Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 11 additions & 0 deletions .github/workflows/code-scan.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,14 @@ on:
required: false
type: boolean
default: true
codeql-build-cmd:
required: false
type: string
default: 'V=1 make build'
codeql-build-mode:
required: false
type: string
default: ''

permissions:
actions: read
Expand All @@ -15,3 +23,6 @@ jobs:
codeql:
if: inputs.run-codeql
uses: ./.github/workflows/codeql-analysis.yml
with:
codeql-build-cmd: ${{ inputs.codeql-build-cmd }}
codeql-build-mode: ${{ inputs.codeql-build-mode }}
10 changes: 10 additions & 0 deletions .github/workflows/codeql-analysis.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,10 @@ on:
required: false
type: string
default: 'V=1 make build'
codeql-build-mode:
required: false
type: string
default: ''
goprivate:
required: false
type: string
Expand Down Expand Up @@ -99,6 +103,7 @@ jobs:
uses: github/codeql-action/init@e46ed2cbd01164d986452f91f178727624ae40d7 # v4.35.3
with:
languages: ${{ matrix.language }}
build-mode: ${{ inputs.codeql-build-mode }}
queries: security-and-quality # use Canonical suite
Comment thread
azazeal marked this conversation as resolved.
packs: codeql/go-queries # and pin the official pack explicitly
-
Expand All @@ -107,7 +112,12 @@ jobs:
run: |
make bootstrap
-
# Run only when the selected build mode expects a manual build:
# - '' (unset) keeps legacy behavior for existing callers.
# - 'manual' means the caller wants this step to drive the build.
# 'autobuild' and 'none' are handled by codeql-action itself, so we skip.
name: Build
if: inputs.codeql-build-mode == '' || inputs.codeql-build-mode == 'manual'
env:
CODEQL_BUILD_CMD: ${{ inputs.codeql-build-cmd }}
run: |
Expand Down
5 changes: 5 additions & 0 deletions .github/workflows/goCI.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,10 @@ on:
required: false
type: string
default: 'V=1 make build'
codeql-build-mode:
required: false
type: string
default: ''
codeql-make-bootstrap:
required: false
type: boolean
Expand Down Expand Up @@ -117,6 +121,7 @@ jobs:
os-dependencies: ${{ inputs.os-dependencies }}
codeql-make-bootstrap: ${{ inputs.codeql-make-bootstrap }}
codeql-build-cmd: ${{ inputs.codeql-build-cmd }}
codeql-build-mode: ${{ inputs.codeql-build-mode }}
secrets:
SSH_PRIVATE_KEY: ${{ secrets.SSH_PRIVATE_KEY }}
PAT: ${{ secrets.PAT }}
Expand Down