From 24fe35cfeb73b359be75fdc1a39174a4d7bebd41 Mon Sep 17 00:00:00 2001 From: David Pine <7679720+IEvangelist@users.noreply.github.com> Date: Wed, 16 Sep 2026 15:17:23 -0500 Subject: [PATCH 1/3] Add scheduled CodeQL scanning Restore CodeQL coverage for the JavaScript/TypeScript frontend and C# AppHost on pushes, pull requests, and a weekly schedule. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0895f8e8-eeec-42ba-a660-a40fa78efc22 --- .github/workflows/codeql.yml | 54 ++++++++++++++++++++++++++++++++++++ 1 file changed, 54 insertions(+) create mode 100644 .github/workflows/codeql.yml diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml new file mode 100644 index 000000000..ca08ff78b --- /dev/null +++ b/.github/workflows/codeql.yml @@ -0,0 +1,54 @@ +name: CodeQL + +on: + push: + branches: [main] + pull_request: + branches: [main] + schedule: + - cron: "23 7 * * 3" + workflow_dispatch: + +permissions: + actions: read + contents: read + packages: read + security-events: write + +jobs: + analyze: + name: Analyze (${{ matrix.language }}) + runs-on: ubuntu-latest + strategy: + fail-fast: false + matrix: + include: + - language: javascript-typescript + build-mode: none + - language: csharp + build-mode: manual + + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + + - name: Setup .NET + if: matrix.language == 'csharp' + uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0 + with: + global-json-file: global.json + + - name: Initialize CodeQL + uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 + with: + languages: ${{ matrix.language }} + build-mode: ${{ matrix.build-mode }} + + - name: Build AppHost + if: matrix.language == 'csharp' + working-directory: src/apphost/Aspire.Dev.AppHost + run: dotnet build --configuration Release + + - name: Perform CodeQL analysis + uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 + with: + category: "/language:${{ matrix.language }}" From 6040ae114aa1c505120653a89a32b17323632af0 Mon Sep 17 00:00:00 2001 From: David Pine <7679720+IEvangelist@users.noreply.github.com> Date: Wed, 16 Sep 2026 15:22:26 -0500 Subject: [PATCH 2/3] Scan the full C# solution with CodeQL Build every C# project in Aspire.Dev.slnx so CodeQL covers the AppHost, StaticHost, generator tools, and test projects. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0895f8e8-eeec-42ba-a660-a40fa78efc22 --- .github/workflows/codeql.yml | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index ca08ff78b..60654975c 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -43,10 +43,9 @@ jobs: languages: ${{ matrix.language }} build-mode: ${{ matrix.build-mode }} - - name: Build AppHost + - name: Build C# solution if: matrix.language == 'csharp' - working-directory: src/apphost/Aspire.Dev.AppHost - run: dotnet build --configuration Release + run: dotnet build Aspire.Dev.slnx --configuration Release - name: Perform CodeQL analysis uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 From 532df7487db1aa949efe440a6849553f1513f218 Mon Sep 17 00:00:00 2001 From: David Pine <7679720+IEvangelist@users.noreply.github.com> Date: Wed, 16 Sep 2026 15:26:35 -0500 Subject: [PATCH 3/3] Avoid Aspire bundle setup during CodeQL build CodeQL only needs compiler extraction, so disable CLI bundle resolution while building the full solution. This keeps all C# projects covered without requiring orchestration assets. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0895f8e8-eeec-42ba-a660-a40fa78efc22 --- .github/workflows/codeql.yml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 60654975c..0d5c0a0c9 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -45,7 +45,8 @@ jobs: - name: Build C# solution if: matrix.language == 'csharp' - run: dotnet build Aspire.Dev.slnx --configuration Release + # CodeQL needs compiler extraction, not the Aspire orchestration bundle. + run: dotnet build Aspire.Dev.slnx --configuration Release -p:AspireUseCliBundle=false - name: Perform CodeQL analysis uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0