From 0ebdaa421c64b07df0957d180b5ee3dc3e2b862b Mon Sep 17 00:00:00 2001 From: Xi Xu Date: Mon, 30 Mar 2026 22:02:55 +0800 Subject: [PATCH] ci: manage codeql workflow in repo --- .github/workflows/ci.yml | 3 ++ .github/workflows/codeql.yml | 50 +++++++++++++++++++++ .github/workflows/dependabot-auto-merge.yml | 3 ++ .github/workflows/image.yml | 3 ++ tests/github-automation.test.cjs | 24 ++++++++++ 5 files changed, 83 insertions(+) create mode 100644 .github/workflows/codeql.yml diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index ad9aecf..904cde0 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -12,6 +12,9 @@ on: permissions: contents: read +env: + FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true + concurrency: group: ci-${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} cancel-in-progress: true diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml new file mode 100644 index 0000000..7af18ff --- /dev/null +++ b/.github/workflows/codeql.yml @@ -0,0 +1,50 @@ +name: CodeQL + +on: + push: + branches: + - main + pull_request: + branches: + - main + schedule: + - cron: '31 16 * * 0' + workflow_dispatch: + +permissions: + actions: read + contents: read + security-events: write + +env: + FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true + +jobs: + analyze: + name: Analyze (${{ matrix.language }}) + runs-on: ubuntu-latest + timeout-minutes: 30 + strategy: + fail-fast: false + matrix: + include: + - language: actions + build-mode: none + - language: javascript-typescript + build-mode: none + + steps: + - name: Check out repository + uses: actions/checkout@v5 + + - name: Initialize CodeQL + uses: github/codeql-action/init@v4 + with: + languages: ${{ matrix.language }} + build-mode: ${{ matrix.build-mode }} + dependency-caching: true + + - name: Perform CodeQL Analysis + uses: github/codeql-action/analyze@v4 + with: + category: /language:${{ matrix.language }} diff --git a/.github/workflows/dependabot-auto-merge.yml b/.github/workflows/dependabot-auto-merge.yml index d67dc1b..2a5d963 100644 --- a/.github/workflows/dependabot-auto-merge.yml +++ b/.github/workflows/dependabot-auto-merge.yml @@ -18,6 +18,9 @@ permissions: contents: write pull-requests: write +env: + FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true + jobs: auto-merge: if: github.event.pull_request.user.login == 'dependabot[bot]' && !github.event.pull_request.draft diff --git a/.github/workflows/image.yml b/.github/workflows/image.yml index de33534..ef68d86 100644 --- a/.github/workflows/image.yml +++ b/.github/workflows/image.yml @@ -15,6 +15,9 @@ permissions: contents: read packages: write +env: + FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true + concurrency: group: image-${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} cancel-in-progress: true diff --git a/tests/github-automation.test.cjs b/tests/github-automation.test.cjs index 470ef79..4668678 100644 --- a/tests/github-automation.test.cjs +++ b/tests/github-automation.test.cjs @@ -20,6 +20,7 @@ test('repository automation files exist for CI, container publish, and Dependabo '.eslintrc.cjs', '.eslintignore', '.github/workflows/ci.yml', + '.github/workflows/codeql.yml', '.github/workflows/image.yml', '.github/workflows/dependabot-auto-merge.yml', '.github/dependabot.yml', @@ -45,6 +46,29 @@ test('container image publishing waits for CI instead of running on pull request assert.doesNotMatch(workflow, /pull_request:/); }); +test('workflows opt into Node 24 for JavaScript-based GitHub Actions', () => { + const workflows = [ + read('.github/workflows/ci.yml'), + read('.github/workflows/codeql.yml'), + read('.github/workflows/image.yml'), + read('.github/workflows/dependabot-auto-merge.yml'), + ]; + + for (const workflow of workflows) { + assert.match(workflow, /FORCE_JAVASCRIPT_ACTIONS_TO_NODE24:\s*true/); + } +}); + +test('CodeQL workflow uses advanced setup with repository-managed configuration', () => { + const workflow = read('.github/workflows/codeql.yml'); + + assert.match(workflow, /uses:\s*actions\/checkout@v5/); + assert.match(workflow, /uses:\s*github\/codeql-action\/init@v4/); + assert.match(workflow, /uses:\s*github\/codeql-action\/analyze@v4/); + assert.match(workflow, /language:\s*actions/); + assert.match(workflow, /language:\s*javascript-typescript/); +}); + test('dependabot config covers npm, docker, and github-actions updates', () => { const dependabot = read('.github/dependabot.yml');