Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
214 changes: 107 additions & 107 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
@@ -1,107 +1,107 @@
# Advisory CodeQL code scanning. Not part of CI / Gate: findings appear in the Security tab and as PR annotations.
# C# is analysed from a manual, traced Release build of the shipped product graph (src/CheatEngine.Client builds every
# shipped assembly and the Lua source generator), so source-generator output is analysed; `build-mode: none` would skip
# generated code. GitHub Actions workflows are analysed without a build. The Client detects no other language.
# Keep the repository's code-scanning default setup OFF: GitHub rejects advanced uploads while it is enabled.
# No dependency or TRAP cache (shared-contracts §1.5: no cache on any path reachable by release, sonar or codeql).
name: CodeQL

on:
pull_request:
push:
branches: [ main ]
schedule:
- cron: '23 4 * * 1'
workflow_dispatch:

concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}

permissions:
contents: read

defaults:
run:
shell: pwsh

jobs:
csharp:
name: Analyze C#
runs-on: windows-2025
timeout-minutes: 45
permissions:
contents: read
security-events: write # upload the SARIF results
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0 # MinVer computes the package version from the tag history
persist-credentials: false

- name: Set up .NET and restore the product graph (locked)
uses: ./.github/actions/setup-dotnet
with:
restore: src/CheatEngine.Client/CheatEngine.Client.csproj
cache: 'false'

- name: Initialize CodeQL
uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1
with:
languages: csharp
build-mode: manual
queries: security-extended
dependency-caching: false
trap-caching: false

# The compiler must run inside the traced process: no incremental skip, no compiler server, no build server.
# https://learn.microsoft.com/dotnet/core/tools/dotnet-build#options
- name: Build the shipped product graph
run: |
$ErrorActionPreference = 'Stop'
dotnet build src/CheatEngine.Client/CheatEngine.Client.csproj --configuration Release --no-restore `
--no-incremental --disable-build-servers -p:UseSharedCompilation=false `
-bl:artifacts/logs/codeql-csharp.binlog
if ($LASTEXITCODE -ne 0) {
throw "dotnet build failed with exit code $LASTEXITCODE."
}

- name: Analyze
uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1
with:
category: /language:csharp

- name: Upload binlog
if: failure()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: binlogs-codeql-csharp
path: artifacts/logs/*.binlog
if-no-files-found: ignore
retention-days: 5

actions:
name: Analyze GitHub Actions
runs-on: ubuntu-24.04
timeout-minutes: 15
permissions:
contents: read
security-events: write # upload the SARIF results
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false

- name: Initialize CodeQL
uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1
with:
languages: actions
build-mode: none
queries: security-extended

