-
Notifications
You must be signed in to change notification settings - Fork 5
147 lines (131 loc) · 5.67 KB
/
Copy pathcodeql.yml
File metadata and controls
147 lines (131 loc) · 5.67 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
# Advisory CodeQL code scanning (audit register PR-CQ-22). Not part of CI / Gate: findings go to the Security tab and
# appear as pull request annotations.
# - C#: a manual, traced Release build of the shipped product graph (src/CheatEngine.SDK builds the six libraries, the
# analyzers and every source generator it packs), so generated code is analysed; build-mode none would skip it.
# - C/C++: the native bridge and the ABI fixture sources, without a build (build-mode none), on Windows so the
# extractor sees the Windows SDK headers.
# - GitHub Actions: the workflows and the composite action.
# The repository's code-scanning default setup must stay OFF: GitHub rejects advanced-setup uploads while it is on.
# No NuGet, dependency or TRAP cache: no cache on any path reachable by codeql (shared-contracts 1.5).
# A fork pull request gets a read-only token, so its SARIF upload can fail; the workflow is advisory and never moves to
# pull_request_target.
name: CodeQL
on:
push:
branches: [ main ]
pull_request:
types: [ opened, synchronize, reopened, ready_for_review ]
schedule:
- cron: '17 3 * * 1'
workflow_dispatch:
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
permissions:
contents: read
defaults:
run:
shell: pwsh
jobs:
csharp:
name: Analyze (csharp)
if: ${{ github.event_name != 'pull_request' || !github.event.pull_request.draft }}
runs-on: windows-2025
timeout-minutes: 45
permissions:
contents: read
security-events: write # upload CodeQL SARIF
actions: read # CodeQL reads workflow run metadata
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0 # MinVer computes the real version, so no version-dependent guard sees a fallback
persist-credentials: false
- name: Set up .NET and restore the product graph
uses: ./.github/actions/setup-dotnet
with:
restore: src/CheatEngine.SDK/CheatEngine.SDK.csproj
- name: Initialize CodeQL
uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
languages: csharp
build-mode: manual
queries: security-extended
dependency-caching: false
trap-caching: false
# The compiler must run inside the traced build: no incremental skip, no build server, no compiler server (the
# tracer only sees newly created csc processes). CodeQL injects EmitCompilerGeneratedFiles itself.
# https://learn.microsoft.com/dotnet/core/tools/dotnet-build
# https://docs.github.com/en/code-security/reference/code-scanning/codeql/build-options-for-compiled-languages
- name: Build the shipped product graph
run: |
$ErrorActionPreference = 'Stop'
dotnet build src/CheatEngine.SDK/CheatEngine.SDK.csproj -c Release --no-restore --no-incremental --disable-build-servers -p:UseSharedCompilation=false -bl:artifacts/logs/codeql-csharp.binlog
if ($LASTEXITCODE -ne 0) {
throw "CodeQL traced build failed with exit code $LASTEXITCODE."
}
- name: Analyze
uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
category: /language:csharp
- name: Upload binary log
if: failure()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: binlogs-codeql
path: artifacts/logs/*.binlog
if-no-files-found: ignore
retention-days: 5
cpp:
name: Analyze (c-cpp)
if: ${{ github.event_name != 'pull_request' || !github.event.pull_request.draft }}
runs-on: windows-2025
timeout-minutes: 20
permissions:
contents: read
security-events: write # upload CodeQL SARIF
actions: read # CodeQL reads workflow run metadata
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Initialize CodeQL
uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
languages: c-cpp
build-mode: none
queries: security-extended
dependency-caching: false
trap-caching: false
- name: Analyze
uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
category: /language:c-cpp
actions:
name: Analyze (actions)
if: ${{ github.event_name != 'pull_request' || !github.event.pull_request.draft }}
runs-on: ubuntu-24.04
timeout-minutes: 15
permissions:
contents: read
security-events: write # upload CodeQL SARIF
actions: read # CodeQL reads workflow run metadata
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Initialize CodeQL
uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
languages: actions
build-mode: none
queries: security-extended
dependency-caching: false
trap-caching: false
- name: Analyze
uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
category: /language:actions