Skip to content

Commit 15bc6fc

Browse files
author
Paolo Tranquilli
committed
Merge branch 'main' into redsun82/rules_rust
2 parents 87f29ad + b096696 commit 15bc6fc

File tree

583 files changed

+12539
-13807
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

583 files changed

+12539
-13807
lines changed

.devcontainer/Dockerfile.codespaces

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
FROM mcr.microsoft.com/devcontainers/base:ubuntu-24.04
2+
3+
USER root
4+
# Install needed packages according to https://codeql.github.com/docs/codeql-overview/system-requirements/
5+
# most come from the base image, but we need to install some additional ones
6+
RUN DEBIAN_FRONTEND=noninteractive apt update && apt install -y sudo man-db python3.12 npm unminimize
7+
RUN yes | unminimize

.devcontainer/devcontainer.json

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,4 @@
11
{
2-
"image": "mcr.microsoft.com/devcontainers/base:ubuntu-24.04",
32
"extensions": [
43
"rust-lang.rust-analyzer",
54
"bungcip.better-toml",
@@ -8,6 +7,10 @@
87
"ms-vscode.test-adapter-converter",
98
"slevesque.vscode-zipexplorer"
109
],
10+
"build": {
11+
// Path is relative to the devcontainer.json file.
12+
"dockerfile": "Dockerfile.codespaces"
13+
},
1114
"settings": {
1215
"files.watcherExclude": {
1316
"**/target/**": true

.github/codeql/codeql-config.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,7 @@ queries:
44
- uses: security-and-quality
55

66
paths-ignore:
7+
- '/actions/ql/test'
78
- '/cpp/'
89
- '/java/'
910
- '/python/'

.github/workflows/codegen.yml

Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
name: Codegen
2+
3+
on:
4+
pull_request:
5+
paths:
6+
- "misc/bazel/**"
7+
- "misc/codegen/**"
8+
- "*.bazel*"
9+
- .github/workflows/codegen.yml
10+
- .pre-commit-config.yaml
11+
branches:
12+
- main
13+
- rc/*
14+
- codeql-cli-*
15+
16+
permissions:
17+
contents: read
18+
19+
jobs:
20+
codegen:
21+
runs-on: ubuntu-latest
22+
steps:
23+
- uses: actions/checkout@v4
24+
- uses: actions/setup-python@v4
25+
with:
26+
python-version-file: 'misc/codegen/.python-version'
27+
- uses: pre-commit/action@646c83fcd040023954eafda54b4db0192ce70507
28+
name: Check that python code is properly formatted
29+
with:
30+
extra_args: autopep8 --all-files
31+
- name: Run codegen tests
32+
shell: bash
33+
run: |
34+
bazel test //misc/codegen/...

.github/workflows/swift.yml

Lines changed: 27 additions & 50 deletions
Original file line numberDiff line numberDiff line change
@@ -18,45 +18,39 @@ on:
1818
- main
1919
- rc/*
2020
- codeql-cli-*
21-
push:
22-
paths:
23-
- "swift/**"
24-
- "misc/bazel/**"
25-
- "misc/codegen/**"
26-
- "shared/**"
27-
- "*.bazel*"
28-
- .github/workflows/swift.yml
29-
- .github/actions/**
30-
- codeql-workspace.yml
31-
- .pre-commit-config.yaml
32-
- "!**/*.md"
33-
- "!**/*.qhelp"
34-
branches:
35-
- main
36-
- rc/*
37-
- codeql-cli-*
3821

