Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
Show all changes
43 commits
Select commit Hold shift + click to select a range
c512861
Extend `UserConfig` type to be aware of Default Setup properties
mbg Jul 3, 2026
cd604f8
Refactor `determineUserConfig` out of `initConfig`
mbg Jul 3, 2026
a52a966
Add `mergeUserConfigs` with tests
mbg Jul 3, 2026
132634d
Add FF for configuration merging
mbg Jul 6, 2026
53a488c
Add JSDoc for `loadUserConfig`
mbg Jul 6, 2026
6860cc1
Move `validateConfig` FF query
mbg Jul 6, 2026
0188f39
Add unit tests for existing behaviour of `determineUserConfig`
mbg Jul 6, 2026
d1db924
Allow `env` input for relevant functions in `actions-util.ts`
mbg Jul 6, 2026
18d20b7
Allow setting environment variables
mbg Jul 6, 2026
3157774
Give `determineUserConfig` access to the environment
mbg Jul 6, 2026
42c0c6a
Allow merging Default Setup `config` with config file
mbg Jul 6, 2026
3707b44
Document that `inputs` might be mutated
mbg Jul 6, 2026
d149f93
Return `mergedConfig` instead of loading it again
mbg Jul 6, 2026
764f470
Test `inputs.configFile` mutation in tests
mbg Jul 6, 2026
9a06fa6
Set the required `workspacePath` input
mbg Jul 6, 2026
44d6b3b
Initialise `env` in `actions-util` when not provided
mbg Jul 6, 2026
4509fb3
Fix JSDoc for `determineUserConfig`
mbg Jul 6, 2026
8476401
Make lazy FF check less ambiguous
mbg Jul 6, 2026
8be707b
Merge remote-tracking branch 'origin/main' into mbg/config/merge
mbg Jul 6, 2026
7ccd988
Merge branch 'main' into mbg/config/merge
mbg Jul 8, 2026
06898d7
Rename `mergeUserConfigs`
mbg Jul 8, 2026
d2472aa
Merge remote-tracking branch 'origin/main' into mbg/config/merge
mbg Jul 9, 2026
6829d6c
Remove obsolete JSDoc parameter for `loadUserConfig`
mbg Jul 9, 2026
6973946
Check file on disk and mutated inputs
mbg Jul 9, 2026
dc2d916
Add `checkSchema` function
mbg Jul 9, 2026
1f91ec8
Add an `array` `Validator`
mbg Jul 9, 2026
98dbd66
Add an `object` `Validator`
mbg Jul 9, 2026
9573f05
Improve type inference for `object` and `validateSchema`
mbg Jul 9, 2026
847e7af
Log warning for unrecognised keys in Default Setup config
mbg Jul 9, 2026
7c961fa
Add diagnostic for unrecognised keys
mbg Jul 9, 2026
cee0056
Allow nested checking
mbg Jul 9, 2026
e4752e7
Remove keys from unrecognised set as soon as found
mbg Jul 10, 2026
8d8f054
Add convenience functions to produce `CheckSchemaResult` values
mbg Jul 10, 2026
512bf6f
Track invalid keys, and use more standard JSON path notation
mbg Jul 10, 2026
0b10dee
Propagate `CheckSchemaOptions` to allow `failFast` to work as intended
mbg Jul 10, 2026
e26215c
fixup! Track invalid keys, and use more standard JSON path notation
mbg Jul 10, 2026
26cbf9f
Don't include nested keys that are unknown
mbg Jul 10, 2026
f630f8f
Report invalid keys separately
mbg Jul 10, 2026
66c15f4
Merge remote-tracking branch 'origin/main' into mbg/config/merge
mbg Jul 13, 2026
2773684
Update test for changed test API
mbg Jul 13, 2026
f181d70
Update `determineUserConfig` tests to use new framework
mbg Jul 13, 2026
7577328
Return function result from `passes` alongside assertion result
mbg Jul 13, 2026
3d2713f
Merge remote-tracking branch 'origin/main' into mbg/config/merge
mbg Jul 14, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
Allow env input for relevant functions in actions-util.ts
  • Loading branch information
mbg committed Jul 6, 2026
commit d1db924e0b79fd8a27931863729a47459c1b2640
64 changes: 33 additions & 31 deletions lib/entry-points.js

