mirror of
https://github.com/microsoft/vscode.git
synced 2026-09-30 03:00:30 +01:00
Create custom CodeQL workflow (#334739)
* Create custom CodeQL workflow * build: Exclude nested esbuild scripts from CodeQL Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * build: Align CodeQL coverage with packaged files Keep Markdown build/test scripts out of the extension package and restore scanning of the shipped chat-library postinstall script. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * ci: Expand CodeQL release coverage and scope permissions Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
co-authored by
Copilot
parent
814ab138a8
commit
efc2c86f03
@@ -1,21 +1,115 @@
|
||||
# Apply this file to CodeQL default setup with the repository property:
|
||||
# github-codeql-config-file: ./.github/codeql/codeql-config.yml
|
||||
# Applied by .github/workflows/codeql.yml.
|
||||
paths-ignore:
|
||||
# Keep directory exclusions scoped: product code imports helpers from some
|
||||
# extension src/test directories.
|
||||
- 'test/**'
|
||||
- 'src/**/test/**'
|
||||
- 'build/**/test/**'
|
||||
# Development, build, packaging, and CI tooling, not shipped product code.
|
||||
- '.agents/**'
|
||||
- '.eslint-plugin-local/**'
|
||||
- '.github/**'
|
||||
- '.vscode-test.js'
|
||||
- '.vscode/**'
|
||||
- 'build/**'
|
||||
- 'cli/build.rs'
|
||||
- 'eslint.config.js'
|
||||
- 'extensions/**/.esbuild.*'
|
||||
- 'extensions/*/build/**'
|
||||
- 'extensions/*/esbuild*.mts'
|
||||
- 'extensions/*/scripts/**'
|
||||
- 'extensions/copilot/.eslintplugin/**'
|
||||
- 'extensions/copilot/.mocha-multi-reporters.js'
|
||||
- 'extensions/copilot/.mocharc.js'
|
||||
- 'extensions/copilot/.vscode-test.mjs'
|
||||
- 'extensions/copilot/.vscode/**'
|
||||
- 'extensions/copilot/chat-lib/vitest.config.ts'
|
||||
- 'extensions/copilot/script/**'
|
||||
- 'extensions/copilot/vite.config.ts'
|
||||
- 'extensions/esbuild*.mts'
|
||||
- 'extensions/postinstall.mjs'
|
||||
- 'extensions/search-result/syntaxes/generateTMLanguage.js'
|
||||
- 'gulpfile.mjs'
|
||||
- 'scripts/**'
|
||||
|
||||
# Generated build output and dependencies; analyze the product sources instead.
|
||||
- '**/node_modules/**'
|
||||
- '**/out/**'
|
||||
- '.build/**'
|
||||
- 'cli/target/**'
|
||||
- 'coverage/**'
|
||||
- 'extensions/**/dist/**'
|
||||
- 'out*/**'
|
||||
|
||||
# Test directories, fixtures, and helpers.
|
||||
- 'cli/tests/**'
|
||||
- '.eslint-plugin-local/tests/**'
|
||||
- 'extensions/*/server/**/test/**'
|
||||
- 'extensions/*/test-workspace/**'
|
||||
- 'extensions/*/test/**'
|
||||
- 'extensions/*/tests/**'
|
||||
- 'extensions/configuration-editing/src/test/**'
|
||||
- 'extensions/copilot/src/extension/**/test/**'
|
||||
- 'extensions/copilot/src/extension/agents/node/adapters/openaiAdapterForSTests.ts'
|
||||
- 'extensions/copilot/src/extension/typescriptContext/serverPlugin/fixtures/**'
|
||||
- 'extensions/copilot/src/lib/**/test/**'
|
||||
- 'extensions/copilot/src/platform/**/test/**'
|
||||
- 'extensions/copilot/src/platform/commands/common/mockRunCommandExecutionService.ts'
|
||||
- 'extensions/copilot/src/platform/notebook/common/mockAlternativeContentService.ts'
|
||||
- 'extensions/copilot/src/platform/tasks/common/testTasksService.ts'
|
||||
- 'extensions/copilot/src/sanity-test-extension.ts'
|
||||
- 'extensions/copilot/src/shared-fetch-utils/**/test/**'
|
||||
- 'extensions/copilot/src/test-extension.ts'
