Updating auto updater for version labeling #339
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Build CodeQL Packs | |
| on: | |
| pull_request: | |
| branches: [ main ] | |
| workflow_dispatch: | |
| # Least-privilege default; jobs that need to comment on PRs override this below. | |
| permissions: | |
| contents: read | |
| packages: read | |
| jobs: | |
| compile-and-test: | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| pull-requests: write # required by pr-suites-packs.sh (gh pr comment) | |
| issues: write # required by pr-suites-packs.sh (gh pr comment) | |
| packages: read # required by pr-suites-packs.sh (gh api packages) | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| language: [ 'cpp', 'csharp', 'go', 'java', 'javascript', 'python', 'ruby' ] | |
| steps: | |
| - uses: actions/checkout@v7 | |
| # Conditionally run actions based on files modified by PR, feature branch or pushed commits | |
| - uses: dorny/paths-filter@7b450fff21473bca461d4b92ce414b9d0420d706 | |
| id: changes | |
| with: | |
| filters: | | |
| src: | |
| - '${{ matrix.language }}/**' | |
| - '.github/**' | |
| - name: Setup CodeQL | |
| if: steps.changes.outputs.src == 'true' || github.event_name == 'workflow_dispatch' | |
| id: install-codeql | |
| uses: ./.github/actions/install-codeql | |
| - name: Install Packs | |
| if: steps.changes.outputs.src == 'true' || github.event_name == 'workflow_dispatch' | |
| env: | |
| GITHUB_TOKEN: ${{ github.token }} | |
| CODEQL_CLI_VERSION: ${{ steps.install-codeql.outputs.codeql-cli-version }} | |
| run: | | |
| gh repo clone github/codeql -- -b codeql-cli-${CODEQL_CLI_VERSION} # to make stubs available for tests | |
| codeql pack install "${{ matrix.language }}/lib" | |
| codeql pack install "${{ matrix.language }}/src" | |
| codeql pack install "${{ matrix.language }}/test" | |
| - name: Compile Queries | |
| if: steps.changes.outputs.src == 'true' || github.event_name == 'workflow_dispatch' | |
| env: | |
| GITHUB_TOKEN: ${{ github.token }} | |
| run: | | |
| ./.github/scripts/pr-compile.sh "${{ github.event.number }}" "${{ matrix.language }}" | |
| - name: Test Queries | |
| if: steps.changes.outputs.src == 'true' || github.event_name == 'workflow_dispatch' | |
| env: | |
| RUNNER_TEMP: ${{ runner.temp }} | |
| shell: python | |
| run: | | |
| import os | |
| import sys | |
| import subprocess | |
| from pathlib import Path | |
| def print_error(fmt, *args): | |
| print(f"::error::{fmt}", *args) | |
| def print_error_and_fail(fmt, *args): | |
| print_error(fmt, args) | |
| sys.exit(1) | |
| runner_temp = os.environ['RUNNER_TEMP'] | |
| test_root = Path('${{ github.workspace }}', '${{ matrix.language }}', 'test') | |
| print(f"Executing tests found (recursively) in the directory '{test_root}'") | |
| files_to_close = [] | |
| try: | |
| # Runners have 4 cores, so split the tests into 4 "slices", and run one per thread | |
| num_slices = 4 | |
| procs = [] | |
| for slice in range(1, num_slices+1): | |
| test_report_path = os.path.join(runner_temp, "${{ matrix.language }}", f"test_report_slice_{slice}_of_{num_slices}.json") | |
| os.makedirs(os.path.dirname(test_report_path), exist_ok=True) | |
| test_report_file = open(test_report_path, 'w') | |
| files_to_close.append(test_report_file) | |
| procs.append(subprocess.Popen(["codeql", "test", "run", "--failing-exitcode=122", f"--slice={slice}/{num_slices}", "--ram=2048", "--format=json", test_root], stdout=test_report_file, stderr=subprocess.PIPE)) | |
| for p in procs: | |
| _, err = p.communicate() | |
| if p.returncode != 0: | |
| if p.returncode == 122: | |
| # Failed because a test case failed, so just print the regular output. | |
| # This will allow us to proceed to validate-test-results, which will fail if | |
| # any test cases failed | |
| print(f"{err.decode()}") | |
| else: | |
| # Some more serious problem occurred, so print and fail fast | |
| print_error_and_fail(f"Failed to run tests with return code {p.returncode}\n{err.decode()}") | |
| finally: | |
| for file in files_to_close: | |
| file.close() | |
| - name: Upload test results | |
| if: steps.changes.outputs.src == 'true' || github.event_name == 'workflow_dispatch' | |
| uses: actions/upload-artifact@v7 | |
| with: | |
| name: ${{ matrix.language }}-test-results | |
| path: | | |
| ${{ runner.temp }}/${{ matrix.language }}/test_report_slice_*.json | |
| if-no-files-found: error | |
| - name: Compile / Check Suites & Packs | |
| if: steps.changes.outputs.src == 'true' || github.event_name == 'workflow_dispatch' | |
| env: | |
| GITHUB_TOKEN: ${{ github.token }} | |
| run: | | |
| ./.github/scripts/pr-suites-packs.sh "${{ github.event.number }}" "${{ matrix.language }}" | |