- name: Analyze
uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1
with:
category: /language:actions
# Advisory CodeQL code scanning. Not part of CI / Gate: findings appear in the Security tab and as PR annotations.
# C# is analysed from a manual, traced Release build of the shipped product graph (src/CheatEngine.Client builds every
# shipped assembly and the Lua source generator), so source-generator output is analysed; `build-mode: none` would skip
# generated code. GitHub Actions workflows are analysed without a build. The Client detects no other language.
# Keep the repository's code-scanning default setup OFF: GitHub rejects advanced uploads while it is enabled.
# No dependency or TRAP cache (shared-contracts §1.5: no cache on any path reachable by release, sonar or codeql).
name: CodeQL
on:
pull_request:
push:
branches: [ main ]
schedule:
- cron: '23 4 * * 1'
workflow_dispatch:
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
permissions:
contents: read
defaults:
run:
shell: pwsh
jobs:
csharp:
name: Analyze C#
runs-on: windows-2025
timeout-minutes: 45
permissions:
contents: read
security-events: write # upload the SARIF results
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0 # MinVer computes the package version from the tag history
persist-credentials: false
- name: Set up .NET and restore the product graph (locked)
uses: ./.github/actions/setup-dotnet
with:
restore: src/CheatEngine.Client/CheatEngine.Client.csproj
cache: 'false'
- name: Initialize CodeQL
uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
languages: csharp
build-mode: manual
queries: security-extended
dependency-caching: false
trap-caching: false
# The compiler must run inside the traced process: no incremental skip, no compiler server, no build server.
# https://learn.microsoft.com/dotnet/core/tools/dotnet-build#options
- name: Build the shipped product graph
run: |
$ErrorActionPreference = 'Stop'
dotnet build src/CheatEngine.Client/CheatEngine.Client.csproj --configuration Release --no-restore `
--no-incremental --disable-build-servers -p:UseSharedCompilation=false `
-bl:artifacts/logs/codeql-csharp.binlog
if ($LASTEXITCODE -ne 0) {
throw "dotnet build failed with exit code $LASTEXITCODE."
}
- name: Analyze
uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
category: /language:csharp
- name: Upload binlog
if: failure()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: binlogs-codeql-csharp
path: artifacts/logs/*.binlog
if-no-files-found: ignore
retention-days: 5
actions:
name: Analyze GitHub Actions
runs-on: ubuntu-24.04
timeout-minutes: 15
permissions:
contents: read
security-events: write # upload the SARIF results
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Initialize CodeQL
uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
languages: actions
build-mode: none
queries: security-extended
- name: Analyze
uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
category: /language:actions
108 changes: 54 additions & 54 deletions .github/workflows/scorecard.yml
Original file line number Diff line number Diff line change
@@ -1,54 +1,54 @@
# Advisory OpenSSF Scorecard (https://github.com/ossf/scorecard-action). Not part of CI / Gate, no score target.
# With publish_results: true the Scorecard API verifies this file and rejects: workflow-level or job-level `env` and
# `defaults`, workflow-level write permissions, `id-token: write` outside this job, `container`/`services`, `run:`
# steps and actions outside its allowlist. This file therefore deliberately does NOT follow the repository's
# `defaults: run: shell: pwsh` convention. Publication works from the default branch only (post-merge check).
# Expected low checks, explained rather than fixed: Code-Review (single maintainer), Branch-Protection (until branch
# protection rules are configured on this repository), Signed-Releases (until the first release), SAST (until CodeQL
# has history).
name: Scorecard

on:
branch_protection_rule:
push:
branches: [ main ]
schedule:
- cron: '41 5 * * 1'

permissions:
contents: read

jobs:
analysis:
name: Scorecard analysis
runs-on: ubuntu-24.04
timeout-minutes: 15
permissions:
contents: read
security-events: write # upload the SARIF results to code scanning
id-token: write # publish_results: signed upload to the Scorecard API
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false

# No repo_token: rulesets are readable with the default token.
- name: Run Scorecard
uses: ossf/scorecard-action@2d1146689b8cda280b9bc96326124645441f03bc # v2.4.4
with:
results_file: results.sarif
results_format: sarif
publish_results: true

- name: Upload results
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: scorecard-results
path: results.sarif
retention-days: 5

- name: Upload to code scanning
uses: github/codeql-action/upload-sarif@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1
with:
sarif_file: results.sarif
# Advisory OpenSSF Scorecard (https://github.com/ossf/scorecard-action). Not part of CI / Gate, no score target.
# With publish_results: true the Scorecard API verifies this file and rejects: workflow-level or job-level `env` and
# `defaults`, workflow-level write permissions, `id-token: write` outside this job, `container`/`services`, `run:`
# steps and actions outside its allowlist. This file therefore deliberately does NOT follow the repository's
# `defaults: run: shell: pwsh` convention. Publication works from the default branch only (post-merge check).
# Expected low checks, explained rather than fixed: Code-Review (single maintainer), Branch-Protection (until branch
# protection rules are configured on this repository), Signed-Releases (until the first release), SAST (until CodeQL
# has history).
name: Scorecard
on:
branch_protection_rule:
push:
branches: [ main ]
schedule:
- cron: '41 5 * * 1'
permissions:
contents: read
jobs:
analysis:
name: Scorecard analysis
runs-on: ubuntu-24.04
timeout-minutes: 15
permissions:
contents: read
security-events: write # upload the SARIF results to code scanning
id-token: write # publish_results: signed upload to the Scorecard API
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
# No repo_token: rulesets are readable with the default token.
- name: Run Scorecard
uses: ossf/scorecard-action@2d1146689b8cda280b9bc96326124645441f03bc # v2.4.4
with:
results_file: results.sarif
results_format: sarif
publish_results: true
- name: Upload results
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: scorecard-results
path: results.sarif
retention-days: 5
- name: Upload to code scanning
uses: github/codeql-action/upload-sarif@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
sarif_file: results.sarif
Loading