diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 0baebc7..a5f4c35 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -1,107 +1,107 @@ -# Advisory CodeQL code scanning. Not part of CI / Gate: findings appear in the Security tab and as PR annotations. -# C# is analysed from a manual, traced Release build of the shipped product graph (src/CheatEngine.Client builds every -# shipped assembly and the Lua source generator), so source-generator output is analysed; `build-mode: none` would skip -# generated code. GitHub Actions workflows are analysed without a build. The Client detects no other language. -# Keep the repository's code-scanning default setup OFF: GitHub rejects advanced uploads while it is enabled. -# No dependency or TRAP cache (shared-contracts §1.5: no cache on any path reachable by release, sonar or codeql). -name: CodeQL - -on: - pull_request: - push: - branches: [ main ] - schedule: - - cron: '23 4 * * 1' - workflow_dispatch: - -concurrency: - group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} - cancel-in-progress: ${{ github.event_name == 'pull_request' }} - -permissions: - contents: read - -defaults: - run: - shell: pwsh - -jobs: - csharp: - name: Analyze C# - runs-on: windows-2025 - timeout-minutes: 45 - permissions: - contents: read - security-events: write # upload the SARIF results - steps: - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - fetch-depth: 0 # MinVer computes the package version from the tag history - persist-credentials: false - - - name: Set up .NET and restore the product graph (locked) - uses: ./.github/actions/setup-dotnet - with: - restore: src/CheatEngine.Client/CheatEngine.Client.csproj - cache: 'false' - - - name: Initialize CodeQL - uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 - with: - languages: csharp - build-mode: manual - queries: security-extended - dependency-caching: false - trap-caching: false - - # The compiler must run inside the traced process: no incremental skip, no compiler server, no build server. - # https://learn.microsoft.com/dotnet/core/tools/dotnet-build#options - - name: Build the shipped product graph - run: | - $ErrorActionPreference = 'Stop' - dotnet build src/CheatEngine.Client/CheatEngine.Client.csproj --configuration Release --no-restore ` - --no-incremental --disable-build-servers -p:UseSharedCompilation=false ` - -bl:artifacts/logs/codeql-csharp.binlog - if ($LASTEXITCODE -ne 0) { - throw "dotnet build failed with exit code $LASTEXITCODE." - } - - - name: Analyze - uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 - with: - category: /language:csharp - - - name: Upload binlog - if: failure() - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 - with: - name: binlogs-codeql-csharp - path: artifacts/logs/*.binlog - if-no-files-found: ignore - retention-days: 5 - - actions: - name: Analyze GitHub Actions - runs-on: ubuntu-24.04 - timeout-minutes: 15 - permissions: - contents: read - security-events: write # upload the SARIF results - steps: - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - - name: Initialize CodeQL - uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 - with: - languages: actions - build-mode: none - queries: security-extended - - - name: Analyze - uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 - with: - category: /language:actions +# Advisory CodeQL code scanning. Not part of CI / Gate: findings appear in the Security tab and as PR annotations. +# C# is analysed from a manual, traced Release build of the shipped product graph (src/CheatEngine.Client builds every +# shipped assembly and the Lua source generator), so source-generator output is analysed; `build-mode: none` would skip +# generated code. GitHub Actions workflows are analysed without a build. The Client detects no other language. +# Keep the repository's code-scanning default setup OFF: GitHub rejects advanced uploads while it is enabled. +# No dependency or TRAP cache (shared-contracts §1.5: no cache on any path reachable by release, sonar or codeql). +name: CodeQL + +on: + pull_request: + push: + branches: [ main ] + schedule: + - cron: '23 4 * * 1' + workflow_dispatch: + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: ${{ github.event_name == 'pull_request' }} + +permissions: + contents: read + +defaults: + run: + shell: pwsh + +jobs: + csharp: + name: Analyze C# + runs-on: windows-2025 + timeout-minutes: 45 + permissions: + contents: read + security-events: write # upload the SARIF results + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + fetch-depth: 0 # MinVer computes the package version from the tag history + persist-credentials: false + + - name: Set up .NET and restore the product graph (locked) + uses: ./.github/actions/setup-dotnet + with: + restore: src/CheatEngine.Client/CheatEngine.Client.csproj + cache: 'false' + + - name: Initialize CodeQL + uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 + with: + languages: csharp + build-mode: manual + queries: security-extended + dependency-caching: false + trap-caching: false + + # The compiler must run inside the traced process: no incremental skip, no compiler server, no build