Merge pull request #11 from xinbetween/feature/threat-model #3
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # CodeQL code scanning. | |
| # | |
| # This exists as a workflow rather than as GitHub's default setup for one reason: the Xcode project is not | |
| # committed. XcodeGen writes it from project.yml, so `autobuild` looked for a project or workspace, found | |
| # neither, and gave up with `no-project-found`. The reaction to that failure was to drop Swift from the | |
| # languages being scanned, which left the one language worth scanning in a tool that reads other people's | |
| # network traffic unscanned. Swift is built here explicitly instead. | |
| # | |
| # Requires GitHub's default setup to be turned OFF for this repository (Settings › Code security › Code | |
| # scanning), because the two configurations cannot both be active. | |
| name: CodeQL | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| schedule: | |
| # Weekly, so a new query release finds old code. Wednesday early UTC: no contention with release runs. | |
| - cron: "17 4 * * 3" | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: codeql-${{ github.ref }} | |
| cancel-in-progress: ${{ github.event_name == 'pull_request' }} | |
| jobs: | |
| analyze: | |
| name: analyze (${{ matrix.language }}) | |
| runs-on: ${{ matrix.runner }} | |
| timeout-minutes: 60 | |
| permissions: | |
| security-events: write # the only reason this workflow needs more than read | |
| contents: read | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| # Swift has to be built, and only a macOS runner can. See the header. | |
| - language: swift | |
| runner: macos-15 | |
| build-mode: manual | |
| # The site generator, the packaging scripts and the workflows themselves. Nothing to build. | |
| - language: python | |
| runner: ubuntu-24.04 | |
| build-mode: none | |
| - language: actions | |
| runner: ubuntu-24.04 | |
| build-mode: none | |
| steps: | |
| - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5.1.0 | |
| # Everything that is not the compilation happens before init, and deliberately so. Once init has run, | |
| # CodeQL traces the job by preloading an x86_64 libtrace.dylib through DYLD_INSERT_LIBRARIES, which puts | |
| # every child process under Rosetta 2 — and Homebrew refuses to install an x86_64 build into the ARM | |
| # prefix: "Cannot install under Rosetta 2 in ARM default prefix". Generating the project needs no tracing | |
| # anyway; only the compiler does. | |
| - name: Prepare the project | |
| if: matrix.build-mode == 'manual' | |
| run: | | |
| set -euo pipefail | |
| # Newest Xcode only. CI's test job covers the oldest-supported compiler; this build exists to give | |
| # CodeQL something to trace, and tracing it twice would double the cost for the same findings. | |
| sudo xcode-select -s "$(ls -d /Applications/Xcode*.app | sort -V | tail -1)" | |
| xcodebuild -version | |
| brew install xcodegen | |
| xcodegen generate | |
| - uses: github/codeql-action/init@7999b86c43a865dc79d8923397f35af22de63401 # v4 | |
| with: | |
| languages: ${{ matrix.language }} | |
| build-mode: ${{ matrix.build-mode }} | |
| # security-extended over the default suite: this app holds decrypted request bodies and a CA key, so | |
| # the extra precision-medium queries are worth the false positives they bring. | |
| queries: security-extended | |
| - name: Build for analysis | |
| if: matrix.build-mode == 'manual' | |
| run: | | |
| set -euo pipefail | |
| # Signing off, as in the test job: analysis needs the compilation, not a runnable app. `clean build` | |
| # rather than `build`, because CodeQL only sees the files the compiler actually recompiles and an | |
| # incremental build would hand it a fraction of the sources. | |
| xcodebuild clean build \ | |
| -project Flowlight.xcodeproj \ | |
| -scheme Flowlight \ | |
| -destination 'platform=macOS' \ | |
| CODE_SIGN_IDENTITY=- CODE_SIGN_STYLE=Manual DEVELOPMENT_TEAM= CODE_SIGN_ENTITLEMENTS= | |
| - uses: github/codeql-action/analyze@7999b86c43a865dc79d8923397f35af22de63401 # v4 | |
| with: | |
| category: /language:${{ matrix.language }} |