diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 4fca50e9..42324e0b 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -15,151 +15,8 @@ permissions: packages: read security-events: write -env: - REPO_FOUNDRY_PROFILE: ${{ vars.REPO_FOUNDRY_PROFILE }} - REPO_FOUNDRY_LANGUAGES: ${{ vars.REPO_FOUNDRY_LANGUAGES }} - REPO_FOUNDRY_FEATURES: ${{ vars.REPO_FOUNDRY_FEATURES }} - -concurrency: - group: ${{ github.workflow }}-${{ github.event.pull_request.head.repo.full_name || github.repository }}-${{ github.event.pull_request.head.ref || github.ref_name }} - cancel-in-progress: true - jobs: - detect: - name: Detect - runs-on: ubuntu-slim - timeout-minutes: 10 - outputs: - languages: ${{ steps.languages.outputs.languages }} - code_security: ${{ steps.security.outputs.status }} - actions_available: ${{ steps.languages.outputs.actions_available }} - actions_changed: ${{ steps.languages.outputs.actions_changed }} - actions_build_mode: ${{ steps.languages.outputs.actions_build_mode }} - javascript_available: ${{ steps.languages.outputs.javascript_available }} - javascript_changed: ${{ steps.languages.outputs.javascript_changed }} - javascript_build_mode: ${{ steps.languages.outputs.javascript_build_mode }} - python_available: ${{ steps.languages.outputs.python_available }} - python_changed: ${{ steps.languages.outputs.python_changed }} - python_build_mode: ${{ steps.languages.outputs.python_build_mode }} - rust_available: ${{ steps.languages.outputs.rust_available }} - rust_changed: ${{ steps.languages.outputs.rust_changed }} - rust_build_mode: ${{ steps.languages.outputs.rust_build_mode }} - steps: - - name: Detect Code Security - id: security - env: - GH_TOKEN: ${{ github.token }} - run: | - status="disabled" - if [ "${{ github.event.repository.private }}" != "true" ]; then - status="enabled" - else - status="$(gh api "repos/${GITHUB_REPOSITORY}" --jq '.security_and_analysis.code_security.status // "disabled"' 2>/dev/null || printf 'disabled')" - fi - printf 'status=%s\n' "$status" >> "$GITHUB_OUTPUT" - - name: Checkout - if: ${{ !github.event.repository.private || steps.security.outputs.status == 'enabled' }} - uses: actions/checkout@v7 - with: - fetch-depth: 2 - # Detection only reads Git trees, paths, and small profile files; - # defer source blob transfer until the analyzer jobs. - filter: blob:none - sparse-checkout: | - .github - .mise.toml - mise.lock - package.json - bun.lock - bun.lockb - pnpm-lock.yaml - yarn.lock - package-lock.json - - id: languages - name: Detect languages - env: - CODEQL_BASE_SHA: ${{ github.event_name == 'pull_request' && github.event.pull_request.base.sha || github.event.before }} - REPO_FOUNDRY_CODE_SECURITY: ${{ steps.security.outputs.status }} - REPO_FOUNDRY_PRIVATE: ${{ github.event.repository.private }} - run: | - if [ "$REPO_FOUNDRY_PRIVATE" = "true" ] && [ "$REPO_FOUNDRY_CODE_SECURITY" != "enabled" ]; then - echo 'languages=[]' >> "$GITHUB_OUTPUT" - else - bash .github/scripts/codeql-languages.sh - fi - - analyze-actions: - name: Analyze (Actions) - needs: detect - if: >- - ( !github.event.repository.private || needs.detect.outputs.code_security == 'enabled' ) && - needs.detect.outputs.actions_available == 'true' && - needs.detect.outputs.actions_changed == 'true' - runs-on: ubuntu-latest - timeout-minutes: 30 - steps: - - name: Checkout - uses: actions/checkout@v7 - - name: Analyze - uses: ./.github/actions/codeql - with: - language: actions - build-mode: ${{ needs.detect.outputs.actions_build_mode }} - category: /language:actions - - analyze-typescript: - name: Analyze (TypeScript) - needs: detect - if: >- - ( !github.event.repository.private || needs.detect.outputs.code_security == 'enabled' ) && - needs.detect.outputs.javascript_available == 'true' && - needs.detect.outputs.javascript_changed == 'true' - runs-on: ubuntu-latest - timeout-minutes: 30 - steps: - - name: Checkout - uses: actions/checkout@v7 - - name: Analyze - uses: ./.github/actions/codeql - with: - language: javascript-typescript - build-mode: ${{ needs.detect.outputs.javascript_build_mode }} - category: /language:javascript-typescript - - analyze-python: - name: Analyze (Python) - needs: detect - if: >- - ( !github.event.repository.private || needs.detect.outputs.code_security == 'enabled' ) && - needs.detect.outputs.python_available == 'true' && - needs.detect.outputs.python_changed == 'true' - runs-on: ubuntu-latest - timeout-minutes: 30 - steps: - - name: Checkout - uses: actions/checkout@v7 - - name: Analyze - uses: ./.github/actions/codeql - with: - language: python - build-mode: ${{ needs.detect.outputs.python_build_mode }} - category: /language:python - - analyze-rust: - name: Analyze (Rust) - needs: detect - if: >- - ( !github.event.repository.private || needs.detect.outputs.code_security == 'enabled' ) && - needs.detect.outputs.rust_available == 'true' && - needs.detect.outputs.rust_changed == 'true' - runs-on: ubuntu-latest - timeout-minutes: 30 - steps: - - name: Checkout - uses: actions/checkout@v7 - - name: Analyze - uses: ./.github/actions/codeql - with: - language: rust - build-mode: ${{ needs.detect.outputs.rust_build_mode }} - category: /language:rust + codeql: + name: CodeQL + uses: 0xPlayerOne/code-foundry/.github/workflows/reusable-codeql.yml@v0.12.0 + secrets: inherit