1- # SPDX-License-Identifier: PMPL-1.0-or-later
1+ # SPDX-License-Identifier: PMPL-1.0
22name : CodeQL Security Analysis
33
44on :
88 branches : [main, master]
99 schedule :
1010 - cron : ' 0 6 * * 1'
11- # Estate guardrail: cancel superseded runs so re-pushes don't pile up
12- # queued runs across the estate. Safe here because this workflow only
13- # performs read-only checks/lint/test/scan with no publish or mutation.
11+
12+ # Estate guardrail: cancel superseded runs so re-pushes / rebased PR
13+ # updates do not pile up queued runs against the shared account-wide
14+ # Actions concurrency pool. Applied only to read-only check workflows
15+ # (no publish/mutation), so cancelling a superseded run is always safe.
1416concurrency :
1517 group : ${{ github.workflow }}-${{ github.ref }}
1618 cancel-in-progress : true
@@ -19,58 +21,29 @@ permissions:
1921 contents : read
2022
2123jobs :
22- # The estate is heterogeneous (Rust, Idris2, Agda, Elixir, ReScript,
23- # occasional JS/TS/Python). A hard-coded `javascript-typescript` matrix
24- # made CodeQL exit with a "no source / configuration error" on every
25- # non-JS/TS repo — a permanent false-red `analyze` on most repos' main.
26- # Detect the languages the repo ACTUALLY contains and only analyse the
27- # CodeQL-supported, buildless-safe ones; skip entirely when none apply.
28- detect :
29- runs-on : ubuntu-latest
30- outputs :
31- langs : ${{ steps.pick.outputs.langs }}
32- steps :
33- - name : Pick CodeQL languages from repo language stats
34- id : pick
35- env :
36- GH_TOKEN : ${{ github.token }}
37- run : |
38- stats=$(gh api "repos/${{ github.repository }}/languages" --jq 'keys[]' 2>/dev/null || echo "")
39- out=""
40- add() { out="$out $1"; }
41- echo "$stats" | grep -qix 'Rust' && add rust
42- echo "$stats" | grep -qixE 'JavaScript|TypeScript' && add javascript-typescript
43- echo "$stats" | grep -qix 'Python' && add python
44- echo "$stats" | grep -qix 'Ruby' && add ruby
45- echo "$stats" | grep -qix 'Go' && add go
46- arr=$(printf '%s\n' $out | grep . | sort -u | jq -R . | jq -s -c .)
47- [ -z "$arr" ] && arr='[]'
48- echo "Detected CodeQL languages: $arr"
49- echo "langs=$arr" >> "$GITHUB_OUTPUT"
50-
5124 analyze :
52- needs : detect
53- if : needs.detect.outputs.langs != '[]'
5425 runs-on : ubuntu-latest
5526 permissions :
5627 contents : read
5728 security-events : write
5829 strategy :
5930 fail-fast : false
6031 matrix :
61- language : ${{ fromJSON(needs.detect.outputs.langs) }}
32+ include :
33+ - language : javascript-typescript
34+ build-mode : none
6235
6336 steps :
6437 - name : Checkout
6538 uses : actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
6639
6740 - name : Initialize CodeQL
68- uses : github/codeql-action/init@0d579ffd059c29b07949a3cce3983f0780820c98 # v3.28.1
41+ uses : github/codeql-action/init@c6f931105cb2c34c8f901cc885ba1e2e259cf745 # v3
6942 with :
7043 languages : ${{ matrix.language }}
71- build-mode : none
44+ build-mode : ${{ matrix.build-mode }}
7245
7346 - name : Perform CodeQL Analysis
74- uses : github/codeql-action/analyze@0d579ffd059c29b07949a3cce3983f0780820c98 # v3.28.1
47+ uses : github/codeql-action/analyze@c6f931105cb2c34c8f901cc885ba1e2e259cf745 # v3
7548 with :
7649 category : " /language:${{ matrix.language }}"
0 commit comments