Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Sync with upstream. CodeQL changes. #3

Merged
merged 83 commits into from
Oct 7, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
83 commits
Select commit Hold shift + click to select a range
231dd3f
Bump jest-circus from 29.4.1 to 29.5.0 (#318)
dependabot[bot] Apr 1, 2023
0371ac0
Bump @types/node from 18.11.18 to 18.15.11 (#319)
dependabot[bot] Apr 1, 2023
67d60d5
Readme: update checkout to v3 (#303)
SpencerIsGiddy Apr 1, 2023
bf3b51b
Bump typescript from 4.9.5 to 5.0.3 (#320)
dependabot[bot] Apr 1, 2023
a48ee3f
Bump glob from 8.1.0 to 9.3.2 (#321)
dependabot[bot] Apr 1, 2023
5a8bbe8
Try and fix weird build error
ncipollo Apr 1, 2023
eb05307
Fix stupid mocking error
ncipollo Apr 1, 2023
ef679c1
Bump @types/jest from 29.5.0 to 29.5.1 (#326)
dependabot[bot] May 23, 2023
e9a4ba6
Bump glob from 9.3.2 to 10.2.2 (#330)
dependabot[bot] May 23, 2023
c13ca79
Bump ts-jest from 29.0.5 to 29.1.0 (#329)
dependabot[bot] May 23, 2023
3aa9307
Bump typescript from 5.0.3 to 5.0.4 (#327)
dependabot[bot] Jun 27, 2023
3ff6c7e
Bump @types/jest from 29.5.1 to 29.5.2 (#337)
dependabot[bot] Jun 27, 2023
2b38523
Bump glob from 10.2.2 to 10.2.6 (#339)
dependabot[bot] Jun 27, 2023
8c78ca2
Bump @types/node from 18.15.11 to 20.3.2 (#340)
dependabot[bot] Jun 27, 2023
cb77c9e
Revert "Bump @types/node from 18.15.11 to 20.3.2 (#340)"
ncipollo Jun 27, 2023
c07e9f4
Bump ts-jest from 29.1.0 to 29.1.1 (#345)
dependabot[bot] Jul 1, 2023
893ce36
Bump glob from 10.2.6 to 10.3.1 (#342)
dependabot[bot] Jul 1, 2023
9347837
Bump typescript from 5.0.4 to 5.1.6 (#343)
dependabot[bot] Jul 1, 2023
384ae1f
Bump @types/node from 18.15.11 to 20.3.3 (#341)
dependabot[bot] Jul 1, 2023
7288236
build dep updates
ncipollo Jul 1, 2023
37c87f6
Fixes #349 Copy description of makeLatest legacy from github docs
ncipollo Jul 10, 2023
9cfd083
Remove explicit typescript src setting
ncipollo Aug 24, 2023
2d19fb4
Remove lib
ncipollo Aug 24, 2023
6c75be8
Fixes #357 Use a read stream for artifacts.
ncipollo Aug 24, 2023
b36d940
Bump semver from 6.3.0 to 6.3.1 (#350)
dependabot[bot] Aug 26, 2023
69d25a3
Bump actions/checkout from 3 to 4 (#364)
dependabot[bot] Sep 11, 2023
e2ce571
Bump glob from 10.3.1 to 10.3.4 (#361)
dependabot[bot] Sep 11, 2023
eb7dfdf
Bump jest-circus from 29.5.0 to 29.6.4 (#359)
dependabot[bot] Sep 11, 2023
2600a44
Bump typescript from 5.1.6 to 5.2.2 (#362)
dependabot[bot] Sep 11, 2023
b4b70f8
Bump @types/node from 20.3.3 to 20.6.0 (#366)
dependabot[bot] Sep 11, 2023
ddbfce0
Bump jest and @types/jest (#367)
dependabot[bot] Sep 11, 2023
7ce102b
Build (dev) with dependency updates
ncipollo Sep 11, 2023
6db48ce
Bump @babel/traverse from 7.17.3 to 7.23.2 (#378)
dependabot[bot] Oct 17, 2023
476ee61
Bump jest and @types/jest (#377)
dependabot[bot] Oct 17, 2023
e386e41
Bump jest-circus from 29.6.4 to 29.7.0 (#376)
dependabot[bot] Oct 17, 2023
d968c2d
Bump @types/node from 20.6.0 to 20.8.6 (#379)
dependabot[bot] Oct 17, 2023
c18db47
Bump @actions/core from 1.10.0 to 1.10.1 (#375)
dependabot[bot] Oct 17, 2023
25918b0
Build main with 10/2023 dependecy updates
ncipollo Oct 17, 2023
9324133
Update typescript config
ncipollo Oct 17, 2023
5a5f227
Bump glob
ncipollo Oct 17, 2023
26cdd97
Use node 20
