11name : Generate code scanning query lists
22
3- # **What it does**: This workflow is currently run manually approximately every two weeks as part
4- # of the release process for the CodeQL CLI. We hope to automate this in the future
5- # When run, this workflow generates updated query lists with data from the codeql
6- # repository, and creates a pull request if there are updates.
7- # **Why we have it**: So we can automate CodeQL query tables and show code scanning users the built in queries.
8- # **Who does it impact**: Anyone making CodeQL query suite changes in `github/codeql`, and wanting to get them published on the docs site.
3+ # Manual CodeQL CLI release runs, about every two weeks, generate query table reusables
4+ # from github/codeql and open a pull request when they change.
95
106on :
117 workflow_dispatch :
@@ -53,16 +49,14 @@ jobs:
5349 echo "Copied files from github/codeql repo. Commit SHA: $OPENAPI_COMMIT_SHA"
5450
5551 - name : Download CodeQL CLI
56- # Look under the ` codeql` directory, as this is where we checked out the ` github/codeql` repo
52+ # fetch- codeql lives in the checked- out github/codeql repository.
5753 uses : ./codeql/.github/actions/fetch-codeql
5854
5955 - name : Test CodeQL CLI Download
6056 shell : bash
6157 run : codeql --version
6258
63- # "Server for running multiple commands while avoiding repeated JVM initialization."
64- # Having started this should speed up the execution of the various
65- # CLI calls of the executable.
59+ # Start the CodeQL CLI server once so later CodeQL commands avoid repeated JVM initialization.
6660 - name : Start CodeQL CLI server in the background
6761 shell : bash
6862 run : |
7266
7367 - uses : ./.github/actions/install-cocofix
7468 with :
75- # The Docs Engineering Bot app cannot read the org-scoped
76- # @github/cocofix package (its Packages permission is repo-level
77- # only), so this step keeps using the PAT until the app is granted
78- # organization package read access.
69+ # The Docs Engineering Bot app has repo-level Packages permission and cannot
70+ # read org-scoped packages, so cocofix installation requires the PAT.
7971 token : ${{ secrets.DOCS_BOT_PAT_BASE }}
8072
8173 - name : Build code scanning security query lists
@@ -123,16 +115,14 @@ jobs:
123115 echo "Copied files from github/codeql repo. Commit SHA: $OPENAPI_COMMIT_SHA"
124116
125117 - name : Download CodeQL CLI
126- # Look under the ` codeql` directory, as this is where we checked out the ` github/codeql` repo
118+ # fetch- codeql lives in the checked- out github/codeql repository.
127119 uses : ./codeql/.github/actions/fetch-codeql
128120
129121 - name : Test CodeQL CLI Download
130122 shell : bash
131123 run : codeql --version
132124
133- # "Server for running multiple commands while avoiding repeated JVM initialization."
134- # Having started this should speed up the execution of the various
135- # CLI calls of the executable.
125+ # Start the CodeQL CLI server once so later CodeQL commands avoid repeated JVM initialization.
136126 - name : Start CodeQL CLI server in the background
137127 shell : bash
138128 run : |
@@ -210,12 +200,10 @@ jobs:
210200 shell : bash
211201 run : |
212202
213- # When we started, we downloaded the CodeQL CLI here in this workflow.
214- # We have no intention of checking that in but we also don't want
215- # `git status ...` to show it as an untracked file.
203+ # Git status must only report generated query tables, so remove the
204+ # checked-out CodeQL repository.
216205 rm -fr ./codeql
217206
218- # If nothing to commit, exit now. It's fine. No orphans.
219207 changes=$(git diff --name-only | wc -l)
220208 untracked=$(git status --untracked-files --short | wc -l)
221209 if [[ $changes -eq 0 ]] && [[ $untracked -eq 0 ]]; then
@@ -228,12 +216,10 @@ jobs:
228216
229217 branchname=codeql-query-tables-${{ steps.codeql.outputs.OPENAPI_COMMIT_SHA }}
230218
231- # Exit if the branch already exists. Since the actions/checkout fetch-depth is 1,
232- # it doesn't "know" about branches locally, so we need to manually list them.
219+ # Query the remote because actions/checkout with fetch-depth 1 omits other remote-tracking branches.
233220 branchExists=$(git ls-remote --heads origin refs/heads/$branchname | wc -l)
234221
235- # When run on a pull_request, we're just testing the tooling.
236- # Exit before it actually pushes the possible changes.
222+ # Pull request runs validate generated files without pushing branches.
237223 if [ "$DRY_RUN" = "true" ]; then
238224 echo "Dry-run mode when run in a pull request"
239225 echo "See the 'Insight into diff' step for the changes it would create PR about."
0 commit comments