Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
Show all changes
76 commits
Select commit Hold shift + click to select a range
d57cc91
Remove Zstandard availability diagnostic
henrymercer Jul 20, 2026
3f208c9
Remove bundle download diagnostic
henrymercer Jul 20, 2026
14e8bf9
Remove Git version diagnostic
henrymercer Jul 20, 2026
1040e2a
Format CodeQL initialization
henrymercer Jul 20, 2026
3c20a74
Remove unused bundle download fields
henrymercer Jul 20, 2026
7248c38
Update changelog and version after v4.37.3
github-actions[bot] Jul 22, 2026
15e2f31
Rebuild
github-actions[bot] Jul 22, 2026
e8e914f
Bump js-yaml and brace-expansion
mbg Jul 21, 2026
0c76f63
Merge pull request #4032 from github/mergeback/v4.37.3-to-main-e4fba868
mbg Jul 22, 2026
909828c
Base custom request options on defaults, and add basic tests for `mak…
mbg Jul 22, 2026
84ae30d
Only allow traffic via the proxy in `global-proxy` test
mbg Jul 22, 2026
a2bfb64
Set other proxy env vars
mbg Jul 22, 2026
f342ca9
Preserve bundle compression coverage
henrymercer Jul 21, 2026
90ea144
Strengthen download status report tests
henrymercer Jul 21, 2026
009715d
Add `github-codeql-tools` property
mbg Jul 22, 2026
1f57eb0
Add FF for `tools` repository property
mbg Jul 22, 2026
f58d696
Move `loadRepositoryProperties` to `properties.ts`
mbg Jul 22, 2026
3479f3f
Load repository properties in `setup-codeql` action
mbg Jul 22, 2026
49f2e37
Add and use `getToolsInput`
mbg Jul 22, 2026
32ed58d
Check log messages in tests
mbg Jul 22, 2026
60339ed
Exclude Copilot review from required checks
henrymercer Jul 22, 2026
be24c11
Rename to `ComputedInput`
mbg Jul 22, 2026
f9442c4
Include computed `tools` value in `computed_inputs`
mbg Jul 22, 2026
1b0d271
Merge pull request #4036 from github/henrymercer/remove-legacy-diagno…
mbg Jul 22, 2026
96bc4c7
Bump the npm-minor group across 1 directory with 5 updates
dependabot[bot] Jul 22, 2026
f6ed33c
Rebuild
github-actions[bot] Jul 22, 2026
8a0be82
Bump the actions-minor group across 1 directory with 3 updates
dependabot[bot] Jul 22, 2026
05f56be
Bump actions/setup-python from 6.3.0 to 7.0.0 in /.github/workflows
dependabot[bot] Jul 22, 2026
6cce0e7
Bump actions/setup-go from 6.5.0 to 7.0.0 in /.github/workflows
dependabot[bot] Jul 22, 2026
5c0fb49
Bump actions/setup-dotnet from 5.4.0 to 6.0.0 in /.github/workflows
dependabot[bot] Jul 22, 2026
11b8f75
Rebuild
github-actions[bot] Jul 22, 2026
d146d63
Rebuild
github-actions[bot] Jul 22, 2026
1eb720c
Rebuild
github-actions[bot] Jul 22, 2026
4671ecc
Rebuild
github-actions[bot] Jul 22, 2026
372f165
Merge remote-tracking branch 'origin/main' into mbg/repo-props/tools
mbg Jul 23, 2026
087006f
Merge pull request #4038 from github/dependabot/npm_and_yarn/npm-mino…
mbg Jul 24, 2026
5ba5550
Merge pull request #4033 from github/mbg/update-deps/21jul26
mbg Jul 24, 2026
ecbe7c2
Merge pull request #4039 from github/dependabot/github_actions/dot-gi…
mbg Jul 24, 2026
2e64471
Merge pull request #4035 from github/mbg/improve-global-proxy-tests
mbg Jul 24, 2026
b060f9d
Merge remote-tracking branch 'origin/main' into mbg/repo-props/tools
mbg Jul 24, 2026
519b270
