Skip to content

Commit a1df1d1

Browse files
authored
Merge branch 'main' into experimental-strong-params
2 parents 9d27702 + d50816a commit a1df1d1

44 files changed

Lines changed: 676 additions & 241 deletions

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

.github/workflows/ql-for-ql-build.yml

Lines changed: 20 additions & 57 deletions
Original file line numberDiff line numberDiff line change
@@ -10,9 +10,10 @@ env:
1010
CARGO_TERM_COLOR: always
1111

1212
jobs:
13-
queries:
14-
runs-on: ubuntu-latest
13+
analyze:
14+
runs-on: ubuntu-latest-xl
1515
steps:
16+
### Build the queries ###
1617
- uses: actions/checkout@v3
1718
- name: Find codeql
1819
id: find-codeql
@@ -48,11 +49,7 @@ jobs:
4849
name: query-pack-zip
4950
path: ${{ runner.temp }}/query-pack.zip
5051

51-
extractors:
52-
runs-on: ubuntu-latest
53-
54-
steps:
55-
- uses: actions/checkout@v3
52+
### Build the extractor ###
5653
- name: Cache entire extractor
5754
id: cache-extractor
5855
uses: actions/cache@v3
@@ -96,15 +93,8 @@ jobs:
9693
ql/target/release/ql-extractor
9794
ql/target/release/ql-extractor.exe
9895
retention-days: 1
99-
package:
100-
runs-on: ubuntu-latest
101-
102-
needs:
103-
- extractors
104-
- queries
10596

106-
steps:
107-
- uses: actions/checkout@v3
97+
### Package the queries and extractor ###
10898
- uses: actions/download-artifact@v3
10999
with:
110100
name: query-pack-zip
@@ -132,16 +122,8 @@ jobs:
132122
name: codeql-ql-pack
133123
path: codeql-ql.zip
134124
retention-days: 1
135-
analyze:
136-
runs-on: ubuntu-latest
137-
strategy:
138-
matrix:
139-
folder: [cpp, csharp, java, javascript, python, ql, ruby, swift, go]
140-
141-
needs:
142-
- package
143125

144-
steps:
126+
### Run the analysis ###
145127
- name: Download pack
146128
uses: actions/download-artifact@v3
147129
with:
@@ -161,22 +143,18 @@ jobs:
161143
env:
162144
PACK: ${{ runner.temp }}/pack
163145

