Skip to content

Commit 17bc7c4

Browse files
committed
Update CodeQLAdvanced.yml
1 parent dd792bb commit 17bc7c4

1 file changed

Lines changed: 26 additions & 51 deletions

File tree

‎.github/workflows/CodeQLAdvanced.yml‎

Lines changed: 26 additions & 51 deletions
Original file line numberDiff line numberDiff line change
@@ -17,84 +17,59 @@ on:
1717
pull_request:
1818
branches: [ "dev", "main", "dependabot" ]
1919
schedule:
20-
- cron: '16 1 * * 5'
20+
- cron: '16 1 * * 5' # 每周五凌晨1:16运行
2121

2222
jobs:
2323
analyze:
2424
name: Analyze (${{ matrix.language }})
25-
# Runner size impacts CodeQL analysis time. To learn more, please see:
26-
# - https://gh.io/recommended-hardware-resources-for-running-codeql
27-
# - https://gh.io/supported-runners-and-hardware-resources
28-
# - https://gh.io/using-larger-runners (GitHub.com only)
29-
# Consider using larger runners or machines with greater resources for possible analysis time improvements.
3025
runs-on: ${{ (matrix.language == 'swift' && 'macos-latest') || 'ubuntu-latest' }}
3126
permissions:
32-
# required for all workflows
3327
security-events: write
34-
35-
# required to fetch internal or private CodeQL packs
3628
packages: read
37-
38-
# only required for workflows in private repositories
3929
actions: read
4030
contents: read
4131

4232
strategy:
4333
fail-fast: false
4434
matrix:
4535
include:
46-
- language: actions
47-
build-mode: none
48-
- language: java-kotlin
49-
build-mode: none # This mode only analyzes Java. Set this to 'autobuild' or 'manual' to analyze Kotlin too.
50-
# CodeQL supports the following values keywords for 'language': 'actions', 'c-cpp', 'csharp', 'go', 'java-kotlin', 'javascript-typescript', 'python', 'ruby', 'rust', 'swift'
51-
# Use `c-cpp` to analyze code written in C, C++ or both
52-
# Use 'java-kotlin' to analyze code written in Java, Kotlin or both
53-
# Use 'javascript-typescript' to analyze code written in JavaScript, TypeScript or both
54-
# To learn more about changing the languages that are analyzed or customizing the build mode for your analysis,
55-
# see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/customizing-your-advanced-setup-for-code-scanning.
56-
# If you are analyzing a compiled language, you can modify the 'build-mode' for that language to customize how
57-
# your codebase is analyzed, see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages
36+
- language: actions
37+
build-mode: none
38+
- language: java-kotlin
39+
build-mode: autobuild # 改为 autobuild 以更好地处理 Kotlin 和 Java 编译:cite[1]
40+
5841
steps:
5942
- name: Checkout repository
6043
uses: actions/checkout@v4
6144

62-
# Add any setup steps before running the `github/codeql-action/init` action.
63-
# This includes steps like installing compilers or runtimes (`actions/setup-node`
64-
# or others). This is typically only required for manual builds.
65-
# - name: Setup runtime (example)
66-
# uses: actions/setup-example@v1
67-
68-
# Initializes the CodeQL tools for scanning.
6945
- name: Initialize CodeQL
70-
uses: github/codeql-action/init@v3
46+
uses: github/codeql-action/init@v3 # 更新到最新v3版本
7147
with:
7248
languages: ${{ matrix.language }}
7349
build-mode: ${{ matrix.build-mode }}
74-
# If you wish to specify custom queries, you can do so here or in a config file.
75-
# By default, queries listed here will override any specified in a config file.
76-
# Prefix the list here with "+" to use these queries and those in the config file.
50+
# 考虑添加自定义查询包或查询套件(如有需要)
51+
# queries: security-and-quality, security-extended
52+
# 或使用配置文件
53+
# config-file: ./.github/codeql/codeql-config.yml
7754

78-
# For more details on CodeQL's query packs, refer to: https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/configuring-code-scanning#using-queries-in-ql-packs
79-
# queries: security-extended,security-and-quality
55+
# 仅为需要编译的语言添加构建步骤
56+
- name: Setup Java (for Java/Kotlin analysis)
57+
if: matrix.language == 'java-kotlin'
58+
uses: actions/setup-java@v3
59+
with:
60+
distribution: 'temurin'
61+
java-version: '11'
8062

81-
# If the analyze step fails for one of the languages you are analyzing with
82-
# "We were unable to automatically build your code", modify the matrix above
83-
# to set the build mode to "manual" for that language. Then modify this step
84-
# to build your code.
85-
# ℹ️ Command-line programs to run using the OS shell.
86-
# 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun
87-
- if: matrix.build-mode == 'manual'
88-
shell: bash
89-
run: |
90-
echo 'If you are using a "manual" build mode for one or more of the' \
91-
'languages you are analyzing, replace this with the commands to build' \
92-
'your code, for example:'
93-
echo ' make bootstrap'
94-
echo ' make release'
95-
exit 1
63+
- name: Build with Maven (for Java/Kotlin analysis)
64+
if: matrix.language == 'java-kotlin' && matrix.build-mode == 'manual'
65+
run: mvn clean compile -q
9666

9767
- name: Perform CodeQL Analysis
9868
uses: github/codeql-action/analyze@v3
9969
with:
70+
# category 可用于区分不同分析任务的结果
10071
category: "/language:${{matrix.language}}"
72+
# 显示设置输出文件格式和名称(可选,但更清晰)
73+
output: codeql-results-${{ matrix.language }}.sarif
74+
# 如果希望发现安全问题时依然上传结果而非失败,可设置以下选项(可选)
75+
# continue-on-error: true

0 commit comments

Comments
 (0)