From cf4ab41df2eeb5131a64ec2faadf4832dbfb7635 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Alvaro=20Mu=C3=B1oz?= Date: Fri, 16 Feb 2024 12:32:48 +0100 Subject: [PATCH] feat(action): rename qlpacks to use githubsecuritylab prefix --- .github/action/dist/index.js | 2 +- .github/action/src/codeql.ts | 2 +- ql/lib/qlpack.yml | 2 +- .../codeql-suites/actions-code-scanning.qls | 19 +++++++++++++++++++ ql/src/qlpack.yml | 2 +- 5 files changed, 23 insertions(+), 4 deletions(-) diff --git a/.github/action/dist/index.js b/.github/action/dist/index.js index e13da63ecda..23c03588162 100644 --- a/.github/action/dist/index.js +++ b/.github/action/dist/index.js @@ -28606,7 +28606,7 @@ async function newCodeQL() { return { language: "yaml", path: await findCodeQL(), - pack: "GitHubSecurityLab/actions-queries", + pack: "githubsecuritylab/actions-queries", suite: "codeql-suites/actions-code-scanning.qls", source_root: core.getInput("source-root"), output: core.getInput("sarif"), diff --git a/.github/action/src/codeql.ts b/.github/action/src/codeql.ts index eeeef401a52..3826737a082 100644 --- a/.github/action/src/codeql.ts +++ b/.github/action/src/codeql.ts @@ -25,7 +25,7 @@ export async function newCodeQL(): Promise { return { language: "yaml", path: await findCodeQL(), - pack: "GitHubSecurityLab/actions-queries", + pack: "githubsecuritylab/actions-queries", suite: "codeql-suites/actions-code-scanning.qls", source_root: core.getInput("source-root"), output: core.getInput("sarif"), diff --git a/ql/lib/qlpack.yml b/ql/lib/qlpack.yml index dc4daebaac8..1ccfae0b278 100644 --- a/ql/lib/qlpack.yml +++ b/ql/lib/qlpack.yml @@ -1,7 +1,7 @@ --- library: true warnOnImplicitThis: true -name: GitHubSecurityLab/actions-all +name: githubsecuritylab/actions-all version: 0.0.1-dev dependencies: codeql/controlflow: ^0.1.7 diff --git a/ql/src/codeql-suites/actions-code-scanning.qls b/ql/src/codeql-suites/actions-code-scanning.qls index e69de29bb2d..7d6c94e0c8c 100644 --- a/ql/src/codeql-suites/actions-code-scanning.qls +++ b/ql/src/codeql-suites/actions-code-scanning.qls @@ -0,0 +1,19 @@ +- description: Standard Code Scanning queries for Actions +- queries: . + +- include: + kind: + - problem + - path-problem + tags contain: + - security + - maintainability + +- include: + kind: + - diagnostic + +- exclude: + tags contain: + - experimental + - testing diff --git a/ql/src/qlpack.yml b/ql/src/qlpack.yml index 919a244b390..fb5d29fb957 100644 --- a/ql/src/qlpack.yml +++ b/ql/src/qlpack.yml @@ -1,6 +1,6 @@ --- library: false -name: GitHubSecurityLab/actions-queries +name: githubsecuritylab/actions-queries version: 0.0.1 groups: - actions