|
||||
# Standalone chat-lib rewrites runtime VS Code API imports to util/common/test/shims.
|
||||
# These are required runtime dependencies, not tests; exclude only their test-only siblings.
|
||||
- 'extensions/copilot/src/util/common/test/annotatedSrc.ts'
|
||||
- 'extensions/copilot/src/util/common/test/mockChatResponseStream.ts'
|
||||
- 'extensions/copilot/src/util/common/test/simpleMock.ts'
|
||||
- 'extensions/copilot/src/util/common/test/testUtils.ts'
|
||||
- 'extensions/copilot/src/util/node/test/**'
|
||||
- 'extensions/copilot/src/util/test/**'
|
||||
- 'extensions/emmet/src/test/**'
|
||||
- 'extensions/git-base/src/test/**'
|
||||
- 'extensions/git/src/test/**'
|
||||
- 'extensions/github-authentication/src/test/**'
|
||||
- 'extensions/github/src/test/**'
|
||||
- 'extensions/ipynb/src/test/**'
|
||||
- 'extensions/markdown-language-features/src/test/**'
|
||||
- 'extensions/microsoft-authentication/src/**/test/**'
|
||||
- 'extensions/notebook-renderers/src/test/**'
|
||||
- 'extensions/npm/src/test/**'
|
||||
- 'extensions/terminal-suggest/fixtures/**'
|
||||
- 'extensions/terminal-suggest/src/**/test/**'
|
||||
- 'extensions/typescript-language-features/src/test-all.ts'
|
||||
- 'extensions/typescript-language-features/src/test/**'
|
||||
- 'extensions/vscode-api-tests/**'
|
||||
- 'extensions/vscode-colorize-perf-tests/**'
|
||||
- 'extensions/vscode-colorize-tests/**'
|
||||
- 'extensions/vscode-test-resolver/**'
|
||||
- 'src/**/test/**'
|
||||
- 'src/vs/workbench/contrib/terminal/browser/terminalTestHelpers.ts'
|
||||
- 'test/**'
|
||||
|
||||
# Keep exact suffixes: themes.test.contribution.ts ships in the product.
|
||||
- '**/*.fixture.cjs'
|
||||
- '**/*.fixture.cts'
|
||||
- '**/*.fixture.js'
|
||||
- '**/*.fixture.jsx'
|
||||
- '**/*.fixture.mjs'
|
||||
- '**/*.fixture.mts'
|
||||
- '**/*.fixture.ts'
|
||||
- '**/*.fixture.tsx'
|
||||
- '**/*.sanity-test.ts'
|
||||
- '**/*.sanity-test.tsx'
|
||||
- '**/*.spec.cjs'
|
||||
- '**/*.spec.cts'
|
||||
- '**/*.spec.js'
|
||||
- '**/*.spec.jsx'
|
||||
- '**/*.spec.mjs'
|
||||
- '**/*.spec.mts'
|
||||
- '**/*.spec.ts'
|
||||
- '**/*.spec.tsx'
|
||||
- '**/*.stest.ts'
|
||||
- '**/*.stest.tsx'
|
||||
- '**/*.test.cjs'
|
||||
- '**/*.test.cts'
|
||||
- '**/*.test.js'
|
||||
- '**/*.test.jsx'
|
||||
- '**/*.test.mjs'
|
||||
- '**/*.test.cjs'
|
||||
- '**/*.test.mts'
|
||||
- '**/*.test.ts'
|
||||
- '**/*.test.tsx'
|
||||
- '**/*.test.mts'
|
||||
- '**/*.test.cts'
|
||||
|
||||
@@ -0,0 +1,51 @@
|
||||
name: CodeQL
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
- 'release/**/*'
|
||||
pull_request:
|
||||
branches:
|
||||
- main
|
||||
- 'release/**/*'
|
||||
schedule:
|
||||
- cron: '17 19 * * 6'
|
||||
|
||||
permissions: {}
|
||||
|
||||
jobs:
|
||||
analyze:
|
||||
name: Analyze (${{ matrix.language }})
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
actions: read
|
||||
contents: read
|
||||
packages: read
|
||||
security-events: write
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
# Other detected languages occur only in test fixtures or build tooling.
|
||||
include:
|
||||
- language: javascript-typescript
|
||||
build-mode: none
|
||||
- language: rust
|
||||
build-mode: none
|
||||
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
|
||||
- name: Initialize CodeQL
|
||||
uses: github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9
|
||||
with:
|
||||
languages: ${{ matrix.language }}
|
||||
build-mode: ${{ matrix.build-mode }}
|
||||
dependency-caching: true
|
||||
config-file: ./.github/codeql/codeql-config.yml
|
||||
|
||||
- name: Perform CodeQL Analysis
|
||||
uses: github/codeql-action/analyze@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9
|
||||
with:
|
||||
category: /language:${{ matrix.language }}
|
||||
-30
@@ -1,30 +0,0 @@
|
||||
path_classifiers:
|
||||
test:
|
||||
# Classify all files in the top-level directories test/ and testsuites/ as test code.
|
||||
- test
|
||||
# Classify all files with suffix `.test` as test code.
|
||||
# Note: use only forward slash / as a path separator.
|
||||
# * Matches any sequence of characters except a forward slash.
|
||||
# ** Matches any sequence of characters, including a forward slash.
|
||||
# This wildcard must either be surrounded by forward slash symbols, or used as the first segment of a path.
|
||||
# It matches zero or more whole directory segments. There is no need to use a wildcard at the end of a directory path because all sub-directories are automatically matched.