164-
- name: Checkout repository
165-
uses: actions/checkout@v3
166146
- name: Create CodeQL config file
167147
run: |
168-
echo "paths:" > ${CONF}
169-
echo " - ${FOLDER}" >> ${CONF}
170148
echo "paths-ignore:" >> ${CONF}
171149
echo " - ql/ql/test" >> ${CONF}
150+
echo " - \"*/ql/lib/upgrades/\"" >> ${CONF}
172151
echo "disable-default-queries: true" >> ${CONF}
173152
echo "packs:" >> ${CONF}
174153
echo " - codeql/ql" >> ${CONF}
175154
echo "Config file: "
176155
cat ${CONF}
177156
env:
178157
CONF: ./ql-for-ql-config.yml
179-
FOLDER: ${{ matrix.folder }}
180158
- name: Initialize CodeQL
181159
uses: github/codeql-action/init@aa93aea877e5fb8841bcb1193f672abf6e9f2980
182160
with:
@@ -187,39 +165,24 @@ jobs:
187165
- name: Perform CodeQL Analysis
188166
uses: github/codeql-action/analyze@aa93aea877e5fb8841bcb1193f672abf6e9f2980
189167
with:
190-
category: "ql-for-ql-${{ matrix.folder }}"
168+
category: "ql-for-ql"
191169
- name: Copy sarif file to CWD
192-
run: cp ../results/ql.sarif ./${{ matrix.folder }}.sarif
170+
run: cp ../results/ql.sarif ./ql-for-ql.sarif
193171
- name: Fixup the $scema in sarif # Until https://github.com/microsoft/sarif-vscode-extension/pull/436/ is part in a stable release
194172
run: |
195-
sed -i 's/\$schema.*/\$schema": "https:\/\/raw.githubusercontent.com\/oasis-tcs\/sarif-spec\/master\/Schemata\/sarif-schema-2.1.0",/' ${{ matrix.folder }}.sarif
173+
sed -i 's/\$schema.*/\$schema": "https:\/\/raw.githubusercontent.com\/oasis-tcs\/sarif-spec\/master\/Schemata\/sarif-schema-2.1.0",/' ql-for-ql.sarif
196174
- name: Sarif as artifact
197175
uses: actions/upload-artifact@v3
198176
with:
199-
name: ${{ matrix.folder }}.sarif
200-
path: ${{ matrix.folder }}.sarif
201-
202-
combine:
203-
runs-on: ubuntu-latest
204-
needs:
205-
- analyze
206-
207-
steps:
208-
- uses: actions/checkout@v3
209-
- name: Make a folder for artifacts.
210-
run: mkdir -p results
211-
- name: Download all sarif files
212-
uses: actions/download-artifact@v3
213-
with:
214-
path: results
215-
- uses: actions/setup-node@v3
216-
with:
217-
node-version: 16
218-
- name: Combine all sarif files
219-
run: |
220-
node ./ql/scripts/merge-sarif.js results/**/*.sarif combined.sarif
221-
- name: Upload combined sarif file
177+
name: ql-for-ql.sarif
178+
path: ql-for-ql.sarif
179+
- name: Split out the sarif file into langs
180+
run: |
181+
mkdir split-sarif
182+
node ./ql/scripts/split-sarif.js ql-for-ql.sarif split-sarif
183+
- name: Upload langs as artifacts
222184
uses: actions/upload-artifact@v3
223185
with:
224-
name: combined.sarif
225-
path: combined.sarif
186+
name: ql-for-ql-langs
187+
path: split-sarif
188+
retention-days: 1

docs/codeql/query-help/cpp.rst

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,9 @@ CodeQL query help for C and C++
33

44
.. include:: ../reusables/query-help-overview.rst
55

6-
For shorter queries that you can use as building blocks when writing your own queries, see the `example queries in the CodeQL repository <https://github.com/github/codeql/tree/main/cpp/ql/examples>`__.
6+
These queries are published in the CodeQL query pack ``codeql/cpp-queries`` (`changelog <https://github.com/github/codeql/tree/codeql-cli/latest/cpp/ql/src/CHANGELOG.md>`__, `source <https://github.com/github/codeql/tree/codeql-cli/latest/cpp/ql/src>`__).
7+
8+
For shorter queries that you can use as building blocks when writing your own queries, see the `example queries in the CodeQL repository <https://github.com/github/codeql/tree/codeql-cli/latest/cpp/ql/examples>`__.
79

810
.. include:: toc-cpp.rst
911

docs/codeql/query-help/csharp.rst

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ CodeQL query help for C#
33

44
.. include:: ../reusables/query-help-overview.rst
55

6-
For shorter queries that you can use as building blocks when writing your own queries, see the `example queries in the CodeQL repository <https://github.com/github/codeql/tree/main/csharp/ql/examples>`__.
6+
These queries are published in the CodeQL query pack ``codeql/csharp-queries`` (`changelog <https://github.com/github/codeql/tree/codeql-cli/latest/csharp/ql/src/CHANGELOG.md>`__, `source <https://github.com/github/codeql/tree/codeql-cli/latest/csharp/ql/src>`__).
7+
8+
For shorter queries that you can use as building blocks when writing your own queries, see the `example queries in the CodeQL repository <https://github.com/github/codeql/tree/codeql-cli/latest/csharp/ql/examples>`__.
79

810
.. include:: toc-csharp.rst

docs/codeql/query-help/go.rst

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ CodeQL query help for Go
33

