From dda610e7c6ee8593604f814fb4ce60c0b8a03c5e Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 1 Oct 2026 08:21:13 +0000 Subject: [PATCH] Bump the actions group across 1 directory with 3 updates Bumps the actions group with 3 updates in the / directory: [github/codeql-action/init](https://github.com/github/codeql-action), [github/codeql-action/analyze](https://github.com/github/codeql-action) and [github/codeql-action/upload-sarif](https://github.com/github/codeql-action). Updates `github/codeql-action/init` from 4.38.1 to 4.38.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/1c5b675653bb5c22dbe9b12b556ec555138e09fd...2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2) Updates `github/codeql-action/analyze` from 4.38.1 to 4.38.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/1c5b675653bb5c22dbe9b12b556ec555138e09fd...2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2) Updates `github/codeql-action/upload-sarif` from 4.38.1 to 4.38.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/1c5b675653bb5c22dbe9b12b556ec555138e09fd...2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2) --- updated-dependencies: - dependency-name: github/codeql-action/init dependency-version: 4.38.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: github/codeql-action/analyze dependency-version: 4.38.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.38.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions ... Signed-off-by: dependabot[bot] --- .github/workflows/codeql.yml | 294 ++++++++++++++++---------------- .github/workflows/scorecard.yml | 104 +++++------ 2 files changed, 199 insertions(+), 199 deletions(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index acc99a5..ca6767a 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -1,147 +1,147 @@ -# Advisory CodeQL code scanning (audit register PR-CQ-22). Not part of CI / Gate: findings go to the Security tab and -# appear as pull request annotations. -# - C#: a manual, traced Release build of the shipped product graph (src/CheatEngine.SDK builds the six libraries, the -# analyzers and every source generator it packs), so generated code is analysed; build-mode none would skip it. -# - C/C++: the native bridge and the ABI fixture sources, without a build (build-mode none), on Windows so the -# extractor sees the Windows SDK headers. -# - GitHub Actions: the workflows and the composite action. -# The repository's code-scanning default setup must stay OFF: GitHub rejects advanced-setup uploads while it is on. -# No NuGet, dependency or TRAP cache: no cache on any path reachable by codeql (shared-contracts 1.5). -# A fork pull request gets a read-only token, so its SARIF upload can fail; the workflow is advisory and never moves to -# pull_request_target. -name: CodeQL - -on: - push: - branches: [ main ] - pull_request: - types: [ opened, synchronize, reopened, ready_for_review ] - schedule: - - cron: '17 3 * * 1' - workflow_dispatch: - -concurrency: - group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} - cancel-in-progress: ${{ github.event_name == 'pull_request' }} - -permissions: - contents: read - -defaults: - run: - shell: pwsh - -jobs: - csharp: - name: Analyze (csharp) - if: ${{ github.event_name != 'pull_request' || !github.event.pull_request.draft }} - runs-on: windows-2025 - timeout-minutes: 45 - permissions: - contents: read - security-events: write # upload CodeQL SARIF - actions: read # CodeQL reads workflow run metadata - steps: - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - fetch-depth: 0 # MinVer computes the real version, so no version-dependent guard sees a fallback - persist-credentials: false - - - name: Set up .NET and restore the product graph - uses: ./.github/actions/setup-dotnet - with: - restore: src/CheatEngine.SDK/CheatEngine.SDK.csproj - - - name: Initialize CodeQL - uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 - with: - languages: csharp - build-mode: manual - queries: security-extended - dependency-caching: false - trap-caching: false - - # The compiler must run inside the traced build: no incremental skip, no build server, no compiler server (the - # tracer only sees newly created csc processes). CodeQL injects EmitCompilerGeneratedFiles itself. - # https://learn.microsoft.com/dotnet/core/tools/dotnet-build - # https://docs.github.com/en/code-security/reference/code-scanning/codeql/build-options-for-compiled-languages - - name: Build the shipped product graph - run: | - $ErrorActionPreference = 'Stop' - dotnet build src/CheatEngine.SDK/CheatEngine.SDK.csproj -c Release --no-restore --no-incremental --disable-build-servers -p:UseSharedCompilation=false -bl:artifacts/logs/codeql-csharp.binlog - if ($LASTEXITCODE -ne 0) { - throw "CodeQL traced build failed with exit code $LASTEXITCODE." - } - - - name: Analyze - uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 - with: - category: /language:csharp - - - name: Upload binary log - if: failure() - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 - with: - name: binlogs-codeql - path: artifacts/logs/*.binlog - if-no-files-found: ignore - retention-days: 5 - - cpp: - name: Analyze (c-cpp) - if: ${{ github.event_name != 'pull_request' || !github.event.pull_request.draft }} - runs-on: windows-2025 - timeout-minutes: 20 - permissions: - contents: read - security-events: write # upload CodeQL SARIF - actions: read # CodeQL reads workflow run metadata - steps: - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - - name: Initialize CodeQL - uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 - with: - languages: c-cpp - build-mode: none - queries: security-extended - dependency-caching: false - trap-caching: false - - - name: Analyze - uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 - with: - category: /language:c-cpp - - actions: - name: Analyze (actions) - if: ${{ github.event_name != 'pull_request' || !github.event.pull_request.draft }} - runs-on: ubuntu-24.04 - timeout-minutes: 15 - permissions: - contents: read - security-events: write # upload CodeQL SARIF - actions: read # CodeQL reads workflow run metadata - steps: - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - - name: Initialize CodeQL - uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 - with: - languages: actions - build-mode: none - queries: security-extended - dependency-caching: false - trap-caching: false - - - name: Analyze - uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 - with: - category: /language:actions +# Advisory CodeQL code scanning (audit register PR-CQ-22). Not part of CI / Gate: findings go to the Security tab and +# appear as pull request annotations. +# - C#: a manual, traced Release build of the shipped product graph (src/CheatEngine.SDK builds the six libraries, the +# analyzers and every source generator it packs), so generated code is analysed; build-mode none would skip it. +# - C/C++: the native bridge and the ABI fixture sources, without a build (build-mode none), on Windows so the +# extractor sees the Windows SDK headers. +# - GitHub Actions: the workflows and the composite action. +# The repository's code-scanning default setup must stay OFF: GitHub rejects advanced-setup uploads while it is on. +# No NuGet, dependency or TRAP cache: no cache on any path reachable by codeql (shared-contracts 1.5). +# A fork pull request gets a read-only token, so its SARIF upload can fail; the workflow is advisory and never moves to +# pull_request_target. +name: CodeQL + +on: + push: + branches: [ main ] + pull_request: + types: [ opened, synchronize, reopened, ready_for_review ] + schedule: + - cron: '17 3 * * 1' + workflow_dispatch: + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: ${{ github.event_name == 'pull_request' }} + +permissions: + contents: read + +defaults: + run: + shell: pwsh + +jobs: + csharp: + name: Analyze (csharp) + if: ${{ github.event_name != 'pull_request' || !github.event.pull_request.draft }} + runs-on: windows-2025 + timeout-minutes: 45 + permissions: + contents: read + security-events: write # upload CodeQL SARIF + actions: read # CodeQL reads workflow run metadata + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + fetch-depth: 0 # MinVer computes the real version, so no version-dependent guard sees a fallback + persist-credentials: false + + - name: Set up .NET and restore the product graph + uses: ./.github/actions/setup-dotnet + with: + restore: src/CheatEngine.SDK/CheatEngine.SDK.csproj + + - name: Initialize CodeQL + uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 + with: + languages: csharp + build-mode: manual + queries: security-extended + dependency-caching: false + trap-caching: false + + # The compiler must run inside the traced build: no incremental skip, no build server, no compiler server (the + # tracer only sees newly created csc processes). CodeQL injects EmitCompilerGeneratedFiles itself. + # https://learn.microsoft.com/dotnet/core/tools/dotnet-build + # https://docs.github.com/en/code-security/reference/code-scanning/codeql/build-options-for-compiled-languages + - name: Build the shipped product graph + run: | + $ErrorActionPreference = 'Stop' + dotnet build src/CheatEngine.SDK/CheatEngine.SDK.csproj -c Release --no-restore --no-incremental --disable-build-servers -p:UseSharedCompilation=false -bl:artifacts/logs/codeql-csharp.binlog + if ($LASTEXITCODE -ne 0) { + throw "CodeQL traced build failed with exit code $LASTEXITCODE." + } + + - name: Analyze + uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 + with: + category: /language:csharp + + - name: Upload binary log + if: failure() + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: binlogs-codeql + path: artifacts/logs/*.binlog + if-no-files-found: ignore + retention-days: 5 + + cpp: + name: Analyze (c-cpp) + if: ${{ github.event_name != 'pull_request' || !github.event.pull_request.draft }} + runs-on: windows-2025 + timeout-minutes: 20 + permissions: + contents: read + security-events: write # upload CodeQL SARIF + actions: read # CodeQL reads workflow run metadata + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + - name: Initialize CodeQL + uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 + with: + languages: c-cpp + build-mode: none + queries: security-extended + dependency-caching: false + trap-caching: false + + - name: Analyze + uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 + with: + category: /language:c-cpp + + actions: + name: Analyze (actions) + if: ${{ github.event_name != 'pull_request' || !github.event.pull_request.draft }} + runs-on: ubuntu-24.04 + timeout-minutes: 15 + permissions: + contents: read + security-events: write # upload CodeQL SARIF + actions: read # CodeQL reads workflow run metadata + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + - name: Initialize CodeQL + uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 + with: + languages: actions + build-mode: none + queries: security-extended + dependency-caching: false + trap-caching: false + + - name: Analyze + uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 + with: + category: /language:actions diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 1567068..51d3028 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -1,52 +1,52 @@ -# Advisory OpenSSF Scorecard (audit register PR-CQ-24; https://github.com/ossf/scorecard-action). Not part of CI / Gate, -# no score target. With publish_results: true the Scorecard API verifies this file and rejects: workflow-level `env` -# or `defaults`, workflow-level write permissions, `id-token` in any other job, job-level `env` or `defaults`, -# containers and services, any step without `uses:` (so no `run:` step), actions outside its allowlist, and runners -# other than ubuntu-latest or ubuntu-NN.NN (NN.NN >= 22.04). This file therefore deliberately does NOT follow the -# repository's `defaults: run: shell: pwsh` convention. -# Publication works from the default branch only: the first run happens after merge. Expected low checks, explained -# rather than chased: Binary-Artifacts (the Lua fixture and the bridge, see SECURITY.md), Code-Review (single -# maintainer), Branch-Protection (until the maintainer configures it in the repository's GitHub settings). -name: Scorecard - -on: - branch_protection_rule: - push: - branches: [ main ] - schedule: - - cron: '23 4 * * 1' - -permissions: - contents: read - -jobs: - analysis: - name: Scorecard analysis - runs-on: ubuntu-24.04 - timeout-minutes: 15 - permissions: - contents: read - security-events: write # upload the SARIF results to code scanning - id-token: write # publish_results: sign the upload to the OpenSSF Scorecard API - actions: read # the Scorecard checks read workflow runs - issues: read # the Scorecard checks read issues - pull-requests: read # the Code-Review check reads pull requests - checks: read # the CI-Tests check reads check runs - steps: - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - # No repo_token: the default token reads the rulesets of a public repository. - - name: Run Scorecard - uses: ossf/scorecard-action@2d1146689b8cda280b9bc96326124645441f03bc # v2.4.4 - with: - results_file: results.sarif - results_format: sarif - publish_results: true - - - name: Upload to code scanning - uses: github/codeql-action/upload-sarif@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 - with: - sarif_file: results.sarif +# Advisory OpenSSF Scorecard (audit register PR-CQ-24; https://github.com/ossf/scorecard-action). Not part of CI / Gate, +# no score target. With publish_results: true the Scorecard API verifies this file and rejects: workflow-level `env` +# or `defaults`, workflow-level write permissions, `id-token` in any other job, job-level `env` or `defaults`, +# containers and services, any step without `uses:` (so no `run:` step), actions outside its allowlist, and runners +# other than ubuntu-latest or ubuntu-NN.NN (NN.NN >= 22.04). This file therefore deliberately does NOT follow the +# repository's `defaults: run: shell: pwsh` convention. +# Publication works from the default branch only: the first run happens after merge. Expected low checks, explained +# rather than chased: Binary-Artifacts (the Lua fixture and the bridge, see SECURITY.md), Code-Review (single +# maintainer), Branch-Protection (until the maintainer configures it in the repository's GitHub settings). +name: Scorecard + +on: + branch_protection_rule: + push: + branches: [ main ] + schedule: + - cron: '23 4 * * 1' + +permissions: + contents: read + +jobs: + analysis: + name: Scorecard analysis + runs-on: ubuntu-24.04 + timeout-minutes: 15 + permissions: + contents: read + security-events: write # upload the SARIF results to code scanning + id-token: write # publish_results: sign the upload to the OpenSSF Scorecard API + actions: read # the Scorecard checks read workflow runs + issues: read # the Scorecard checks read issues + pull-requests: read # the Code-Review check reads pull requests + checks: read # the CI-Tests check reads check runs + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + # No repo_token: the default token reads the rulesets of a public repository. + - name: Run Scorecard + uses: ossf/scorecard-action@2d1146689b8cda280b9bc96326124645441f03bc # v2.4.4 + with: + results_file: results.sarif + results_format: sarif + publish_results: true + + - name: Upload to code scanning + uses: github/codeql-action/upload-sarif@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 + with: + sarif_file: results.sarif