-
-
Notifications
You must be signed in to change notification settings - Fork 179
147 lines (138 loc) · 6.56 KB
/
Copy pathcodeql.yml
File metadata and controls
147 lines (138 loc) · 6.56 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
# The contents of this file are subject to the terms of the Common Development and
# Distribution License (the License). You may not use this file except in compliance with the
# License.
#
# You can obtain a copy of the License at legal/CDDLv1.0.txt. See the License for the
# specific language governing permission and limitations under the License.
#
# When distributing Covered Software, include this CDDL Header Notice in each file and include
# the License file at legal/CDDLv1.0.txt. If applicable, add the following below the CDDL
# Header, with the fields enclosed by brackets [] replaced by your own identifying
# information: "Portions copyright [year] [name of copyright owner]".
#
# Copyright 2026 3A Systems, LLC.
name: "CodeQL"
on:
push:
branches: [ 'master' ]
pull_request:
branches: [ 'master' ]
schedule:
# Weekly run, Mondays at 03:27 UTC
- cron: '27 3 * * 1'
# Allows running this workflow manually from the Actions tab or via the gh CLI.
workflow_dispatch:
# Cancel superseded runs on the same ref to avoid the long-running,
# eventually-cancelled analyses seen with the previous default setup.
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
analyze:
name: Analyze (${{ matrix.language }})
runs-on: ubuntu-latest
timeout-minutes: 360
permissions:
# Required to upload results to code scanning.
security-events: write
# Only needed for workflows in private repositories.
actions: read
contents: read
strategy:
fail-fast: false
matrix:
include:
# This large multi-module Maven build is expensive to compile, so we
# use build-mode 'none': CodeQL builds its model straight from the
# Java/Kotlin sources without invoking Maven. This avoids the long,
# eventually-cancelled autobuild that the previous default setup hit.
#
# For higher precision (dataflow through compiled dependencies) switch
# this to 'manual' and uncomment the "Build with Maven" step below.
- language: java-kotlin
build-mode: none
# Interpreted languages: no compilation, extracted straight from source.
- language: javascript-typescript
build-mode: none
# The Fedlet .NET/SAML2 library (openam-federation-library). C#
# supports build-mode 'none', so it is extracted from source without
# needing MSBuild/nuget on the runner.
- language: csharp
build-mode: none
# Scans the repository's own GitHub Actions workflows.
- language: actions
build-mode: none
steps:
- name: Checkout repository
uses: actions/checkout@v7
- name: Initialize CodeQL
uses: github/codeql-action/init@v4
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}
# security-and-quality = security-extended plus the maintainability and
# reliability queries. The security packs alone carry no rule scored
# below "medium" and no note-level rule, so this is the only way the
# low/note tiers of the Security tab ever get populated.
queries: security-and-quality
# Exclude test and integration-test sources. With build-mode 'none'
# CodeQL extracts straight from source, so paths-ignore reliably
# scopes the analysis (it is honored for compiled languages only when
# build-mode is 'none').
config: |
paths-ignore:
- '**/src/test/**'
- '**/src/it/**'
# Third-party / vendored JavaScript — analysing it only adds noise.
- '**/*.min.js'
- '**/node_modules/**'
- '**/test-output/**'
- 'openam-ui/openam-ui-ria/src/main/js/libs/**'
# Unmodified third-party libraries served by openam-server-only:
# YUI 2.3.0, the Sun Web UI (Lockhart) scripts and Bluff 0.3.6.2.
# The com_sun_web_ui JSPs carry OpenAM changes and stay analysed.
- 'openam-server-only/src/main/webapp/assets/lib/yui/**'
- 'openam-server-only/src/main/webapp/com_sun_web_ui/js/**'
- 'openam-server-only/src/main/webapp/js/Bluff-0.3.6.2/**'
# JAXB 1.0.6 classes generated in 2012 and committed, with a copy
# of its com.sun.xml.bind runtime. They yield about 44,500 of the
# 58,900 Java results; a SARIF upload may carry at most 25,000.
# Of an accepted upload Code scanning keeps the top 5,000 results
# by severity: every error and warning of the remaining ~14,400
# is kept, only recommendation-level results are dropped.
- 'openam-schema/openam-liberty-schema/src/main/java/**'
- 'openam-schema/openam-saml2-schema/src/main/java/**'
- 'openam-schema/openam-wsfederation-schema/src/main/java/**'
# .NET build output (generated AssemblyInfo, compiled artifacts).
- '**/obj/**'
- '**/bin/**'
query-filters:
# The JavaScript extractor parses script blocks of JSPs and Velocity
# templates, and scripts injected into XML, as plain JavaScript, so
# every <%= %>, #if or < is reported as a syntax error. The
# extractor skips a block it cannot parse either way.
- exclude:
id: js/syntax-error
# --- Manual build (only used when build-mode is 'manual') -------------
# - name: Set up JDK 11
# uses: actions/setup-java@v5
# with:
# java-version: '11'
# distribution: 'zulu'
# - name: Cache Maven packages
# uses: actions/cache@v6
# with:
# path: ~/.m2/repository
# key: ${{ runner.os }}-m2-repository-${{ hashFiles('**/pom.xml') }}
# restore-keys: ${{ runner.os }}-m2-repository
# - name: Build with Maven
# env:
# MAVEN_OPTS: -Dhttps.protocols=TLSv1.2 -Dmaven.wagon.httpconnectionManager.ttlSeconds=120 -Dmaven.wagon.http.retryHandler.requestSentEnabled=true -Dmaven.wagon.http.retryHandler.count=10
# run: mvn --batch-mode --errors -DskipTests -Dmaven.test.skip=true clean compile --file pom.xml
# ---------------------------------------------------------------------
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v4
with:
category: "/language:${{ matrix.language }}"