44
.. include:: ../reusables/query-help-overview.rst
55

6-
For shorter queries that you can use as building blocks when writing your own queries, see the `example queries in the CodeQL repository <https://github.com/github/codeql/tree/main/go/ql/examples>`__.
6+
These queries are published in the CodeQL query pack ``codeql/go-queries`` (`changelog <https://github.com/github/codeql/tree/codeql-cli/latest/go/ql/src/CHANGELOG.md>`__, `source <https://github.com/github/codeql/tree/codeql-cli/latest/go/ql/src>`__).
7+
8+
For shorter queries that you can use as building blocks when writing your own queries, see the `example queries in the CodeQL repository <https://github.com/github/codeql/tree/codeql-cli/latest/go/ql/examples>`__.
79

810
.. include:: toc-go.rst

docs/codeql/query-help/java.rst

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ CodeQL query help for Java
33

44
.. include:: ../reusables/query-help-overview.rst
55

6-
For shorter queries that you can use as building blocks when writing your own queries, see the `example queries in the CodeQL repository <https://github.com/github/codeql/tree/main/java/ql/examples>`__.
6+
These queries are published in the CodeQL query pack ``codeql/java-queries`` (`changelog <https://github.com/github/codeql/tree/codeql-cli/latest/java/ql/src/CHANGELOG.md>`__, `source <https://github.com/github/codeql/tree/codeql-cli/latest/java/ql/src>`__).
7+
8+
For shorter queries that you can use as building blocks when writing your own queries, see the `example queries in the CodeQL repository <https://github.com/github/codeql/tree/codeql-cli/latest/java/ql/examples>`__.
79

810
.. include:: toc-java.rst

docs/codeql/query-help/javascript.rst

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ CodeQL query help for JavaScript
33

44
.. include:: ../reusables/query-help-overview.rst
55

6-
For shorter queries that you can use as building blocks when writing your own queries, see the `example queries in the CodeQL repository <https://github.com/github/codeql/tree/main/javascript/ql/examples>`__.
6+
These queries are published in the CodeQL query pack ``codeql/javascript-queries`` (`changelog <https://github.com/github/codeql/tree/codeql-cli/latest/javascript/ql/src/CHANGELOG.md>`__, `source <https://github.com/github/codeql/tree/codeql-cli/latest/javascript/ql/src>`__).
7+
8+
For shorter queries that you can use as building blocks when writing your own queries, see the `example queries in the CodeQL repository <https://github.com/github/codeql/tree/codeql-cli/latest/javascript/ql/examples>`__.
79

810
.. include:: toc-javascript.rst

docs/codeql/query-help/python.rst

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ CodeQL query help for Python
33

44
.. include:: ../reusables/query-help-overview.rst
55

6-
For shorter queries that you can use as building blocks when writing your own queries, see the `example queries in the CodeQL repository <https://github.com/github/codeql/tree/main/python/ql/examples>`__.
6+
These queries are published in the CodeQL query pack ``codeql/python-queries`` (`changelog <https://github.com/github/codeql/tree/codeql-cli/latest/python/ql/src/CHANGELOG.md>`__, `source <https://github.com/github/codeql/tree/codeql-cli/latest/python/ql/src>`__).
7+
8+
For shorter queries that you can use as building blocks when writing your own queries, see the `example queries in the CodeQL repository <https://github.com/github/codeql/tree/codeql-cli/latest/python/ql/examples>`__.
79

810
.. include:: toc-python.rst

docs/codeql/query-help/ruby.rst

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ CodeQL query help for Ruby
33

44
.. include:: ../reusables/query-help-overview.rst
55

6-
For shorter queries that you can use as building blocks when writing your own queries, see the `example queries in the CodeQL repository <https://github.com/github/codeql/tree/main/ruby/ql/examples>`__.
6+
These queries are published in the CodeQL query pack ``codeql/ruby-queries`` (`changelog <https://github.com/github/codeql/tree/codeql-cli/latest/ruby/ql/src/CHANGELOG.md>`__, `source <https://github.com/github/codeql/tree/codeql-cli/latest/ruby/ql/src>`__).
7+
8+
For shorter queries that you can use as building blocks when writing your own queries, see the `example queries in the CodeQL repository <https://github.com/github/codeql/tree/codeql-cli/latest/ruby/ql/examples>`__.
79

