Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
192 changes: 190 additions & 2 deletions .github/workflows/native-build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,16 +6,49 @@ on:
pull_request:
branches: [ main, 'sprint/**', 'release/**', topic/RDK*, develop ]

permissions:
actions: read
contents: read
pull-requests: read

jobs:
build-jst-on-push:
name: Build javascript-templates component on push
if: github.event_name == 'push'
runs-on: ubuntu-latest
container:
image: ghcr.io/rdkcentral/docker-rdk-ci:latest

steps:
- name: Checkout code
uses: actions/checkout@v4

- name: native build
run: |
# Trust the workspace
git config --global --add safe.directory '*'
# Pull the latest changes for the native build system
git submodule update --init --recursive --remote
# Build and install dependencies
chmod +x build_tools_workflows/cov_docker_script/setup_dependencies.sh
./build_tools_workflows/cov_docker_script/setup_dependencies.sh ./cov_docker_script/component_config.json
# Build component
chmod +x build_tools_workflows/cov_docker_script/build_native.sh
./build_tools_workflows/cov_docker_script/build_native.sh ./cov_docker_script/component_config.json "$(pwd)"
env:
GITHUB_TOKEN: ${{ secrets.RDKCM_RDKE }}

build-jst-on-pr:
name: Build javascript-templates component in github rdkcentral
name: Build javascript-templates component on PR
needs: detect-source-changes
if: github.event_name == 'pull_request' && needs.detect-source-changes.outputs.has_component == 'true'
runs-on: ubuntu-latest
container:
image: ghcr.io/rdkcentral/docker-rdk-ci:latest

steps:
- name: Checkout code
uses: actions/checkout@v3
uses: actions/checkout@v4

- name: native build
run: |
Expand All @@ -31,3 +64,158 @@ jobs:
./build_tools_workflows/cov_docker_script/build_native.sh ./cov_docker_script/component_config.json "$(pwd)"
env:
GITHUB_TOKEN: ${{ secrets.RDKCM_RDKE }}

detect-source-changes:
name: Detect source path changes for CodeQL
if: github.event_name == 'pull_request'
runs-on: ubuntu-latest
outputs:
has_component: ${{ steps.filter.outputs.component }}
has_cpp: ${{ steps.filter.outputs.cpp }}
has_python: ${{ steps.filter.outputs.python }}
has_js: ${{ steps.filter.outputs.javascript }}

steps:
- name: Checkout code
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Detect changed source paths
id: filter
uses: dorny/paths-filter@v4
with:
predicate-quantifier: some-with-excludes
filters: |
component:
- 'source/**/*'
cpp:
- 'source/**/*.c'
- 'source/**/*.h'
- 'source/**/*.cpp'
- 'tools/**/*.c'
- 'tools/**/*.h'
- 'tools/**/*.cpp'
- 'tests/**/*.c'
- 'tests/**/*.h'
- 'tests/**/*.cpp'
python:
- 'build_tools_workflows/**/*.py'
- 'cov_docker_script/**/*.py'
- 'tools/**/*.py'
- 'tests/**/*.py'
javascript:
- 'source/**/*.js'
- 'source/**/*.ts'
- 'jsts/**/*.js'
- 'jsts/**/*.ts'
- 'tests/**/*.js'
- 'tests/**/*.ts'
- '!jsts/jst_prefix.js'
- '!jsts/jst_suffix.js'
- '!tests/parser/jst_prefix.js'
- '!tests/parser/jst_suffix.js'
- '!tests/parser/**/*.jst.parsed'

codeql-c-cpp:
name: CodeQL (C/C++)
needs: detect-source-changes
if: github.event_name == 'pull_request' && needs.detect-source-changes.outputs.has_cpp == 'true'
runs-on: ubuntu-latest
permissions:
actions: read
contents: read
security-events: write
container:
image: ghcr.io/rdkcentral/docker-rdk-ci:latest

steps:
- name: Checkout code
uses: actions/checkout@v4

- name: Initialize CodeQL (C/C++)
uses: github/codeql-action/init@v4
with:
languages: c-cpp
build-mode: manual

- name: Build component for CodeQL
run: |
git config --global --add safe.directory '*'
git submodule update --init --recursive
chmod +x build_tools_workflows/cov_docker_script/setup_dependencies.sh
./build_tools_workflows/cov_docker_script/setup_dependencies.sh ./cov_docker_script/component_config.json
chmod +x build_tools_workflows/cov_docker_script/build_native.sh
./build_tools_workflows/cov_docker_script/build_native.sh ./cov_docker_script/component_config.json "$(pwd)"
env:
GITHUB_TOKEN: ${{ secrets.RDKCM_RDKE }}