Merge pull request #4041 from github/dependabot/github_actions/dot-gi…
mbg Jul 24, 2026
f170b3a
Remove `name` field from `ComputedInput`
mbg Jul 24, 2026
1564bfa
Add changelog entry
mbg Jul 24, 2026
6de0a56
Merge pull request #4040 from github/dependabot/github_actions/dot-gi…
mbg Jul 24, 2026
d4bfde7
Merge pull request #4042 from github/dependabot/github_actions/dot-gi…
mbg Jul 24, 2026
2d14f71
Add `NO_CHANGES_STR` constant
mbg Jul 24, 2026
85d1570
Add `prepare-changelog.ts` with tests
mbg Jul 24, 2026
b69467c
Update workflows to use `prepare-changelog.ts`
mbg Jul 24, 2026
5901394
Remove `prepare_changelog.py`
mbg Jul 24, 2026
57eb441
Add constant for unreleased placeholder
mbg Jul 24, 2026
093dce6
Add `extractChangelogSnippet` test for the case where there is no fir…
mbg Jul 24, 2026
916098a
Add `parseChangelog` and `renderChangelog`
mbg Jul 24, 2026
adba086
Update `processChangelogForBackports` to use `parseChangelog`
mbg Jul 24, 2026
c5d6212
Update `extractChangelogSnippet` to use `parseChangelog`
mbg Jul 24, 2026
66a6f42
Add `bundle-changelog.ts` with tests
mbg Jul 24, 2026
027ac05
Use `bundle-changelog.ts` and remove Python version
mbg Jul 24, 2026
d714617
Add `rollback-changelog.ts` with tests
mbg Jul 24, 2026
961b583
Use `rollback-changelog.ts` and remove Python version
mbg Jul 24, 2026
ab44eb9
Remove `python` from CodeQL workflow
mbg Jul 24, 2026
cbad145
Remove Python-specific steps from workflows that no longer need them
mbg Jul 24, 2026
0953dc0
Add `getErrorMessage` to `pr-checks`-local `util.ts` to avoid pulling…
mbg Jul 24, 2026
4c0a1f0
Merge pull request #4037 from github/mbg/repo-props/tools
mbg Jul 24, 2026
f00f809
Fix checking keys rather than values
mbg Jul 24, 2026
74b15aa
Install JS deps if needed in `post-release-mergeback` workflow
mbg Jul 24, 2026
3013ac0
Promote `AllowToolcacheInput` feature
mbg Jul 24, 2026
3434fbb
Merge pull request #4044 from github/mbg/ff/promote-toolcache
mbg Jul 24, 2026
2a8731c
Move `config-file` computation after determining the `analysisKinds`
mbg Jul 27, 2026
8289a49
Ignore repository property for unsupported analysis kinds
mbg Jul 27, 2026
98c05a1
Fix argument validation in `rollback-changelog.ts`
mbg Jul 28, 2026
2d4c474
Log `!analysisKindSupported` case
mbg Jul 28, 2026
7e8d897
Merge pull request #4046 from github/mbg/repo-prop/code-quality
mbg Jul 28, 2026
18420e3
Merge pull request #4043 from github/mbg/ts/changelog
mbg Jul 28, 2026
da0c190
Update default bundle to codeql-bundle-v2.26.2
github-actions[bot] Jul 29, 2026
c62d824
Add changelog note
github-actions[bot] Jul 29, 2026
9130ce0
Merge pull request #4051 from github/update-bundle/codeql-bundle-v2.26.2
oscarsj Jul 29, 2026
e40d079
Update changelog for v4.37.4
github-actions[bot] Jul 29, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
Add bundle-changelog.ts with tests
  • Loading branch information
mbg committed Jul 24, 2026
commit 66a6f42f0a3913dd88868e788503602498b26925
142 changes: 142 additions & 0 deletions pr-checks/bundle-changelog.test.ts
Original file line number Diff line number Diff line change
@@ -0,0 +1,142 @@
/**
* Tests for `bundle-changelog.ts`.
*/