ncipollo Oct 17, 2023
a7c3669
Revert "Bump glob"
ncipollo Oct 17, 2023
7b2b452
update build workflow
ncipollo Oct 17, 2023
53f1c32
try to bump glob again
ncipollo Oct 17, 2023
8231257
Try and force jest-cli/yargs resolution
ncipollo Oct 17, 2023
454de29
Bump @types/jest from 29.5.5 to 29.5.7 (#386)
dependabot[bot] Nov 15, 2023
a454b01
Bump actions/setup-node from 3 to 4 (#381)
dependabot[bot] Nov 15, 2023
712dbe3
Bump @types/node from 20.8.6 to 20.9.0 (#390)
dependabot[bot] Nov 16, 2023
3453d72
Bump typescript from 5.2.2 to 5.3.2 (#396)
dependabot[bot] Dec 11, 2023
b878ec7
Bump @types/node from 20.9.0 to 20.10.1 (#395)
dependabot[bot] Dec 11, 2023
37813b7
Bump @types/jest from 29.5.7 to 29.5.11 (#399)
dependabot[bot] Dec 11, 2023
4f53bc4
Add discussionCategory caveat to readme
ncipollo Dec 11, 2023
c4a7702
Add more info about announcements category
ncipollo Dec 11, 2023
0300282
Bump @actions/github from 5.1.1 to 6.0.0 (#385)
dependabot[bot] Dec 11, 2023
02a91b5
Fix build errors from github api update
ncipollo Dec 11, 2023
39c57fe
Bump typescript from 5.3.2 to 5.3.3 (#403)
dependabot[bot] Jan 2, 2024
a8aa04e
Bump @types/node from 20.10.1 to 20.10.6 (#402)
dependabot[bot] Jan 2, 2024
66b1844
Upgrade to Node 20 (#411)
aovens-quantifi Feb 5, 2024
c03240c
apply debug build
ncipollo Feb 5, 2024
1e3e9c6
Fix production build error
ncipollo Feb 5, 2024
7588f62
Bump undici from 5.28.2 to 5.28.3 (#423)
dependabot[bot] Mar 2, 2024
a36404d
Bump @types/jest from 29.5.11 to 29.5.12 (#427)
dependabot[bot] Mar 7, 2024
578e414
Bump @types/node from 20.10.6 to 20.11.24 (#426)
dependabot[bot] Mar 7, 2024
4074199
Bump ts-jest from 29.1.1 to 29.1.2 (#409)
dependabot[bot] Mar 7, 2024
f4b7f82
Create main build with most recent dependencies.
ncipollo Mar 7, 2024
4f8867f
Update body documentation in readme
ncipollo Mar 7, 2024
1da2ee6
Bump undici from 5.28.3 to 5.28.4 (#439)
dependabot[bot] Apr 16, 2024
b6d6ead
Bump typescript from 5.3.3 to 5.4.3 (#438)
dependabot[bot] Apr 16, 2024
4b91e3a
Bump @types/node from 20.11.24 to 20.12.2 (#437)
dependabot[bot] Apr 16, 2024
1cbdc80
Bump glob from 10.3.10 to 10.3.12 (#436)
dependabot[bot] Apr 18, 2024
00fc285
Bump braces from 3.0.2 to 3.0.3 (#449)
dependabot[bot] Jun 16, 2024
765cc97
Bump glob from 10.3.12 to 11.0.0 (#457)
dependabot[bot] Aug 1, 2024
e9a9292
Bump typescript from 5.4.3 to 5.5.4 (#459)
dependabot[bot] Aug 1, 2024
bb3709b
Bump ts-jest from 29.1.2 to 29.2.4 (#460)
dependabot[bot] Aug 1, 2024
a8bcd95
Bump @types/node from 20.12.2 to 22.0.2 (#458)
dependabot[bot] Aug 1, 2024
95283a9
Revert "chore: fix sonar issues"
aszeszo Oct 7, 2024
330b624
Revert "chore: fix sonar issues"
aszeszo Oct 7, 2024
3252d30
Merge remote-tracking branch 'upstream/main' into sync-with-upstream
aszeszo Oct 7, 2024
5e327d2
Bump 3rd party GitHub Action versions
aszeszo Oct 7, 2024
989d038
chore: fix sonar issues
aszeszo Oct 7, 2024
ecad830
Use actions/upload-artifact@v4 in sonar-scan.yml
aszeszo Oct 7, 2024
fc9c44e
Switch to the stock CodeQL Advanced workflow
aszeszo Oct 7, 2024
e71c289
Ignore dist directory in CodeQL scan
aszeszo Oct 7, 2024
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Binary file added .DS_Store
Binary file not shown.
7 changes: 0 additions & 7 deletions .github/codeql/codeql-config.yml