3922
permissions:
4023
contents: read
4124

25+
defaults:
26+
run:
27+
shell: bash
28+
working-directory: swift
29+
4230
jobs:
43-
# not using a matrix as you cannot depend on a specific job in a matrix, and we want to start linux checks
44-
# without waiting for the macOS build
45-
build-and-test-macos:
31+
build-and-test:
4632
if: github.repository_owner == 'github'
47-
runs-on: macos-13-xlarge
48-
steps:
49-
- uses: actions/checkout@v4
50-
- uses: ./swift/actions/build-and-test
51-
qltests-macos:
52-
if: ${{ github.repository_owner == 'github' && github.event_name == 'pull_request' }}
53-
needs: build-and-test-macos
54-
runs-on: macos-13-xlarge
33+
strategy:
34+
matrix:
35+
runner: [ubuntu-latest, macos-13-xlarge]
36+
fail-fast: false
37+
runs-on: ${{ matrix.runner }}
5538
steps:
5639
- uses: actions/checkout@v4
57-
- uses: ./swift/actions/run-ql-tests
40+
- name: Setup (Linux)
41+
if: runner.os == 'Linux'
42+
run: |
43+
sudo apt-get update
44+
sudo apt-get install -y uuid-dev zlib1g-dev
45+
- name: Build Swift extractor
46+
shell: bash
47+
run: |
48+
bazel run :install
49+
- name: Run Swift tests
50+
shell: bash
51+
run: |
52+
bazel test ... --test_tag_filters=-override --test_output=errors
5853
clang-format:
59-
if : ${{ github.event_name == 'pull_request' }}
6054
runs-on: ubuntu-latest
6155
steps:
6256
- uses: actions/checkout@v4
@@ -65,41 +59,24 @@ jobs:
6559
with:
6660
extra_args: clang-format --all-files
6761
codegen:
68-
if : ${{ github.event_name == 'pull_request' }}
6962
runs-on: ubuntu-latest
7063
steps:
7164
- uses: actions/checkout@v4
72-
- uses: bazelbuild/setup-bazelisk@v2
73-
- uses: actions/setup-python@v4
74-
with:
75-
python-version-file: 'swift/.python-version'
76-
- uses: pre-commit/action@646c83fcd040023954eafda54b4db0192ce70507
77-
name: Check that python code is properly formatted
78-
with:
79-
extra_args: autopep8 --all-files
8065
- uses: ./.github/actions/fetch-codeql
8166
- uses: pre-commit/action@646c83fcd040023954eafda54b4db0192ce70507
8267
name: Check that QL generated code was checked in
8368
with:
8469
extra_args: swift-codegen --all-files
8570
- name: Generate C++ files
8671
run: |
87-
bazel run //swift/codegen:codegen -- --generate=trap,cpp --cpp-output=$PWD/generated-cpp-files
72+
bazel run codegen -- --generate=trap,cpp --cpp-output=$PWD/generated-cpp-files
8873
- uses: actions/upload-artifact@v4
8974
with:
9075
name: swift-generated-cpp-files
9176
path: generated-cpp-files/**
92-
database-upgrade-scripts:
93-
if : ${{ github.event_name == 'pull_request' }}
94-
runs-on: ubuntu-latest
95-
steps:
96-
- uses: actions/checkout@v4
97-
- uses: ./.github/actions/fetch-codeql
98-
- uses: ./swift/actions/database-upgrade-scripts
9977
check-no-override:
100-
if : github.event_name == 'pull_request'
10178
runs-on: ubuntu-latest
10279
steps:
10380
- uses: actions/checkout@v4
104-
- shell: bash
105-
run: bazel test //swift/... --test_tag_filters=override --test_output=errors
81+
- name: Check that no override is present in load.bzl
82+
run: bazel test ... --test_tag_filters=override --test_output=errors

actions/ql/src/Security/CWE-077/EnvPathInjectionCritical.ql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
/**
2-
* @name PATH Enviroment Variable built from user-controlled sources
2+
* @name PATH environment variable built from user-controlled sources
33
* @description Building the PATH environment variable from user-controlled sources may alter the execution of following system commands
44
* @kind path-problem
55
* @problem.severity error

actions/ql/src/Security/CWE-077/EnvPathInjectionMedium.ql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
/**
2-
* @name PATH Enviroment Variable built from user-controlled sources
2+
* @name PATH environment variable built from user-controlled sources
33
* @description Building the PATH environment variable from user-controlled sources may alter the execution of following system commands
44
* @kind path-problem
55
* @problem.severity error

actions/ql/src/Security/CWE-077/EnvVarInjectionCritical.ql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
/**
2-
* @name Enviroment Variable built from user-controlled sources
2+
* @name Environment variable built from user-controlled sources
33
* @description Building an environment variable from user-controlled sources may alter the execution of following system commands
44
* @kind path-problem
55
* @problem.severity error

actions/ql/src/Security/CWE-077/EnvVarInjectionMedium.ql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
/**
2-
* @name Enviroment Variable built from user-controlled sources
2+
* @name Environment variable built from user-controlled sources
33
* @description Building an environment variable from user-controlled sources may alter the execution of following system commands
44
* @kind path-problem
55
* @problem.severity error
Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
---
2+
category: fix
3+
---
4+
* Fixed typos in the query and alert titles for the queries
5+
`actions/envpath-injection/critical`, `actions/envpath-injection/medium`,
6+
`actions/envvar-injection/critical`, and `actions/envvar-injection/medium`.

0 commit comments

Comments
 (0)