import * as assert from "node:assert/strict";
import * as fs from "node:fs";
import * as os from "node:os";
import * as path from "node:path";
import { afterEach, beforeEach, describe, it } from "node:test";

import {
CLI_VERSION_ENV_VAR,
getCLIVersion,
getPRNumber,
getPRUrl,
PR_URL_ENV_VAR,
updateChangelog,
} from "./bundle-changelog";
import {
EMPTY_CHANGELOG,
NO_CHANGES_STR,
UNRELEASED_PLACEHOLDER,
} from "./changelog";

let testDir: string;

beforeEach(() => {
// Set up a temporary directory for testing
testDir = fs.mkdtempSync(path.join(os.tmpdir(), "bundle-changelog-test-"));
});

afterEach(() => {
/** Clean up temporary directories. */
fs.rmSync(testDir, { recursive: true, force: true });
});

describe("getCLIVersion", async () => {
await it("throws if the environment variable is not set", async () => {
delete process.env[CLI_VERSION_ENV_VAR];
assert.throws(() => getCLIVersion());
});

await it("throws if the environment variable is empty", async () => {
process.env[CLI_VERSION_ENV_VAR] = " ";
assert.throws(() => getCLIVersion());
});

await it("returns value of the environment variable if set", async () => {
const testValue = "1.2.3";
process.env[CLI_VERSION_ENV_VAR] = testValue;
assert.deepEqual(getCLIVersion(), testValue);
});
});

const testPrUrl = "https://github.com/github/codeql-action/pulls/42";

describe("getPRUrl", async () => {
await it("throws if the environment variable is not set", async () => {
delete process.env[PR_URL_ENV_VAR];
assert.throws(() => getPRUrl());
});

await it("throws if the environment variable is empty", async () => {
process.env[PR_URL_ENV_VAR] = " ";
assert.throws(() => getPRUrl());
});

await it("returns value of the environment variable if set", async () => {
process.env[PR_URL_ENV_VAR] = testPrUrl;
assert.deepEqual(getPRUrl(), testPrUrl);
});
});

describe("getPRNumber", async () => {
await it("throws if the last part of the input is not a number", async () => {
assert.throws(() => getPRNumber(`${testPrUrl}/foo`));
});

await it("throws if the last part of the input is not a positive number", async () => {
assert.throws(() => getPRNumber(`${testPrUrl}/-100`));
});

await it("returns the PR number from an URL", async () => {
assert.equal(getPRNumber(testPrUrl), 42);
});
});

const testChangelog = `${EMPTY_CHANGELOG.trimEnd()}

## 4.23.7

- Other change

## 4.23.6

${NO_CHANGES_STR}`;

const expectedChangelog = `# CodeQL Action Changelog

## ${UNRELEASED_PLACEHOLDER}

- Update default CodeQL bundle version to

## 4.23.7

- Other change

## 4.23.6

${NO_CHANGES_STR}`;

describe("updateChangelog", async () => {
await it("removes `NO_CHANGES_STR` if present in [UNRELEASED] section", async () => {
const result = updateChangelog(EMPTY_CHANGELOG, "");
assert.ok(!result.includes(NO_CHANGES_STR.trim()));
});

await it("doesn't remove `NO_CHANGES_STR` if present in versioned section", async () => {
const result = updateChangelog(
EMPTY_CHANGELOG.replace(UNRELEASED_PLACEHOLDER, "1.2.3"),
"",
);
assert.ok(result.includes(NO_CHANGES_STR.trim()));
});

await it("throws if there are no sections", async () => {
assert.throws(() => {
updateChangelog(
"# CodeQL Action Changelog",
"- Update default CodeQL bundle version to",
);
});
});

await it("adds note at the end of the first section", async () => {
const result = updateChangelog(
testChangelog,
"- Update default CodeQL bundle version to",
);
assert.deepEqual(result, expectedChangelog);
});
});
128 changes: 128 additions & 0 deletions pr-checks/bundle-changelog.ts
Original file line number Diff line number Diff line change
@@ -0,0 +1,128 @@
#!/usr/bin/env npx tsx

