feat(security): add reusable security workflow runtime #352
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CodeQL | |
| on: | |
| push: | |
| branches: [main, staging] | |
| pull_request: | |
| branches: [staging] | |
| schedule: | |
| - cron: '31 6 * * 1' | |
| workflow_dispatch: | |
| permissions: | |
| actions: read | |
| contents: read | |
| packages: read | |
| security-events: write | |
| env: | |
| REPO_FOUNDRY_PROFILE: ${{ vars.REPO_FOUNDRY_PROFILE }} | |
| REPO_FOUNDRY_LANGUAGES: ${{ vars.REPO_FOUNDRY_LANGUAGES }} | |
| REPO_FOUNDRY_FEATURES: ${{ vars.REPO_FOUNDRY_FEATURES }} | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.event.pull_request.head.repo.full_name || github.repository }}-${{ github.event.pull_request.head.ref || github.ref_name }} | |
| cancel-in-progress: true | |
| jobs: | |
| detect: | |
| name: Detect | |
| runs-on: ubuntu-slim | |
| timeout-minutes: 10 | |
| outputs: | |
| languages: ${{ steps.languages.outputs.languages }} | |
| code_security: ${{ steps.security.outputs.status }} | |
| actions_available: ${{ steps.languages.outputs.actions_available }} | |
| actions_changed: ${{ steps.languages.outputs.actions_changed }} | |
| actions_build_mode: ${{ steps.languages.outputs.actions_build_mode }} | |
| javascript_available: ${{ steps.languages.outputs.javascript_available }} | |
| javascript_changed: ${{ steps.languages.outputs.javascript_changed }} | |
| javascript_build_mode: ${{ steps.languages.outputs.javascript_build_mode }} | |
| python_available: ${{ steps.languages.outputs.python_available }} | |
| python_changed: ${{ steps.languages.outputs.python_changed }} | |
| python_build_mode: ${{ steps.languages.outputs.python_build_mode }} | |
| rust_available: ${{ steps.languages.outputs.rust_available }} | |
| rust_changed: ${{ steps.languages.outputs.rust_changed }} | |
| rust_build_mode: ${{ steps.languages.outputs.rust_build_mode }} | |
| steps: | |
| - name: Detect Code Security | |
| id: security | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| run: | | |
| status="disabled" | |
| if [ "${{ github.event.repository.private }}" != "true" ]; then | |
| status="enabled" | |
| else | |
| status="$(gh api "repos/${GITHUB_REPOSITORY}" --jq '.security_and_analysis.code_security.status // "disabled"' 2>/dev/null || printf 'disabled')" | |
| fi | |
| printf 'status=%s\n' "$status" >> "$GITHUB_OUTPUT" | |
| - name: Checkout | |
| if: ${{ !github.event.repository.private || steps.security.outputs.status == 'enabled' }} | |
| uses: actions/checkout@v7 | |
| with: | |
| fetch-depth: 2 | |
| # Detection only reads Git trees, paths, and small profile files; | |
| # defer source blob transfer until the analyzer jobs. | |
| filter: blob:none | |
| sparse-checkout: | | |
| .github | |
| .mise.toml | |
| mise.lock | |
| package.json | |
| bun.lock | |
| bun.lockb | |
| pnpm-lock.yaml | |
| yarn.lock | |
| package-lock.json | |
| - id: languages | |
| name: Detect languages | |
| env: | |
| CODEQL_BASE_SHA: ${{ github.event_name == 'pull_request' && github.event.pull_request.base.sha || github.event.before }} | |
| REPO_FOUNDRY_CODE_SECURITY: ${{ steps.security.outputs.status }} | |
| REPO_FOUNDRY_PRIVATE: ${{ github.event.repository.private }} | |
| run: | | |
| if [ "$REPO_FOUNDRY_PRIVATE" = "true" ] && [ "$REPO_FOUNDRY_CODE_SECURITY" != "enabled" ]; then | |
| echo 'languages=[]' >> "$GITHUB_OUTPUT" | |
| else | |
| bash .github/scripts/codeql-languages.sh | |
| fi | |
| analyze-actions: | |
| name: Analyze (Actions) | |
| needs: detect | |
| if: >- | |
| ( !github.event.repository.private || needs.detect.outputs.code_security == 'enabled' ) && | |
| needs.detect.outputs.actions_available == 'true' && | |
| needs.detect.outputs.actions_changed == 'true' | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 30 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v7 | |
| - name: Analyze | |
| uses: ./.github/actions/codeql | |
| with: | |
| language: actions | |
| build-mode: ${{ needs.detect.outputs.actions_build_mode }} | |
| category: /language:actions | |
| analyze-typescript: | |
| name: Analyze (TypeScript) | |
| needs: detect | |
| if: >- | |
| ( !github.event.repository.private || needs.detect.outputs.code_security == 'enabled' ) && | |
| needs.detect.outputs.javascript_available == 'true' && | |
| needs.detect.outputs.javascript_changed == 'true' | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 30 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v7 | |
| - name: Analyze | |
| uses: ./.github/actions/codeql | |
| with: | |
| language: javascript-typescript | |
| build-mode: ${{ needs.detect.outputs.javascript_build_mode }} | |
| category: /language:javascript-typescript | |
| analyze-python: | |
| name: Analyze (Python) | |
| needs: detect | |
| if: >- | |
| ( !github.event.repository.private || needs.detect.outputs.code_security == 'enabled' ) && | |
| needs.detect.outputs.python_available == 'true' && | |
| needs.detect.outputs.python_changed == 'true' | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 30 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v7 | |
| - name: Analyze | |
| uses: ./.github/actions/codeql | |
| with: | |
| language: python | |
| build-mode: ${{ needs.detect.outputs.python_build_mode }} | |
| category: /language:python | |
| analyze-rust: | |
| name: Analyze (Rust) | |
| needs: detect | |
| if: >- | |
| ( !github.event.repository.private || needs.detect.outputs.code_security == 'enabled' ) && | |
| needs.detect.outputs.rust_available == 'true' && | |
| needs.detect.outputs.rust_changed == 'true' | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 30 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v7 | |
| - name: Analyze | |
| uses: ./.github/actions/codeql | |
| with: | |
| language: rust | |
| build-mode: ${{ needs.detect.outputs.rust_build_mode }} | |
| category: /language:rust |