mirror of
https://github.com/microsoft/regorus.git
synced 2026-08-05 02:16:11 +00:00
Bumps the per-dependency group with 12 updates: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `4.3.1` | `6.0.2` | | [actions/setup-python](https://github.com/actions/setup-python) | `5.6.0` | `6.2.0` | | [actions/setup-java](https://github.com/actions/setup-java) | `4.8.0` | `5.2.0` | | [actions/setup-go](https://github.com/actions/setup-go) | `5.1.0` | `6.2.0` | | [actions/setup-dotnet](https://github.com/actions/setup-dotnet) | `4.1.0` | `5.1.0` | | [actions/setup-node](https://github.com/actions/setup-node) | `4.4.0` | `6.2.0` | | [github/codeql-action](https://github.com/github/codeql-action) | `3.32.2` | `4.32.2` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.6.2` | `6.0.0` | | [actions/download-artifact](https://github.com/actions/download-artifact) | `5.0.0` | `7.0.0` | | [PyO3/maturin-action](https://github.com/pyo3/maturin-action) | `63b75c597b83e247fbf4fb7719801cc4220ae9f3` | `b1bd829e37fef14c63f19162034228a2f3dc1021` | | [MarcoIeni/release-plz-action](https://github.com/marcoieni/release-plz-action) | `0.5.108` | `0.5.126` | | [oxidize-rb/actions](https://github.com/oxidize-rb/actions) | `1.2.6` | `1.4.4` | Updates `actions/checkout` from 4.3.1 to 6.0.2 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](34e114876b...de0fac2e45) Updates `actions/setup-python` from 5.6.0 to 6.2.0 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](a26af69be9...a309ff8b42) Updates `actions/setup-java` from 4.8.0 to 5.2.0 - [Release notes](https://github.com/actions/setup-java/releases) - [Commits](https://github.com/actions/setup-java/compare/v4.8.0...be666c2fcd27ec809703dec50e508c2fdc7f6654) Updates `actions/setup-go` from 5.1.0 to 6.2.0 - [Release notes](https://github.com/actions/setup-go/releases) - [Commits](https://github.com/actions/setup-go/compare/v5.1.0...7a3fe6cf4cb3a834922a1244abfce67bcef6a0c5) Updates `actions/setup-dotnet` from 4.1.0 to 5.1.0 - [Release notes](https://github.com/actions/setup-dotnet/releases) - [Commits](https://github.com/actions/setup-dotnet/compare/v4.1.0...baa11fbfe1d6520db94683bd5c7a3818018e4309) Updates `actions/setup-node` from 4.4.0 to 6.2.0 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](49933ea528...6044e13b5d) Updates `github/codeql-action` from 3.32.2 to 4.32.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/v3.32.2...45cbd0c69e560cd9e7cd7f8c32362050c9b7ded2) Updates `actions/upload-artifact` from 4.6.2 to 6.0.0 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](ea165f8d65...b7c566a772) Updates `actions/download-artifact` from 5.0.0 to 7.0.0 - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](634f93cb29...37930b1c2a) Updates `PyO3/maturin-action` from 63b75c597b83e247fbf4fb7719801cc4220ae9f3 to b1bd829e37fef14c63f19162034228a2f3dc1021 - [Release notes](https://github.com/pyo3/maturin-action/releases) - [Commits](63b75c597b...b1bd829e37) Updates `MarcoIeni/release-plz-action` from 0.5.108 to 0.5.126 - [Release notes](https://github.com/marcoieni/release-plz-action/releases) - [Commits](8724d33cd9...52440b50d3) Updates `oxidize-rb/actions` from 1.2.6 to 1.4.4 - [Release notes](https://github.com/oxidize-rb/actions/releases) - [Commits](7ca44a16e2...e5f9a49a78) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 6.0.2 dependency-type: direct:production update-type: version-update:semver-major dependency-group: per-dependency - dependency-name: actions/setup-python dependency-version: 6.2.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: per-dependency - dependency-name: actions/setup-java dependency-version: 5.2.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: per-dependency - dependency-name: actions/setup-go dependency-version: 6.2.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: per-dependency - dependency-name: actions/setup-dotnet dependency-version: 5.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: per-dependency - dependency-name: actions/setup-node dependency-version: 6.2.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: per-dependency - dependency-name: github/codeql-action dependency-version: 4.32.2 dependency-type: direct:production update-type: version-update:semver-major dependency-group: per-dependency - dependency-name: actions/upload-artifact dependency-version: 6.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: per-dependency - dependency-name: actions/download-artifact dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: per-dependency - dependency-name: PyO3/maturin-action dependency-version: b1bd829e37fef14c63f19162034228a2f3dc1021 dependency-type: direct:production dependency-group: per-dependency - dependency-name: MarcoIeni/release-plz-action dependency-version: 0.5.126 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: per-dependency - dependency-name: oxidize-rb/actions dependency-version: 1.4.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: per-dependency ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