server. + # https://learn.microsoft.com/dotnet/core/tools/dotnet-build#options + - name: Build the shipped product graph + run: | + $ErrorActionPreference = 'Stop' + dotnet build src/CheatEngine.Client/CheatEngine.Client.csproj --configuration Release --no-restore ` + --no-incremental --disable-build-servers -p:UseSharedCompilation=false ` + -bl:artifacts/logs/codeql-csharp.binlog + if ($LASTEXITCODE -ne 0) { + throw "dotnet build failed with exit code $LASTEXITCODE." + } + + - name: Analyze + uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 + with: + category: /language:csharp + + - name: Upload binlog + if: failure() + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: binlogs-codeql-csharp + path: artifacts/logs/*.binlog + if-no-files-found: ignore + retention-days: 5 + + actions: + name: Analyze GitHub Actions + runs-on: ubuntu-24.04 + timeout-minutes: 15 + permissions: + contents: read + security-events: write # upload the SARIF results + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + - name: Initialize CodeQL + uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 + with: + languages: actions + build-mode: none + queries: security-extended + + - name: Analyze + uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 + with: + category: /language:actions diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index a2d601b..f5bad3e 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -1,54 +1,54 @@ -# Advisory OpenSSF Scorecard (https://github.com/ossf/scorecard-action). Not part of CI / Gate, no score target. -# With publish_results: true the Scorecard API verifies this file and rejects: workflow-level or job-level `env` and -# `defaults`, workflow-level write permissions, `id-token: write` outside this job, `container`/`services`, `run:` -# steps and actions outside its allowlist. This file therefore deliberately does NOT follow the repository's -# `defaults: run: shell: pwsh` convention. Publication works from the default branch only (post-merge check). -# Expected low checks, explained rather than fixed: Code-Review (single maintainer), Branch-Protection (until branch -# protection rules are configured on this repository), Signed-Releases (until the first release), SAST (until CodeQL -# has history). -name: Scorecard - -on: - branch_protection_rule: - push: - branches: [ main ] - schedule: - - cron: '41 5 * * 1' - -permissions: - contents: read - -jobs: - analysis: - name: Scorecard analysis - runs-on: ubuntu-24.04 - timeout-minutes: 15 - permissions: - contents: read - security-events: write # upload the SARIF results to code scanning - id-token: write # publish_results: signed upload to the Scorecard API - steps: - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - # No repo_token: rulesets are readable with the default token. - - name: Run Scorecard - uses: ossf/scorecard-action@2d1146689b8cda280b9bc96326124645441f03bc # v2.4.4 - with: - results_file: results.sarif - results_format: sarif - publish_results: true - - - name: Upload results - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 - with: - name: scorecard-results - path: results.sarif - retention-days: 5 - - - name: Upload to code scanning - uses: github/codeql-action/upload-sarif@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 - with: - sarif_file: results.sarif +# Advisory OpenSSF Scorecard (https://github.com/ossf/scorecard-action). Not part of CI / Gate, no score target. +# With publish_results: true the Scorecard API verifies this file and rejects: workflow-level or job-level `env` and +# `defaults`, workflow-level write permissions, `id-token: write` outside this job, `container`/`services`, `run:` +# steps and actions outside its allowlist. This file therefore deliberately does NOT follow the repository's +# `defaults: run: shell: pwsh` convention. Publication works from the default branch only (post-merge check). +# Expected low checks, explained rather than fixed: Code-Review (single maintainer), Branch-Protection (until branch +# protection rules are configured on this repository), Signed-Releases (until the first release), SAST (until CodeQL +# has history). +name: Scorecard + +on: + branch_protection_rule: + push: + branches: [ main ] + schedule: + - cron: '41 5 * * 1' + +permissions: + contents: read + +jobs: + analysis: + name: Scorecard analysis + runs-on: ubuntu-24.04 + timeout-minutes: 15 + permissions: + contents: read + security-events: write # upload the SARIF results to code scanning + id-token: write # publish_results: signed upload to the Scorecard API + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + # No repo_token: rulesets are readable with the default token. + - name: Run Scorecard + uses: ossf/scorecard-action@2d1146689b8cda280b9bc96326124645441f03bc # v2.4.4 + with: + results_file: results.sarif + results_format: sarif + publish_results: true + + - name: Upload results + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: scorecard-results + path: results.sarif + retention-days: 5 + + - name: Upload to code scanning + uses: github/codeql-action/upload-sarif@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 + with: + sarif_file: results.sarif