/**
* Updates the changelog with a change note for an updated CodeQL CLI bundle.
*/

import * as fs from "node:fs";

import { getErrorMessage } from "../src/util";

import {
parseChangelog,
renderChangelog,
UNRELEASED_PLACEHOLDER,
} from "./changelog";
import { CHANGELOG_FILE, CLI_BUNDLE_RELEASE_URL_PREFIX } from "./config";

export const CLI_VERSION_ENV_VAR = "CLI_VERSION";
export const PR_URL_ENV_VAR = "PR_URL";

/** Gets the CLI version from the environment. */
export function getCLIVersion() {
const cliVersion = process.env[CLI_VERSION_ENV_VAR];

if (cliVersion === undefined || cliVersion.trim() === "") {
throw new Error(`No CLI version was set in '${CLI_VERSION_ENV_VAR}'.`);
}

return cliVersion;
}

/** Gets the PR URL from the environment. */
export function getPRUrl() {
const prUrl = process.env[PR_URL_ENV_VAR];

if (prUrl === undefined || prUrl.trim() === "") {
throw new Error(`No PR URL was set in '${PR_URL_ENV_VAR}'.`);
}

return prUrl;
}

/**
* Gets the PR number from something like a PR URL.
*/
export function getPRNumber(prUrl: string) {
const prUrlParts = prUrl.split("/");
const prNumberStr = prUrlParts[prUrlParts.length - 1];

const prNumber = Number.parseInt(prNumberStr, 10);

if (!Number.isInteger(prNumber) || prNumber <= 0) {
throw new Error(
`Invalid PR URL '${prUrl}': last part is not a positive number`,
);
}

return prNumber;
}

/**
* Updates `changelog` by adding `changelogNote` to the first section.
*
* @param contents The existing changelog contents.
* @param changelogNote The note to add to the first section.
*/
export function updateChangelog(contents: string, changelogNote: string) {
// If the "[UNRELEASED]" section starts with "no user facing changes", remove that line.
contents = contents.replace(
`## ${UNRELEASED_PLACEHOLDER}\n\nNo user facing changes.`,
`## ${UNRELEASED_PLACEHOLDER}\n`,
);

const changelog = parseChangelog(contents);

if (changelog.sections.length === 0) {
throw new Error("The changelog contains no existing sections.");
}

// Add the changelog note to the bottom of the first section.
const firstSection = changelog.sections[0];
const lastLine = firstSection.bodyLines.pop();

if (lastLine !== undefined && lastLine.trim() !== "") {
// We expect the last line to be empty. If it isn't for some reason,
// add it back.
firstSection.bodyLines.push(lastLine);
}

firstSection.bodyLines.push(changelogNote);

// If the last line is empty as expected, then add it back in after the new note.
if (lastLine?.trim() === "") {
firstSection.bodyLines.push(lastLine);
}

return renderChangelog(changelog);
}

function main() {
try {
const cliVersion = getCLIVersion();
const prUrl = getPRUrl();

// The GitHub Release for the new bundle version.
const bundleReleaseUrl = `${CLI_BUNDLE_RELEASE_URL_PREFIX}${cliVersion}`;

// Get the PR number from the PR URL.
const prNumber = getPRNumber(prUrl);
const changelogNote = `- Update default CodeQL bundle version to [${cliVersion}](${bundleReleaseUrl}). [#${prNumber}](${prUrl})`;

let changelog = fs.readFileSync(CHANGELOG_FILE, "utf-8");

changelog = updateChangelog(changelog, changelogNote);

fs.writeFileSync(CHANGELOG_FILE, changelog);

return 0;
} catch (err) {
console.error(`Failed to bundle changelog: ${getErrorMessage(err)}`);
return -1;
}
}

// Only call `main` if this script was run directly.
if (require.main === module) {
process.exit(main());
}
4 changes: 4 additions & 0 deletions pr-checks/config.ts
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,10 @@ export const API_COMPATIBILITY_FILE = path.join(
"api-compatibility.json",
);

/** The prefix of CodeQL CLI bundle release URLs. */
export const CLI_BUNDLE_RELEASE_URL_PREFIX =
"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v";

/** A common interface for operations that support dry runs. */
export interface DryRunOption {
/** A value indicating whether to perform operations with side effects. */
Expand Down