193 lines
6.5 KiB
YAML
193 lines
6.5 KiB
YAML
# Copyright (c) Microsoft Corporation. All rights reserved.
|
|
#
|
|
name: "CodeQL Security Analysis"
|
|
|
|
on:
|
|
schedule:
|
|
# Run weekly on Wednesdays at 3:17 AM UTC
|
|
- cron: '17 3 * * 3'
|
|
workflow_dispatch:
|
|
# Allow manual triggering
|
|
push:
|
|
branches: [ "main" ]
|
|
pull_request:
|
|
branches: [ "main" ]
|
|
|
|
jobs:
|
|
analyze:
|
|
name: Analyze (${{ matrix.language }})
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 60
|
|
permissions:
|
|
# required for all workflows
|
|
security-events: write
|
|
# required to fetch internal or private CodeQL packs
|
|
packages: read
|
|
# only required for workflows in private repositories
|
|
actions: read
|
|
contents: read
|
|
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
include:
|
|
# Rust analysis for main crate and Rust-based bindings
|
|
- language: rust
|
|
build-mode: none
|
|
working-directory: .
|
|
# C/C++ analysis for FFI bindings
|
|
- language: c-cpp
|
|
build-mode: manual
|
|
working-directory: bindings/ffi
|
|
# Python analysis for Python bindings
|
|
- language: python
|
|
build-mode: none
|
|
working-directory: bindings/python
|
|
# Java analysis for Java bindings
|
|
- language: java-kotlin
|
|
build-mode: manual
|
|
working-directory: bindings/java
|
|
# Go analysis for Go bindings
|
|
- language: go
|
|
build-mode: manual
|
|
working-directory: bindings/go
|
|
# C# analysis for C# bindings
|
|
- language: csharp
|
|
build-mode: manual
|
|
working-directory: bindings/csharp
|
|
# JavaScript analysis for WASM bindings
|
|
- language: javascript-typescript
|
|
build-mode: none
|
|
working-directory: bindings/wasm
|
|
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
|
|
# Setup language-specific dependencies BEFORE CodeQL init for proper tracing setup
|
|
- name: Setup Rust
|
|
uses: ./.github/actions/toolchains/rust
|
|
|
|
- name: Cache cargo
|
|
uses: Swatinem/rust-cache@779680da715d629ac1d338a641029a2f4372abb5 # v2.8.2
|
|
with:
|
|
shared-key: ${{ runner.os }}-regorus
|
|
|
|
- name: Fetch workspace dependencies
|
|
run: cargo fetch --locked
|
|
|
|
- name: Fetch FFI crate dependencies
|
|
if: matrix.language == 'c-cpp' || matrix.language == 'go' || matrix.language == 'csharp'
|
|
run: cargo fetch --locked --manifest-path bindings/ffi/Cargo.toml
|
|
|
|
- name: Fetch Java crate dependencies
|
|
if: matrix.language == 'java-kotlin'
|
|
run: cargo fetch --locked --manifest-path bindings/java/Cargo.toml
|
|
|
|
- name: Setup Python
|
|
if: matrix.language == 'python'
|
|
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
|
|
with:
|
|
python-version: '3.10'
|
|
|
|
- name: Setup Java
|
|
if: matrix.language == 'java-kotlin'
|
|
uses: actions/setup-java@be666c2fcd27ec809703dec50e508c2fdc7f6654 # v5.2.0
|
|
with:
|
|
distribution: 'corretto'
|
|
java-version: '8'
|
|
|
|
- name: Setup Go
|
|
if: matrix.language == 'go'
|
|
uses: actions/setup-go@7a3fe6cf4cb3a834922a1244abfce67bcef6a0c5 # v6.2.0
|
|
with:
|
|
go-version: '1.21'
|
|
|
|
- name: Setup .NET
|
|
if: matrix.language == 'csharp'
|
|
