From f066d0df0cf121069b3bdd98f1540469199e592f Mon Sep 17 00:00:00 2001 From: Alexandre Paillier Date: Wed, 22 Nov 2023 14:14:26 +0100 Subject: [PATCH] wip --- .github/workflows/codeql_checks.yml | 32 +++++++++++++++++++++++++++-- 1 file changed, 30 insertions(+), 2 deletions(-) diff --git a/.github/workflows/codeql_checks.yml b/.github/workflows/codeql_checks.yml index 2494182..8eb796e 100644 --- a/.github/workflows/codeql_checks.yml +++ b/.github/workflows/codeql_checks.yml @@ -18,27 +18,55 @@ jobs: name: Analyse strategy: matrix: - sdk: [ "$NANOS_SDK", "$NANOX_SDK", "$NANOSP_SDK" ] + sdk: [ "$NANOSP_SDK" ] #'cpp' covers C and C++ language: [ 'cpp' ] runs-on: ubuntu-latest + env: + CODEQL_JAVA_HOME: /usr/lib/jvm/java-17-openjdk container: - image: ghcr.io/ledgerhq/ledger-app-builder/ledger-app-builder-legacy:latest + image: ghcr.io/ledgerhq/ledger-app-builder/ledger-app-builder-lite:latest steps: - name: Clone uses: actions/checkout@v3 + - name: Install JRE + run: | + apk add openjdk17-jre-headless + - name: Initialize CodeQL uses: github/codeql-action/init@v2 with: languages: ${{ matrix.language }} queries: security-and-quality + #- name: Install glibc compatibility layer + # run: | + # echo $LD_PRELOAD + # apk add gcompat + # env + + - name: Get pre logs + uses: actions/upload-artifact@v3 + with: + name: pre-logs + path: /__w/_temp/ + # CodeQL will create the database during the compilation - name: Build run: | make BOLOS_SDK=${{ matrix.sdk }} + #- name: git status + # run: | + # git status + + - name: Get post logs + uses: actions/upload-artifact@v3 + with: + name: post-logs + path: /__w/_temp/ + - name: Perform CodeQL Analysis uses: github/codeql-action/analyze@v2