- name: Analyze C/C++
uses: github/codeql-action/analyze@v4
with:
category: '/language:c-cpp'

codeql-python:
name: CodeQL (Python)
needs: detect-source-changes
if: github.event_name == 'pull_request' && needs.detect-source-changes.outputs.has_python == 'true'
runs-on: ubuntu-latest
permissions:
actions: read
contents: read
security-events: write

steps:
- name: Checkout code
uses: actions/checkout@v4

- name: Initialize CodeQL (Python)
uses: github/codeql-action/init@v4
with:
languages: python
build-mode: none
config: |
paths:
- build_tools_workflows
- cov_docker_script
- tools
- tests

- name: Analyze Python
uses: github/codeql-action/analyze@v4
with:
category: '/language:python'

codeql-javascript:
name: CodeQL (JavaScript)
needs: detect-source-changes
if: github.event_name == 'pull_request' && needs.detect-source-changes.outputs.has_js == 'true'
runs-on: ubuntu-latest
permissions:
actions: read
contents: read
security-events: write

steps:
- name: Checkout code
uses: actions/checkout@v4

- name: Initialize CodeQL (JavaScript)
uses: github/codeql-action/init@v4
with:
languages: javascript-typescript
build-mode: none
config: |
paths:
- source
- jsts
- tests
paths-ignore:
- jsts/jst_prefix.js
- jsts/jst_suffix.js
- tests/parser/jst_prefix.js
- tests/parser/jst_suffix.js
- tests/parser/**/*.jst.parsed
- name: Analyze JavaScript
uses: github/codeql-action/analyze@v4
with:
category: '/language:javascript-typescript'
16 changes: 16 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,12 +4,28 @@ All notable changes to this project will be documented in this file. Dates are d

Generated by [`auto-changelog`](https://github.com/CookPete/auto-changelog).

#### [2.9.0](https://github.com/rdkcentral/javascript-templates/compare/2.8.0...2.9.0)

- RDKB-65595 : [Risk-Critical] JST (Generic) Security Fuzzing Report [`#34`](https://github.com/rdkcentral/javascript-templates/pull/34)
- RDKB-66532 RDKB-66534 : Validate session ID format before handling [`#36`](https://github.com/rdkcentral/javascript-templates/pull/36)
- RDKB-65597 : [Risk-High] JST (Generic) Security Fuzzing Report [`#35`](https://github.com/rdkcentral/javascript-templates/pull/35)
- RDKB-66116 : use freedesktop dbus-1.14 and gate native-build/CodeQL by source paths [`#31`](https://github.com/rdkcentral/javascript-templates/pull/31)

#### [2.8.0](https://github.com/rdkcentral/javascript-templates/compare/2.3.0...2.8.0)

> 22 July 2026

- Merge tag '2.3.0' into develop [`f0478c8`](https://github.com/rdkcentral/javascript-templates/commit/f0478c8b644c4feb6f322abc556f527d562ebd58)

#### [2.3.0](https://github.com/rdkcentral/javascript-templates/compare/2.2.0...2.3.0)

> 22 July 2026

- RDKB-66032 : Add PR Format Check workflow [`#29`](https://github.com/rdkcentral/javascript-templates/pull/29)
- RDKB-64641 sets post_data = NULL to keep getPost() unset for file-only multipart bodies [`#27`](https://github.com/rdkcentral/javascript-templates/pull/27)
- RDKB-64256 fix OOB access in log_syntax_error for malformed include parsing [`#26`](https://github.com/rdkcentral/javascript-templates/pull/26)
- RDKB-65677 eliminate session_create leaks and strengthen regression coverage [`#24`](https://github.com/rdkcentral/javascript-templates/pull/24)
- Add changelog for release 2.3.0 [`6d3c2ca`](https://github.com/rdkcentral/javascript-templates/commit/6d3c2ca36a06cc878c9b125b4053dd66d4be3f25)
- Merge tag '2.2.0' into develop [`d73972d`](https://github.com/rdkcentral/javascript-templates/commit/d73972dcf3281b29682f4561a32904d0eb9611dc)

#### [2.2.0](https://github.com/rdkcentral/javascript-templates/compare/2.1.0...2.2.0)
Expand Down
4 changes: 2 additions & 2 deletions cov_docker_script/component_config.json
Original file line number Diff line number Diff line change
Expand Up @@ -75,8 +75,8 @@
},
{
"name": "dbus",
"repo": "https://github.com/deepin-community/dbus.git",
"branch" : "master",
"repo": "https://gitlab.freedesktop.org/dbus/dbus.git",
"branch": "dbus-1.14",
"build": {
"type": "cmake",
"build_dir": "build",
Expand Down
Loading
Loading