David Verdeguer
cd7eedd4a5
Address comments
2021-05-05 12:30:20 +02:00
Andrew Eisenberg
925cef7601
Merge pull request #474 from github/aeisenberg/change-metric-id
...
Change from `metric` to `rule`
2021-05-04 11:20:18 -07:00
Andrew Eisenberg
a2312a0bf3
Change from metric to rule
...
The SARIF that we are interpreting has moved away from using `metric`
to the more general term, `rule`. We need to adapt our baseline lines of
code counting to use `rule` as well.
2021-05-04 10:06:16 -07:00
Aditya Sharad
8e3540bb01
Merge pull request #472 from github/adityasharad/pr/2.5.4
...
Update CodeQL bundle to 20210503 / 2.5.4
2021-05-03 15:14:07 -07:00
Aditya Sharad
c3e98fb528
Update CodeQL bundle to 20210503 / 2.5.4
2021-05-03 14:41:51 -07:00
David Verdeguer
aa53f64b85
Use the category on the runner
2021-05-03 19:58:30 +02:00
David Verdeguer
3b741b35ad
Use actionsUtil.computeAutomationID on upload-lib
2021-05-03 19:56:04 +02:00
David Verdeguer
c93cbc943a
Forward category input to codeql cli
2021-05-03 19:41:53 +02:00
David Verdeguer
519d0771c7
Add actions-util.getAutomationID()
2021-05-03 19:36:32 +02:00
Henning Makholm
cb5810848d
Merge pull request #470 from github/hmakholm/pr/2.5.3
...
update bundle to 20210430
codeql-bundle-20210503
2021-04-30 19:02:00 +02:00
Henning Makholm
7ab95f642d
update bundle to 20210430
2021-04-30 18:26:08 +02:00
Chris Gavin
33bb16c8b4
Merge pull request #457 from github/restrict-permissions
...
Restrict Actions token permissions in CodeQL workflow.
codeql-bundle-20210430
2021-04-30 14:19:45 +01:00
Chris Gavin
d879f4b84e
Merge branch 'main' into restrict-permissions
2021-04-30 13:55:34 +01:00
Chris Gavin
e305db89c2
Fix the token permissions for private copies of the CodeQL Action, and for runs that are not from pull requests.
2021-04-30 13:47:54 +01:00
David Verdeguer
c6e734ccc5
Add category option to runner
2021-04-29 14:59:36 +02:00
David Verdeguer
76f5ada659
Don't use getOptionalInput on the runner codepath
2021-04-29 08:00:19 +02:00
Andrew Eisenberg
1585462c63
Merge pull request #465 from github/aeisenberg/lines-of-code-trim
...
Avoid analyzing excluded language files for line counting
codeql-bundle-20210429
2021-04-28 16:41:55 -07:00
Andrew Eisenberg
ee2346270d
Avoid analyzing excluded language files for line counting
...
This change passes in a list of file types to the line counting
analysis. These are the languages for the databases being analyzed.
Line count analysis is restricted to these files.
2021-04-28 16:07:55 -07:00
Andrew Eisenberg
5c0a38d7e4
Update github-linguist dependency
...
This version adds a larger list of auto-excluded binary files.
And allows for the passing of a list of file types to restrict
analysis to.
2021-04-28 14:55:17 -07:00
David Verdeguer
40fb1f3f00
Add category input
2021-04-28 14:32:16 +02:00
Andrew Eisenberg
03f029c2a1
Merge pull request #459 from github/aeisenberg/add-linguist-data
...
Add baseline metrics for lines of code
2021-04-26 14:23:31 -07:00
Andrew Eisenberg
998f472183
Add baseline metrics for lines of code
...
This commit uses a third party library to estimate the lines of code in
a database that is to be analyzed by codeql.
The estimate uses the same includes and excludes globs for determining
which files should be counted.
The lines of code count is returned by language and injected into the
SARIF as `baseline` property in the `${language}/summary/lines-of-code`
metric.
2021-04-26 14:09:38 -07:00
Andrew Eisenberg
7c5b1287d5
Merge pull request #460 from github/dependabot/npm_and_yarn/runner/ssri-6.0.2
...
Bump ssri from 6.0.1 to 6.0.2 in /runner
2021-04-23 14:19:20 -07:00
dependabot[bot]
e2d70d6a0b
Bump ssri from 6.0.1 to 6.0.2 in /runner
...
Bumps [ssri](https://github.com/npm/ssri ) from 6.0.1 to 6.0.2.