| validate-test-results: | |
| name: Validate test results | |
| needs: compile-and-test | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Check if compile-and-test job failed to complete, if so fail | |
| if: ${{ needs.compile-and-test.result == 'failure' }} | |
| uses: actions/github-script@v9 | |
| with: | |
| script: | | |
| core.setFailed('Test run job failed') | |
| - name: Collect test results | |
| uses: actions/download-artifact@v8 | |
| - name: Validate test results | |
| run: | | |
| mapfile -t test_reports < <(find . -name 'test_report_*.json') | |
| if [[ ${#test_reports[@]} -eq 0 ]]; then | |
| echo "No test results found" | |
| exit 0 | |
| fi | |
| for json_report in "${test_reports[@]}" | |
| do | |
| jq --raw-output '"PASS \(map(select(.pass == true)) | length)/\(length)"' "$json_report" | |
| done | |
| FAILING_TESTS=$(jq --slurp --raw-output '.[][] | select(.pass == false)' "${test_reports[@]}") | |
| if [[ ! -z "$FAILING_TESTS" ]]; then | |
| echo "ERROR: The following tests failed:" | |
| echo $FAILING_TESTS | jq . | |
| exit 1 | |
| fi | |
| extensions: | |
| runs-on: ubuntu-latest | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| language: [ 'csharp', 'go', 'java', 'python' ] | |
| steps: | |
| - uses: actions/checkout@v7 | |
| with: | |
| submodules: true | |
| - uses: dorny/paths-filter@7b450fff21473bca461d4b92ce414b9d0420d706 | |
| id: changes | |
| with: | |
| filters: | | |
| src: | |
| - '${{ matrix.language }}/ext/**' | |
| - name: Setup CodeQL | |
| if: steps.changes.outputs.src == 'true' || github.event_name == 'workflow_dispatch' | |
| uses: ./.github/actions/install-codeql | |
| - name: Install Packs | |
| if: steps.changes.outputs.src == 'true' || github.event_name == 'workflow_dispatch' | |
| env: | |
| GITHUB_TOKEN: ${{ github.token }} | |
| run: | | |
| gh extension install github/gh-codeql | |
| # NOTE: deliberately no `gh codeql pack install` here. `ext` is a CodeQL model/extension | |
| # pack (`library: true`, `extensionTargets`, no `dependencies`) - installing it just | |
| # (re)writes a `codeql-pack.lock.yml` with an empty `dependencies: {}` map, and a | |
| # checked-in lock file in that state makes a subsequent `codeql pack create` emit a | |
| # bogus `addsTo.pack '...' is not an extension target of '...'` warning for every data | |
| # extension in the pack (a known CodeQL CLI bug, see | |
| # https://github.com/github/codeql/issues/20211). See CONTRIBUTING.md. | |
| gh codeql pack create "${{ matrix.language }}/ext/" | |
| library-sources: | |
| runs-on: ubuntu-latest | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| language: [ 'csharp', 'java' ] | |
| steps: | |
| - uses: actions/checkout@v7 | |
| with: | |
| submodules: true | |
| - uses: dorny/paths-filter@7b450fff21473bca461d4b92ce414b9d0420d706 | |
| id: changes | |
| with: | |
| filters: | | |
| src: | |
| - '${{ matrix.language }}/ext-library-sources/**' | |
| - name: Setup CodeQL | |
| if: steps.changes.outputs.src == 'true' || github.event_name == 'workflow_dispatch' | |
| uses: ./.github/actions/install-codeql | |
| - name: Install CodeQL | |
| if: steps.changes.outputs.src == 'true' || github.event_name == 'workflow_dispatch' | |
| env: | |
| GITHUB_TOKEN: ${{ github.token }} | |
| run: | | |
| # NOTE: deliberately no `codeql pack install` here - see the matching comment in the | |
| # `extensions` job above. | |
| codeql pack create "${{ matrix.language }}/ext-library-sources/" | |
| configs: | |
| runs-on: ubuntu-latest | |
| needs: compile-and-test | |
| permissions: | |
| contents: read | |
| packages: read # required by codeql pack install (GHCR rate limiting) | |
| pull-requests: read # required by pr-configs.sh (gh pr view) | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - uses: dorny/paths-filter@7b450fff21473bca461d4b92ce414b9d0420d706 | |
| id: changes | |
| with: | |
| filters: | | |
| src: | |
| - 'configs/**' | |
| - name: Setup CodeQL | |
| if: steps.changes.outputs.src == 'true' || github.event_name == 'workflow_dispatch' | |
| uses: ./.github/actions/install-codeql | |
| - name: Install Packs | |
| if: steps.changes.outputs.src == 'true' || github.event_name == 'workflow_dispatch' | |
| env: | |
| GITHUB_TOKEN: ${{ github.token }} | |
| run: | | |
| for lang in cpp csharp go java javascript python ruby; do | |
| if [[ -d "${lang}/src" ]]; then | |
| codeql pack install "${lang}/src" | |
| fi | |
| done | |
| - name: "Check Configurations" | |
| if: steps.changes.outputs.src == 'true' || github.event_name == 'workflow_dispatch' | |
| env: | |
| GITHUB_TOKEN: ${{ github.token }} | |
| run: | | |
| ./.github/scripts/pr-configs.sh "${{ github.event.number }}" |