Skip to content

DO NOT MERGE: Remove caching steps from QL4QL workflows #51587

DO NOT MERGE: Remove caching steps from QL4QL workflows

DO NOT MERGE: Remove caching steps from QL4QL workflows #51587

name: Run QL for QL
on:
push:
branches: ['henrymercer/test-ql4ql-*']
env:
CODEQL_ACTION_PER_LANGUAGE_BUNDLES: "true"
CARGO_TERM_COLOR: always
permissions:
contents: read
security-events: write
jobs:
analyze:
if: github.repository_owner == 'github'
runs-on: ubuntu-latest-xl
steps:
### Build the queries ###
- uses: actions/checkout@v5
with:
fetch-depth: 0
- name: Find codeql
id: find-codeql
uses: github/codeql-action/setup-codeql@main
with:
tools: nightly
### Build the extractor ###
- name: Release build
run: cd ql; ./scripts/create-extractor-pack.sh
env:
GH_TOKEN: ${{ github.token }}
- name: Make database and analyze
run: |
./ql/target/release/buramu | tee deprecated.blame # Add a blame file for the extractor to parse.
${CODEQL} database create --threads=0 -l=ql ${DB} --search-path "${{ github.workspace }}"
${CODEQL} database analyze -j0 --format=sarif-latest --output=ql-for-ql.sarif ${DB} ql/ql/src/codeql-suites/ql-code-scanning.qls
env:
CODEQL: ${{ steps.find-codeql.outputs.codeql-path }}
DB: ${{ runner.temp }}/DB
LGTM_INDEX_FILTERS: |
exclude:ql/ql/test
exclude:*/ql/lib/upgrades/
exclude:java/ql/integration-tests
- name: Upload sarif to code-scanning
uses: github/codeql-action/upload-sarif@main
with:
sarif_file: ql-for-ql.sarif
category: ql-for-ql
- name: Sarif as artifact
uses: actions/upload-artifact@v4
with:
name: ql-for-ql.sarif
path: ql-for-ql.sarif
- name: Split out the sarif file into langs
run: |
mkdir split-sarif
node ./ql/scripts/split-sarif.js ql-for-ql.sarif split-sarif
- name: Upload langs as artifacts
uses: actions/upload-artifact@v4
with:
name: ql-for-ql-langs
path: split-sarif
retention-days: 1