uses: actions/setup-dotnet@baa11fbfe1d6520db94683bd5c7a3818018e4309 # v5.1.0
|
|
with:
|
|
global-json-file: ./bindings/csharp/global.json
|
|
|
|
- name: Invoke dotnet directly
|
|
if: matrix.language == 'csharp'
|
|
run: dotnet --info
|
|
|
|
- name: Setup Node.js
|
|
if: matrix.language == 'javascript-typescript'
|
|
uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6.2.0
|
|
with:
|
|
node-version: '18'
|
|
|
|
- name: Initialize CodeQL
|
|
uses: github/codeql-action/init@45cbd0c69e560cd9e7cd7f8c32362050c9b7ded2 # v4.32.2
|
|
with:
|
|
languages: ${{ matrix.language }}
|
|
build-mode: ${{ matrix.build-mode }}
|
|
|
|
# Install additional build dependencies
|
|
- name: Install system dependencies
|
|
if: matrix.language == 'rust' || matrix.language == 'c-cpp'
|
|
run: |
|
|
sudo apt-get update
|
|
sudo apt-get install -y build-essential cmake
|
|
|
|
- name: Install Python build dependencies
|
|
if: matrix.language == 'python'
|
|
working-directory: ${{ matrix.working-directory }}
|
|
run: |
|
|
python -m pip install --upgrade pip
|
|
pip install maturin[patchelf] pytest
|
|
|
|
- name: Setup Ruby
|
|
if: matrix.language == 'rust' && contains(matrix.working-directory, 'ruby')
|
|
uses: ruby/setup-ruby@09a7688d3b55cf0e976497ff046b70949eeaccfd # v1.288.0
|
|
with:
|
|
ruby-version: '3.4.2'
|
|
bundler-cache: true
|
|
working-directory: bindings/ruby
|
|
|
|
- name: Install WASM build dependencies
|
|
if: matrix.language == 'javascript-typescript'
|
|
run: |
|
|
cargo install wasm-pack
|
|
|
|
# Manual build steps for different languages
|
|
- name: Build C/C++ bindings via xtask
|
|
if: matrix.language == 'c-cpp'
|
|
run: |
|
|
cargo xtask test-c --release --frozen
|
|
cargo xtask test-cpp --release --frozen --skip-ffi
|
|
cargo xtask test-c-no-std --release --frozen --skip-ffi
|
|
|
|
- name: Build Java bindings via xtask
|
|
if: matrix.language == 'java-kotlin'
|
|
run: cargo xtask test-java --release --frozen
|
|
|
|
- name: Build Go bindings via xtask
|
|
if: matrix.language == 'go'
|
|
run: cargo xtask test-go --release --frozen
|
|
|
|
- name: Build C# bindings manually
|
|
if: matrix.language == 'csharp'
|
|
working-directory: ${{ matrix.working-directory }}
|
|
run: |
|
|
# Temporary workaround: CodeQL's tracer replaces dotnet with a missing shim when cargo xtask test-csharp runs,
|
|
# so invoke dotnet directly here until the upstream fix lands.
|
|
# Ideal command once fixed: cargo xtask test-csharp --release
|
|
# Build the FFI library that C# bindings access via P/Invoke
|
|
cd ../ffi
|
|
cargo build --release --locked
|
|
cd ../csharp
|
|
# Restore NuGet packages and build .NET assemblies in release mode
|
|
dotnet restore Regorus/Regorus.csproj
|
|
dotnet build Regorus/Regorus.csproj --no-restore /p:Configuration=Release /p:IgnoreMissingArtifacts=true
|
|
|
|
- name: Build WASM bindings via xtask
|
|
if: matrix.language == 'javascript-typescript'
|
|
run: cargo xtask build-wasm --release
|
|
|
|
- name: Perform CodeQL Analysis
|
|
uses: github/codeql-action/analyze@45cbd0c69e560cd9e7cd7f8c32362050c9b7ded2 # v4.32.2
|
|
with:
|
|
category: "/language:${{matrix.language}}" |