Skip to content

Commit 1c3addb

Browse files
committed
Fix nasa#48, Implement Coding Standard CodeQL
1 parent 9761ab5 commit 1c3addb

File tree

3 files changed

+87
-3
lines changed

3 files changed

+87
-3
lines changed
+19
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
name: "CodeQL Coding Standard Configuration File"
2+
3+
disable-default-queries: true
4+
5+
queries:
6+
- name: JPL Rules
7+
uses: ./codeql/cpp/ql/src/JPL_C
8+
- name: MISRA Rule 9-5-1
9+
uses: ./codeql/cpp/ql/src/jsf/4.20 Unions and Bit Fields/AV Rule 153.ql
10+
- name: MISRA Rule 5-18-1
11+
uses: ./codeql/cpp/ql/src/jsf/4.21 Operators/AV Rule 168.ql
12+
- name: MISRA 6-2-2
13+
uses: ./codeql/cpp/ql/src/jsf/4.25 Expressions/AV Rule 202.ql
14+
- name: MISRA Rule 5-14-1
15+
uses: ./codeql/cpp/ql/src/jsf/4.21 Operators/AV Rule 165.ql
16+
- name: MISRA Rule 5-3-2
17+
uses: ./codeql/cpp/ql/src/jsf/4.21 Operators/AV Rule 165.ql
18+
- name: MISRA Rule 7-5-2
19+
uses: ./codeql/cpp/ql/src/jsf/4.22 Pointers and References/AV Rule 173.ql

.github/codeql/codeql-security.yml

+8
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
name: "CodeQL Security Configuration File"
2+
3+
queries:
4+
- name: Security and Quality
5+
uses: security-and-quality
6+
- name: Security Extended
7+
uses: security-extended
8+

.github/workflows/codeql-build.yml

+60-3
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@ name: "CodeQL Analysis"
22

33
on:
44
push:
5+
pull_request:
56
branches:
67
- main
7-
pull_request:
88

99
env:
1010
SIMULATION: native
@@ -13,8 +13,23 @@ env:
1313
BUILDTYPE: release
1414

1515
jobs:
16+
#Checks for duplicate actions. Skips push actions if there is a matching or duplicate pull-request action.
17+
check-for-duplicates:
18+
runs-on: ubuntu-latest
19+
# Map a step output to a job output
20+
outputs:
21+
should_skip: ${{ steps.skip_check.outputs.should_skip }}
22+
steps:
23+
- id: skip_check
24+
uses: fkirc/skip-duplicate-actions@master
25+
with:
26+
concurrent_skipping: 'same_content'
27+
skip_after_successful_duplicate: 'true'
28+
do_not_skip: '["pull_request", "workflow_dispatch", "schedule"]'
1629

17-
CodeQL-Build:
30+
CodeQL-Security-Build:
31+
needs: check-for-duplicates
32+
if: ${{ needs.check-for-duplicates.outputs.should_skip != 'true' }}
1833
runs-on: ubuntu-18.04
1934
timeout-minutes: 15
2035

@@ -38,7 +53,7 @@ jobs:
3853
uses: github/codeql-action/init@v1
3954
with:
4055
languages: c
41-
queries: +security-extended, security-and-quality
56+
config-file: nasa/tblCRCTool/.github/codeql/codeql-security.yml@main
4257

4358
# Setup the build system
4459
- name: Set up for build
@@ -53,3 +68,45 @@ jobs:
5368

5469
- name: Perform CodeQL Analysis
5570
uses: github/codeql-action/analyze@v1
71+
72+
CodeQL-Coding-Standard-Build:
73+
needs: check-for-duplicates
74+
if: ${{ needs.check-for-duplicates.outputs.should_skip != 'true' }}
75+
runs-on: ubuntu-18.04
76+
timeout-minutes: 15
77+
78+
steps:
79+
# Checks out a copy of your repository on the ubuntu-latest machine
80+
- name: Checkout bundle
81+
uses: actions/checkout@v2
82+
with:
83+
repository: nasa/cFS
84+
submodules: true
85+
86+
- name: Checkout submodule
87+
uses: actions/checkout@v2
88+
with:
89+
path: tools/tblCRCTool
90+
91+
- name: Check versions
92+
run: git submodule
93+
94+
- name: Initialize CodeQL
95+
uses: github/codeql-action/init@v1
96+
with:
97+
languages: c
98+
config-file: nasa/tblCRCTool/.github/codeql/codeql-coding-standard.yml@main
99+
100+
# Setup the build system
101+
- name: Set up for build
102+
run: |
103+
cp ./cfe/cmake/Makefile.sample Makefile
104+
cp -r ./cfe/cmake/sample_defs sample_defs
105+
make prep
106+
107+
# Build the code
108+
- name: Build
109+
run: make tools/tblCRCTool/
110+
111+
- name: Perform CodeQL Analysis
112+
uses: github/codeql-action/analyze@v1

0 commit comments

Comments
 (0)