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

89 changes: 58 additions & 31 deletions src/actions-util.ts
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,7 @@ import * as github from "@actions/github";
import * as io from "@actions/io";

import type { Config } from "./config-utils";
import { Env, EnvVar } from "./environment";
import { Logger } from "./logging";
import {
doesDirectoryExist,
Expand Down Expand Up @@ -83,17 +84,23 @@ export const getOptionalInput = function (name: string): string | undefined {
return value.length > 0 ? value : undefined;
};

export function getTemporaryDirectory(): string {
const value = process.env["CODEQL_ACTION_TEMP"];
/**
* Gets the temporary directory used by the CodeQL Action. This will either be the temporary
* directory that has been set in `CODEQL_ACTION_TEMP` by e.g. a previous step, or the
* value of `RUNNER_TEMP` otherwise.
*/
export function getTemporaryDirectory(env?: Env): string {
const value = env?.getOptional(EnvVar.TEMP) || process.env[EnvVar.TEMP];
return value !== undefined && value !== ""
? value
: getRequiredEnvParam(ActionsEnvVars.RUNNER_TEMP);
: env?.getRequired(ActionsEnvVars.RUNNER_TEMP) ||
getRequiredEnvParam(ActionsEnvVars.RUNNER_TEMP);
}
Comment thread
mbg marked this conversation as resolved.
Outdated

const PR_DIFF_RANGE_JSON_FILENAME = "pr-diff-range.json";

export function getDiffRangesJsonFilePath(): string {
return path.join(getTemporaryDirectory(), PR_DIFF_RANGE_JSON_FILENAME);
export function getDiffRangesJsonFilePath(env?: Env): string {
return path.join(getTemporaryDirectory(env), PR_DIFF_RANGE_JSON_FILENAME);
}

export function getActionVersion(): string {
Expand All @@ -105,16 +112,19 @@ export function getActionVersion(): string {
*
* This will be "dynamic" for default setup workflow runs.
*/
export function getWorkflowEventName() {
export function getWorkflowEventName(env?: Env) {
if (env) {
return env.getRequired(ActionsEnvVars.GITHUB_EVENT_NAME);
}
return getRequiredEnvParam(ActionsEnvVars.GITHUB_EVENT_NAME);
}

/**
* Returns whether the current workflow is executing a local copy of the Action, e.g. we're running
* a workflow on the codeql-action repo itself.
*/
export function isRunningLocalAction(): boolean {
const relativeScriptPath = getRelativeScriptPath();
export function isRunningLocalAction(env?: Env): boolean {
const relativeScriptPath = getRelativeScriptPath(env);
return (
relativeScriptPath.startsWith("..") || path.isAbsolute(relativeScriptPath)
);
Expand All @@ -125,15 +135,21 @@ export function isRunningLocalAction(): boolean {
*
* This can be used to get the Action's name or tell if we're running a local Action.
*/
function getRelativeScriptPath(): string {
const runnerTemp = getRequiredEnvParam(ActionsEnvVars.RUNNER_TEMP);
function getRelativeScriptPath(env?: Env): string {
const runnerTemp =
env === undefined
? getRequiredEnvParam(ActionsEnvVars.RUNNER_TEMP)
: env.getRequired(ActionsEnvVars.RUNNER_TEMP);
const actionsDirectory = path.join(path.dirname(runnerTemp), "_actions");
return path.relative(actionsDirectory, __filename);
}

/** Returns the contents of `GITHUB_EVENT_PATH` as a JSON object. */
export function getWorkflowEvent(): any {
const eventJsonFile = getRequiredEnvParam(ActionsEnvVars.GITHUB_EVENT_PATH);
export function getWorkflowEvent(env?: Env): any {
const eventJsonFile =
env === undefined
? getRequiredEnvParam(ActionsEnvVars.GITHUB_EVENT_PATH)
: env.getRequired(ActionsEnvVars.GITHUB_EVENT_PATH);
try {
return JSON.parse(fs.readFileSync(eventJsonFile, "utf-8"));
} catch (e) {
Expand Down Expand Up @@ -202,8 +218,11 @@ export function getUploadValue(input: string | undefined): UploadKind {
/**
* Get the workflow run ID.
*/
export function getWorkflowRunID(): number {
const workflowRunIdString = getRequiredEnvParam(ActionsEnvVars.GITHUB_RUN_ID);
export function getWorkflowRunID(env?: Env): number {
const workflowRunIdString =
env === undefined
? getRequiredEnvParam(ActionsEnvVars.GITHUB_RUN_ID)
: env.getRequired(ActionsEnvVars.GITHUB_RUN_ID);
const workflowRunID = parseInt(workflowRunIdString, 10);
if (Number.isNaN(workflowRunID)) {
throw new Error(
Expand All @@ -221,10 +240,11 @@ export function getWorkflowRunID(): number {
/**
* Get the workflow run attempt number.
*/
export function getWorkflowRunAttempt(): number {
const workflowRunAttemptString = getRequiredEnvParam(
ActionsEnvVars.GITHUB_RUN_ATTEMPT,
);
export function getWorkflowRunAttempt(env?: Env): number {
const workflowRunAttemptString =
env === undefined
? getRequiredEnvParam(ActionsEnvVars.GITHUB_RUN_ATTEMPT)
: env.getRequired(ActionsEnvVars.GITHUB_RUN_ATTEMPT);
const workflowRunAttempt = parseInt(workflowRunAttemptString, 10);
if (Number.isNaN(workflowRunAttempt)) {
throw new Error(
Expand Down Expand Up @@ -295,13 +315,13 @@ export function isSelfHostedRunner() {
}