- [Release notes](https://github.com/npm/ssri/releases )
- [Changelog](https://github.com/npm/ssri/blob/v6.0.2/CHANGELOG.md )
- [Commits](https://github.com/npm/ssri/compare/v6.0.1...v6.0.2 )
Signed-off-by: dependabot[bot] <support@github.com >
2021-04-23 18:01:34 +00:00
Andrew Eisenberg
e266dfb63e
Merge pull request #458 from github/aeisenberg/add-github-linguist
...
Add the github-linguist package
2021-04-23 10:59:56 -07:00
Andrew Eisenberg
b6b197e0ad
Merge branch 'main' into aeisenberg/add-github-linguist
2021-04-23 10:54:04 -07:00
Robert
ba64dfb959
Merge pull request #456 from github/robertbrignull/toolcache-interface
...
Introduce our own toolcache implementation for use by the runnner
2021-04-23 16:24:04 +01:00
Robert
27bf3a208d
fix typo
2021-04-23 10:01:50 +01:00
Robert
8207018b75
make query more robust
2021-04-23 10:01:28 +01:00
Robert
ce467e7e36
use safeWhich
2021-04-23 09:59:23 +01:00
Andrew Eisenberg
c4a84a93d4
Add the github-linguist package
...
This commit only adds a single package and all of its transitive
dependencies. The github-linguist package will be used for counting
lines of code as a baseline for databases we are analyzing.
2021-04-22 15:59:49 -07:00
Chris Gavin
643bc6e3ed
Remove spurious blank line.
2021-04-22 17:26:26 +01:00
Chris Gavin
7e85b5d66a
Restrict Actions token permissions in CodeQL workflow.
2021-04-22 17:07:03 +01:00
Robert
8c91ba83e2
Introduce our own toolcache implementation for use by the runnner
2021-04-22 15:31:15 +01:00
Henning Makholm
896b4ff181
Merge pull request #454 from github/hmakholm/pr/2.5.2
...
update bundle to 20210421 (CLI 2.5.2)
2021-04-21 20:24:18 +02:00
Henning Makholm
cb4c96ba60
Merge remote-tracking branch 'origin/main' into hmakholm/pr/2.5.2
2021-04-21 18:56:33 +02:00
Edoardo Pirovano
578f9fc99e
Add external git repositories to search path for custom queries
2021-04-21 17:40:56 +01:00
Henning Makholm
46517cfb47
update bundle to 20210421 (CLI 2.5.2)
2021-04-21 17:31:57 +02:00
David Verdeguer
1fa35632f2
Merge pull request #452 from github/daverlo/category
...
Ignore non-string values in populateRunAutomationDetails
codeql-bundle-20210421
2021-04-20 13:31:19 +02:00
David Verdeguer
496bf0ec11
Ignore non-string values in populateRunAutomationDetails
2021-04-20 12:53:16 +02:00
David Verdeguer
8bd2b3516b
Merge pull request #446 from github/daverlo/runAutomationDetails
...
Add automationdetails id to runs
codeql-bundle-20210419
2021-04-19 11:30:53 +02:00
David Verdeguer
bc14da99c5
Merge branch 'main' into daverlo/runAutomationDetails
2021-04-19 10:47:18 +02:00
David Verdeguer
351d36fd18
Add test for existing automationDetails
2021-04-19 09:04:58 +02:00
Andrew Eisenberg
c87ee1c65a
[Runner] Throw error on unknown option in init command
...
And explicitly document the advanced --trace-process-name and
--trace-process-level args.
2021-04-16 12:09:26 -07:00
David Verdeguer
0ece0d074b
Fix populateRunAutomationDetails for null environments
2021-04-16 09:24:34 +02:00
David Verdeguer
de611b2de3
Prevent the automationDetails to be regenerated if it already exists
2021-04-16 07:47:42 +02:00
David Verdeguer
47755f0910
Add automationdetails id to runs
2021-04-15 16:20:49 +02:00
Andrew Eisenberg
6aebd1b98a
Fixes a regex for language and locale recognition
...
See https://github.com/oasis-tcs/sarif-spec/pull/490
See #418
Note that this changes the sarif spec file. Unless this
change is actually merged in the sarif spec repo, the
version used by the action will be slightly different.
2021-04-14 08:10:56 -07:00
Aditya Sharad
0c2281fb06
Merge pull request #441 from adityasharad/tests/matrix-tools-latest
...
PR checks: Run integration tests against both `tools: null` and `tools: latest`
2021-04-09 16:24:56 -07:00
Aditya Sharad
fcf0863613
Merge branch 'main' into tests/matrix-tools-latest
2021-04-09 16:11:35 -07:00