810
.. include:: toc-ruby.rst

java/documentation/library-coverage/coverage.csv

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,7 @@ java.lang,13,,58,,,,,,,,,,,8,,,,,4,,,1,,,,,,,,,,,,,,,46,12
3636
java.net,10,3,7,,,,,,,,,,,,,,10,,,,,,,,,,,,,,,,,,,3,7,
3737
java.nio,15,,6,,13,,,,,,,,,,,,,,,,,,,,,,,,2,,,,,,,,6,
3838
java.sql,11,,,,,,,,,4,,,,,,,,,,,,,,,,7,,,,,,,,,,,,
39-
java.util,44,,438,,,,,,,,,,,34,,,,,,5,2,,1,2,,,,,,,,,,,,,24,414
39+
java.util,44,,441,,,,,,,,,,,34,,,,,,5,2,,1,2,,,,,,,,,,,,,24,417
4040
javax.faces.context,2,7,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,2,,,,7,,
4141
javax.jms,,9,57,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,9,57,
4242
javax.json,,,123,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,100,23

java/documentation/library-coverage/coverage.rst

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -15,9 +15,9 @@ Java framework & library support
1515
`Apache HttpComponents <https://hc.apache.org/>`_,"``org.apache.hc.core5.*``, ``org.apache.http``",5,136,28,,,3,,,,25
1616
`Google Guava <https://guava.dev/>`_,``com.google.common.*``,,728,39,,6,,,,,
1717
`JSON-java <https://github.com/stleary/JSON-java>`_,``org.json``,,236,,,,,,,,
18-
Java Standard Library,``java.*``,3,549,130,28,,,7,,,10
18+
Java Standard Library,``java.*``,3,552,130,28,,,7,,,10
1919
Java extensions,"``javax.*``, ``jakarta.*``",63,609,32,,,4,,1,1,2
2020
`Spring <https://spring.io/>`_,``org.springframework.*``,29,476,101,,,,19,14,,29
2121
Others,"``androidx.slice``, ``cn.hutool.core.codec``, ``com.esotericsoftware.kryo.io``, ``com.esotericsoftware.kryo5.io``, ``com.fasterxml.jackson.core``, ``com.fasterxml.jackson.databind``, ``com.opensymphony.xwork2.ognl``, ``com.rabbitmq.client``, ``com.unboundid.ldap.sdk``, ``com.zaxxer.hikari``, ``flexjson``, ``groovy.lang``, ``groovy.util``, ``jodd.json``, ``kotlin.jvm.internal``, ``net.sf.saxon.s9api``, ``ognl``, ``okhttp3``, ``org.apache.commons.codec``, ``org.apache.commons.jexl2``, ``org.apache.commons.jexl3``, ``org.apache.commons.logging``, ``org.apache.commons.ognl``, ``org.apache.directory.ldap.client.api``, ``org.apache.ibatis.jdbc``, ``org.apache.log4j``, ``org.apache.logging.log4j``, ``org.apache.shiro.codec``, ``org.apache.shiro.jndi``, ``org.codehaus.groovy.control``, ``org.dom4j``, ``org.hibernate``, ``org.jboss.logging``, ``org.jdbi.v3.core``, ``org.jooq``, ``org.mvel2``, ``org.scijava.log``, ``org.slf4j``, ``org.xml.sax``, ``org.xmlpull.v1``, ``play.mvc``, ``ratpack.core.form``, ``ratpack.core.handling``, ``ratpack.core.http``, ``ratpack.exec``, ``ratpack.form``, ``ratpack.func``, ``ratpack.handling``, ``ratpack.http``, ``ratpack.util``, ``retrofit2``",65,395,932,,,,14,18,,3
22-
Totals,,217,6410,1474,117,6,10,107,33,1,84
22+
Totals,,217,6413,1474,117,6,10,107,33,1,84
2323

0 commit comments

Comments
 (0)