/** Determines whether the workflow trigger is `dynamic`. */
export function isDynamicWorkflow(): boolean {
return getWorkflowEventName() === "dynamic";
export function isDynamicWorkflow(env?: Env): boolean {
return getWorkflowEventName(env) === "dynamic";
}

/** Determines whether we are running in default setup. */
export function isDefaultSetup(): boolean {
return isDynamicWorkflow();
export function isDefaultSetup(env?: Env): boolean {
return isDynamicWorkflow(env);
}

export function prettyPrintInvocation(cmd: string, args: string[]): string {
Expand Down Expand Up @@ -399,9 +419,10 @@ const persistedInputsKey = "persisted_inputs";
* This would be simplified if actions/runner#3514 is addressed.
* https://github.com/actions/runner/issues/3514
*/
export const persistInputs = function () {
const inputEnvironmentVariables = Object.entries(process.env).filter(
([name]) => name.startsWith("INPUT_"),
export const persistInputs = function (env?: Env) {
const entries = env?.entries() || Object.entries(process.env);
const inputEnvironmentVariables = entries.filter(([name]) =>
name.startsWith("INPUT_"),
);
core.saveState(persistedInputsKey, JSON.stringify(inputEnvironmentVariables));
};
Comment thread
mbg marked this conversation as resolved.
Outdated
Expand Down Expand Up @@ -429,7 +450,9 @@ export interface PullRequestBranches {
* @returns the base and head branches of the pull request, or undefined if
* we are not analyzing a pull request.
*/
export function getPullRequestBranches(): PullRequestBranches | undefined {
export function getPullRequestBranches(
env?: Env,
): PullRequestBranches | undefined {
const pullRequest = github.context.payload.pull_request;
if (pullRequest) {
return {
Expand All @@ -443,8 +466,11 @@ export function getPullRequestBranches(): PullRequestBranches | undefined {

// PR analysis under Default Setup does not have the pull_request context,
// but it should set CODE_SCANNING_REF and CODE_SCANNING_BASE_BRANCH.
const codeScanningRef = process.env.CODE_SCANNING_REF;
const codeScanningBaseBranch = process.env.CODE_SCANNING_BASE_BRANCH;
const codeScanningRef =
env?.getOptional("CODE_SCANNING_REF") || process.env.CODE_SCANNING_REF;
const codeScanningBaseBranch =
env?.getOptional("CODE_SCANNING_BASE_BRANCH") ||
process.env.CODE_SCANNING_BASE_BRANCH;
Comment thread
mbg marked this conversation as resolved.
Outdated
if (codeScanningRef && codeScanningBaseBranch) {
return {
base: codeScanningBaseBranch,
Expand All @@ -459,8 +485,8 @@ export function getPullRequestBranches(): PullRequestBranches | undefined {
/**
* Returns whether we are analyzing a pull request.
*/
export function isAnalyzingPullRequest(): boolean {
return getPullRequestBranches() !== undefined;
export function isAnalyzingPullRequest(env?: Env): boolean {
return getPullRequestBranches(env) !== undefined;
}

/**
Expand All @@ -484,13 +510,14 @@ const qualityCategoryMapping: Record<string, string> = {
export function fixCodeQualityCategory(
logger: Logger,
category?: string,
env?: Env,
): string | undefined {
// The `category` should always be set by Default Setup. We perform this check
// to avoid potential issues if Code Quality supports Advanced Setup in the future
// and before this workaround is removed.
if (
category !== undefined &&
isDefaultSetup() &&
isDefaultSetup(env) &&
category.startsWith("/language:")
) {
const language = category.substring("/language:".length);
Expand Down
5 changes: 5 additions & 0 deletions src/environment.ts
Original file line number Diff line number Diff line change
Expand Up @@ -83,6 +83,9 @@ export enum EnvVar {
/** Whether to suppress the warning if the current CLI will soon be unsupported. */
SUPPRESS_DEPRECATED_SOON_WARNING = "CODEQL_ACTION_SUPPRESS_DEPRECATED_SOON_WARNING",

/** Used to dictate or persist the temporary directory used by the CodeQL Action. */
TEMP = "CODEQL_ACTION_TEMP",

/** Whether to disable uploading SARIF results or status reports to the GitHub API */
TEST_MODE = "CODEQL_ACTION_TEST_MODE",

Expand Down Expand Up @@ -167,4 +170,6 @@ export interface Env {
getRequired(name: string): string;
/** Gets the value for `name`, or `undefined` if it isn't set or empty. */
getOptional(name: string): string | undefined;
/** Gets the entries of the underlying `ProcessEnv`. */
entries(): Array<[string, string | undefined]>;
}
1 change: 1 addition & 0 deletions src/util.ts
Original file line number Diff line number Diff line change
Expand Up @@ -571,6 +571,7 @@ export function getEnv(env: NodeJS.ProcessEnv = process.env): Env {
return {
getRequired: (name) => getRequiredEnvVar(env, name),
getOptional: (name) => getOptionalEnvVarFrom(env, name),
entries: () => Object.entries(env),
};
}

Expand Down