Skip to content

Merge pull request #89 from GitHubSecurityLab/runcionworkflowchange #102

Merge pull request #89 from GitHubSecurityLab/runcionworkflowchange

Merge pull request #89 from GitHubSecurityLab/runcionworkflowchange #102

Workflow file for this run

name: Publish CodeQL Packs
on:
push:
branches: [main]
workflow_dispatch:
jobs:
queries:
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
strategy:
fail-fast: false
matrix:
language: ["cpp", "csharp", "go", "java", "javascript", "python", "ruby"]
steps:
- uses: actions/checkout@v3
- name: Initialize CodeQL
run: |
VERSION="$(find "${{ runner.tool_cache }}/CodeQL/" -maxdepth 1 -mindepth 1 -type d -print \
| sort \
| tail -n 1 \
| tr -d '\n')"
echo "$VERSION/x64/codeql" >> $GITHUB_PATH
- name: "Check and publish codeql-LANG-queries (src) pack"
env:
GITHUB_TOKEN: ${{ secrets.GHCR_TOKEN }}
run: |
PUBLISHED_VERSION=$(gh api /orgs/githubsecuritylab/packages/container/codeql-${{ matrix.language }}-queries/versions --jq '.[0].metadata.container.tags[0]')
CURRENT_VERSION=$(grep version ${{ matrix.language }}/src/qlpack.yml | awk '{print $2}')
echo "Published verion: $PUBLISHED_VERSION"
echo "Local verion: $CURRENT_VERSION"
if [ "$PUBLISHED_VERSION" != "$CURRENT_VERSION" ]; then
codeql pack install "${{ matrix.language }}/src"
codeql pack publish "${{ matrix.language }}/src"
fi
library:
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
strategy:
fail-fast: false
matrix:
language: ["cpp", "csharp", "go", "java", "javascript", "python", "ruby"]
steps:
- uses: actions/checkout@v3
- name: Initialize CodeQL
run: |
VERSION="$(find "${{ runner.tool_cache }}/CodeQL/" -maxdepth 1 -mindepth 1 -type d -print \
| sort \
| tail -n 1 \
| tr -d '\n')"
echo "$VERSION/x64/codeql" >> $GITHUB_PATH
- name: "Check and publish codeql-LANG-libs (lib) pack"
env:
GITHUB_TOKEN: ${{ secrets.GHCR_TOKEN }}
run: |
PUBLISHED_VERSION=$(gh api /orgs/githubsecuritylab/packages/container/codeql-${{ matrix.language }}-libs/versions --jq '.[0].metadata.container.tags[0]')
CURRENT_VERSION=$(grep version ${{ matrix.language }}/lib/qlpack.yml | awk '{print $2}')
echo "Published verion: $PUBLISHED_VERSION"
echo "Local verion: $CURRENT_VERSION"
if [ "$PUBLISHED_VERSION" != "$CURRENT_VERSION" ]; then
codeql pack install "${{ matrix.language }}/lib"
codeql pack publish "${{ matrix.language }}/lib"
fi
extensions:
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
language: ["csharp", "java"]
steps:
- uses: actions/checkout@v3
- name: Initialize CodeQL
run: |
VERSION="$(find "${{ runner.tool_cache }}/CodeQL/" -maxdepth 1 -mindepth 1 -type d -print \
| sort \
| tail -n 1 \
| tr -d '\n')"
echo "$VERSION/x64/codeql" >> $GITHUB_PATH
- name: Check and publish codeql-LANG-extensions (ext) pack
env:
GITHUB_TOKEN: ${{ secrets.GHCR_TOKEN }}
run: |
PUBLISHED_VERSION=$(gh api /orgs/githubsecuritylab/packages/container/codeql-${{ matrix.language }}-extensions/versions --jq '.[0].metadata.container.tags[0]')
CURRENT_VERSION=$(grep version ${{ matrix.language }}/ext/qlpack.yml | awk '{print $2}')
echo "Published verion: $PUBLISHED_VERSION"
echo "Local verion: $CURRENT_VERSION"
if [ "$PUBLISHED_VERSION" != "$CURRENT_VERSION" ]; then
codeql pack install "${{ matrix.language }}/ext"
codeql pack publish "${{ matrix.language }}/ext"
fi
library_sources_extensions:
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
language: ["csharp", "java"]
steps:
- uses: actions/checkout@v3
- name: Initialize CodeQL
run: |
VERSION="$(find "${{ runner.tool_cache }}/CodeQL/" -maxdepth 1 -mindepth 1 -type d -print \
| sort \
| tail -n 1 \
| tr -d '\n')"
echo "$VERSION/x64/codeql" >> $GITHUB_PATH
- name: Check and publish codeql-LANG-library-sources (ext-library-sources) pack
env:
GITHUB_TOKEN: ${{ secrets.GHCR_TOKEN }}
run: |
PUBLISHED_VERSION=$(gh api /orgs/githubsecuritylab/packages/container/codeql-${{ matrix.language }}-library-sources/versions --jq '.[0].metadata.container.tags[0]')
CURRENT_VERSION=$(grep version ${{ matrix.language }}/ext-library-sources/qlpack.yml | awk '{print $2}')
echo "Published verion: $PUBLISHED_VERSION"
echo "Local verion: $CURRENT_VERSION"
if [ "$PUBLISHED_VERSION" != "$CURRENT_VERSION" ]; then
codeql pack install "${{ matrix.language }}/ext-library-sources"
codeql pack publish "${{ matrix.language }}/ext-library-sources"
fi