Skip to content

Merge branch 'main' of github.com:GeekMasher/security-codeql #13

Merge branch 'main' of github.com:GeekMasher/security-codeql

Merge branch 'main' of github.com:GeekMasher/security-codeql #13

name: Publish CodeQL Packs
on:
push:
branches: [ main ]
workflow_dispatch:
jobs:
queries:
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
strategy:
fail-fast: false
matrix:
language: ["python"]
steps:
- uses: actions/checkout@v3
with:
submodules: true
- name: Initialize CodeQL
run: |
VERSION="$(find "${{ runner.tool_cache }}/CodeQL/" -maxdepth 1 -mindepth 1 -type d -print \
| sort \
| tail -n 1 \
| tr -d '\n')"
echo "$VERSION/x64/codeql" >> $GITHUB_PATH
- name: "Check and publish codeql-LANG-queries (src) pack"
env:
GITHUB_TOKEN: ${{ github.token }}
GH_TOKEN: ${{ github.token }}
run: |
PUBLISHED_VERSION=$(gh api /user/packages/container/codeql-python/versions --jq '.[0].metadata.container.tags[0]')
CURRENT_VERSION=$(grep version ${{ matrix.language }}/qlpack.yml | awk '{print $2}')
echo "Published verion: $PUBLISHED_VERSION"
echo "Local verion: $CURRENT_VERSION"
if [ "$PUBLISHED_VERSION" != "$CURRENT_VERSION" ]; then
# create a pack out of the community submodule
codeql pack create --output=$HOME/.codeql/packages codeql-community/${{ matrix.language }}/lib
codeql pack install "${{ matrix.language }}"
codeql pack publish "${{ matrix.language }}"
fi