from "./init";
@@ -32,7 +32,6 @@ import {
checkDiskUsage,
checkForTimeout,
checkGitHubVersionInRange,
getRequiredEnvParam,
initializeEnvironment,
ConfigurationError,
wrapError,
@@ -108,8 +107,8 @@ async function run(
const apiDetails = {
auth: getRequiredInput("token"),
externalRepoAuth: getOptionalInput("external-repository-token"),
url: getRequiredEnvParam("GITHUB_SERVER_URL"),
apiURL: getRequiredEnvParam("GITHUB_API_URL"),
url: actionState.env.getRequired(ActionsEnvVars.GITHUB_SERVER_URL),
apiURL: actionState.env.getRequired(ActionsEnvVars.GITHUB_API_URL),
};
const gitHubVersion = await getGitHubVersion();
+20 -16
View File
@@ -69,25 +69,29 @@ function stubHostedNightly(tagName: string) {
available: true,
foundZstdBinary: true,
});
const fetchRelease = sinon
.stub<Parameters<typeof fetch>, ReturnType<typeof fetch>>()
.rejects(new Error("Unexpected API request in nightly bundle test"));
fetchRelease
.withArgs(
"https://api.github.com/repos/dsp-testing/codeql-cli-nightlies/releases?per_page=1&page=1&prerelease=true",
sinon.match({ method: "GET" }),
)
.callsFake(
async () =>
new Response(JSON.stringify([{ tag_name: tagName }]), {
headers: { "content-type": "application/json" },
}),
);
const client = github.getOctokit("123", {
request: { fetch: fetchRelease },
request: {
fetch: async () => {
throw new Error("Unexpected API request in nightly bundle test");
},
},
});
const listReleases = sinon
.stub(client.rest.repos, "listReleases")
.rejects(new Error("Unexpected release request in nightly bundle test"));
listReleases
.withArgs({
owner: "dsp-testing",
repo: "codeql-cli-nightlies",
per_page: 1,
page: 1,
prerelease: true,
})
.resolves({
data: [{ tag_name: tagName }],
} as Awaited<ReturnType<typeof client.rest.repos.listReleases>>);
sinon.stub(api, "getApiClient").value(() => client);
return fetchRelease;
return listReleases;
}
test.serial("parse codeql bundle url version", (t) => {
+1 -1
View File
@@ -682,7 +682,7 @@ export async function bundleDb(
return databaseBundlePath;
}
/** Returns the elapsed milliseconds, rounded, since a `performance.now()` timestamp. */
/** Returns the elapsed milliseconds, rounded, since `startTime` was recorded with `performance.now()`. */
export function durationMsSince(startTime: number): number {
return Math.round(performance.now() - startTime);
}