This file was deleted.

8 changes: 6 additions & 2 deletions .github/workflows/build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,11 +11,15 @@ jobs:
check_pr:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: actions/checkout@v4

- uses: actions/setup-node@v4
with:
node-version: 20

- name: "yarn install"
run: yarn install

- name: "yarn build"
run: yarn build

Expand Down
99 changes: 81 additions & 18 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
@@ -1,32 +1,95 @@

name: CodeQl
# For most projects, this workflow file will not need changing; you simply need
# to commit it to your repository.
#
# You may wish to alter this file to override the set of languages analyzed,
# or to provide custom queries or build logic.
#
# ******** NOTE ********
# We have attempted to detect the languages in your repository. Please check
# the `language` matrix defined below to confirm you have the correct set of
# supported CodeQL languages.
#
name: "CodeQL Advanced"

on:
pull_request:
push:
branches: [ "main" ]
pull_request:
branches: [ "main" ]
schedule:
- cron: '31 7 * * 4'

jobs:
scan:
runs-on: ubuntu-latest
analyze:
name: Analyze (${{ matrix.language }})
# Runner size impacts CodeQL analysis time. To learn more, please see:
# - https://gh.io/recommended-hardware-resources-for-running-codeql
# - https://gh.io/supported-runners-and-hardware-resources
# - https://gh.io/using-larger-runners (GitHub.com only)
# Consider using larger runners or machines with greater resources for possible analysis time improvements.
runs-on: ${{ (matrix.language == 'swift' && 'macos-latest') || 'ubuntu-latest' }}
permissions:
# required for all workflows
security-events: write

# required to fetch internal or private CodeQL packs
packages: read

# only required for workflows in private repositories
actions: read
contents: read

strategy:
fail-fast: false
matrix:
include:
- language: javascript-typescript
build-mode: none
# CodeQL supports the following values keywords for 'language': 'c-cpp', 'csharp', 'go', 'java-kotlin', 'javascript-typescript', 'python', 'ruby', 'swift'
# Use `c-cpp` to analyze code written in C, C++ or both
# Use 'java-kotlin' to analyze code written in Java, Kotlin or both
# Use 'javascript-typescript' to analyze code written in JavaScript, TypeScript or both
# To learn more about changing the languages that are analyzed or customizing the build mode for your analysis,
# see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/customizing-your-advanced-setup-for-code-scanning.
# If you are analyzing a compiled language, you can modify the 'build-mode' for that language to customize how
# your codebase is analyzed, see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages
steps:
- name: Checkout repository
uses: actions/checkout@v2

- name: Initialize CodeQL
uses: github/codeql-action/init@v2
with:
debug: true
languages: javascript
config-file: ./.github/codeql/codeql-config.yml

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v2

- name: Checkout repository
uses: actions/checkout@v4

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@v3
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}
config: |
paths-ignore:
- dist/**
# If you wish to specify custom queries, you can do so here or in a config file.
# By default, queries listed here will override any specified in a config file.
# Prefix the list here with "+" to use these queries and those in the config file.

# For more details on CodeQL's query packs, refer to: https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/configuring-code-scanning#using-queries-in-ql-packs
# queries: security-extended,security-and-quality

# If the analyze step fails for one of the languages you are analyzing with
# "We were unable to automatically build your code", modify the matrix above
# to set the build mode to "manual" for that language. Then modify this step
# to build your code.
# ℹ️ Command-line programs to run using the OS shell.
# 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun
- if: matrix.build-mode == 'manual'
shell: bash
run: |
echo 'If you are using a "manual" build mode for one or more of the' \
'languages you are analyzing, replace this with the commands to build' \
'your code, for example:'
echo ' make bootstrap'
echo ' make release'
exit 1

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v3
with:
category: "/language:${{matrix.language}}"
7 changes: 2 additions & 5 deletions .github/workflows/sonar-scan.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,14 +13,11 @@ jobs:

steps:
- name: Checkout repository
uses: actions/checkout@v2
uses: actions/checkout@v4

# https://github.com/SonarSource/sonarqube-scan-action
- name: SonarQube Scan
uses: SonarSource/sonarqube-scan-action@master
with:
args: >
-Dsonar.exclusions=lib/**,dist/**
env:
GITHUB_TOKEN: ${{ github.token }}
SONAR_TOKEN: ${{ secrets.sonar_token }}
Expand All @@ -34,7 +31,7 @@ jobs:
SONAR_TOKEN: ${{ secrets.sonar_token }}

- name: Upload SonarQube Scan Report
uses: actions/upload-artifact@master
uses: actions/upload-artifact@v4
with:
name: sonar-scan-log
path: .scannerwork/report-task.txt
Expand Down
6 changes: 5 additions & 1 deletion .github/workflows/test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,11 @@ jobs:
check_pr:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: actions/checkout@v4

- uses: actions/setup-node@v4
with:
node-version: 20

- name: "yarn install"
run: yarn install
Expand Down
5 changes: 4 additions & 1 deletion .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -95,4 +95,7 @@ fabric.properties
# End of https://www.gitignore.io/api/webstorm

# Coverage
coverage
coverage

# Ignore lib, it contains intermediates
/lib
Loading
Loading