|
||||
# That is, /anything/ matches the anything directory and all its subdirectories.
|
||||
# Always enclose the expression in double quotes if it includes *.
|
||||
- "**/*.test.ts"
|
||||
|
||||
# The default behavior is to tag all files created during the
|
||||
# build as `generated`. Results are hidden for generated code. You can tag
|
||||
# further files as being generated by adding them to the `generated` section.
|
||||
generated:
|
||||
# generated code.
|
||||
- out
|
||||
- "out-build"
|
||||
- "out-vscode"
|
||||
- "**/out/**"
|
||||
- ".build/distro/cli-patches/index.js"
|
||||
|
||||
# The default behavior is to tag library code as `library`. Results are hidden
|
||||
# for library code. You can tag further files as being library code by adding them
|
||||
# to the `library` section.
|
||||
library:
|
||||
- "**/node_modules/**"
|
||||
@@ -7,6 +7,8 @@ parameters:
|
||||
type: string
|
||||
|
||||
variables:
|
||||
- name: Codeql.SkipTaskAutoInjection
|
||||
value: true
|
||||
- name: NPM_REGISTRY
|
||||
value: "https://pkgs.dev.azure.com/monacotools/Monaco/_packaging/vscode/npm/registry/"
|
||||
- name: VSCODE_QUALITY
|
||||
|
||||
@@ -6,6 +6,10 @@ trigger:
|
||||
|
||||
pr: none
|
||||
|
||||
variables:
|
||||
- name: Codeql.SkipTaskAutoInjection
|
||||
value: true
|
||||
|
||||
pool:
|
||||
vmImage: ubuntu-latest
|
||||
|
||||
|
||||
@@ -1,5 +0,0 @@
|
||||
path_classifiers:
|
||||
tests:
|
||||
- "test/simulation/fixtures/edit-asyncawait-4151/*.ts"
|
||||
- "test/simulation/fixtures/edit-slice-4149/*.ts"
|
||||
- src/platform/parser/test/node/fixtures
|
||||
@@ -1,6 +1,10 @@
|
||||
trigger: none
|
||||
pr: none
|
||||
|
||||
variables:
|
||||
- name: Codeql.SkipTaskAutoInjection
|
||||
value: true
|
||||
|
||||
resources:
|
||||
repositories:
|
||||
- repository: 1esPipelines
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
test/**
|
||||
test-workspace/**
|
||||
scripts/**
|
||||
src/**
|
||||
notebook/**
|
||||
tsconfig*.json
|
||||
|
||||
@@ -6,9 +6,9 @@
|
||||
import * as jsonc from 'jsonc-parser';
|
||||
import * as path from 'path';
|
||||
import * as vscode from 'vscode';
|
||||
import { wait } from '../test/testUtils';
|
||||
import { ITypeScriptServiceClient, ServerResponse } from '../typescriptService';
|
||||
import { coalesce } from '../utils/arrays';
|
||||
import { raceTimeout } from '../utils/async';
|
||||
import { readUnifiedConfig } from '../utils/configuration';
|
||||
import { Disposable } from '../utils/dispose';
|
||||
import { exists } from '../utils/fs';
|
||||
@@ -157,13 +157,11 @@ class TscTaskProvider extends Disposable implements vscode.TaskProvider {
|
||||
const getConfigsTimeout = new vscode.CancellationTokenSource();
|
||||
token.onCancellationRequested(() => getConfigsTimeout.cancel());
|
||||
|
||||
return Promise.race([
|
||||
return (await raceTimeout(
|
||||
this.tsconfigProvider.getConfigsForWorkspace(getConfigsTimeout.token).then(x => Array.from(x)),
|
||||
wait(this.findConfigFilesTimeout).then(() => {
|
||||
getConfigsTimeout.cancel();
|
||||
return [];
|
||||
}),
|
||||
]);
|
||||
this.findConfigFilesTimeout,
|
||||
() => getConfigsTimeout.cancel(),
|
||||
)) ?? [];
|
||||
}
|
||||
|
||||
private static async getCommand(project: TSConfig): Promise<string> {
|
||||
|
||||
Reference in New Issue
Block a user