Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
43 changes: 24 additions & 19 deletions .github/workflows/codeql-analysis.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,16 +15,29 @@ on: [pull_request]

jobs:
analyze:
name: Analyze
name: Analyze (${{ matrix.language }})
# The other workflows pin the runner image to match the VMs. This one
# does not need to: the analysis reads the sources without building
# or running them, so the image cannot influence the findings.
runs-on: ubuntu-latest

# Stated here rather than inherited from the repository default, so
# that tightening that default cannot silently stop the results from
# being uploaded.
permissions:
contents: read
# Required to upload the analysis results.
security-events: write

strategy:
fail-fast: false
matrix:
language: [ 'javascript', 'python' ]
# CodeQL supports [ 'cpp', 'csharp', 'go', 'java', 'javascript', 'python' ]
# CodeQL supports [ 'actions', 'cpp', 'csharp', 'go', 'java',
# 'javascript', 'python', 'ruby', 'rust', 'swift' ]. 'javascript'
# covers TypeScript as well.
# Learn more:
# https://docs.github.com/en/free-pro-team@latest/github/finding-security-vulnerabilities-and-errors-in-your-code/configuring-code-scanning#changing-the-languages-that-are-analyzed
# https://docs.github.com/en/code-security/reference/code-scanning/workflow-configuration-options

steps:
- name: Checkout repository
Expand All @@ -35,26 +48,18 @@ jobs:
uses: github/codeql-action/init@v4
with:
languages: ${{ matrix.language }}
# Both languages are interpreted, so the database is built from the
# sources and nothing has to be compiled first. A compiled language
# added to the matrix would need `autobuild` or `manual` instead.
build-mode: none
# If you wish to specify custom queries, you can do so here or in a config file.
# By default, queries listed here will override any specified in a config file.
# Prefix the list here with "+" to use these queries and those in the config file.
# queries: ./path/to/local/query, your-org/your-repo/queries@main

# Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
# If this step fails, then you should remove it and run the build manually (see below)
- name: Autobuild
uses: github/codeql-action/autobuild@v4

# ℹ️ Command-line programs to run using the OS shell.
# 📚 https://git.io/JvXDl

# ✏️ If the Autobuild fails above, remove it and uncomment the following three lines
# and modify them (or add more) to build your code if your project
# uses a compiled language

#- run: |
# make bootstrap
# make release

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v4
with:
# Names the analysis the results belong to, so the two matrix legs
# are matched separately instead of by job identity alone.
category: "/language:${{ matrix.language }}"
9 changes: 8 additions & 1 deletion .github/workflows/sphinx-books-tests.js.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,14 @@ jobs:
uses: actions/setup-python@v7
with:
python-version: ${{ matrix.python-version }}
# Pinned like the packages it installs; the action applies it as an
# exact `pip==` requirement.
pip-version: '26.2.1'
cache: 'pip'
# Named explicitly: the default pattern matches `requirements.txt`,
# which is not the file the workflow installs, so the key would not
# change when a pinned version does.
cache-dependency-path: 'frontend/requirements_frozen.txt'
- uses: actions/checkout@v7
- name: Enable Corepack
run: corepack enable
Expand Down Expand Up @@ -61,7 +69,6 @@ jobs:
run: pnpm install --frozen-lockfile
- name: Install Python dependencies
run: |
python -m pip install --upgrade pip
pip install -r requirements_frozen.txt
pip install -e python/rst_code_example_pipeline
- name: Run Webpack production
Expand Down
9 changes: 8 additions & 1 deletion .github/workflows/sphinx-content-tests.js.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,14 @@ jobs:
uses: actions/setup-python@v7
with:
python-version: ${{ matrix.python-version }}
# Pinned like the packages it installs; the action applies it as an
# exact `pip==` requirement.
pip-version: '26.2.1'
cache: 'pip'
# Named explicitly: the default pattern matches `requirements.txt`,
# which is not the file the workflow installs, so the key would not
# change when a pinned version does.
cache-dependency-path: 'frontend/requirements_frozen.txt'
- uses: actions/checkout@v7
- name: Enable Corepack
run: corepack enable
Expand Down Expand Up @@ -49,7 +57,6 @@ jobs:
run: pnpm install --frozen-lockfile
- name: Install Python dependencies
run: |
python -m pip install --upgrade pip
pip install -r requirements_frozen.txt
pip install -e python/rst_code_example_pipeline
- name: Run SPHINX engine tests
Expand Down
9 changes: 8 additions & 1 deletion .github/workflows/sphinx-plugin-tests.js.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,6 +28,14 @@ jobs:
uses: actions/setup-python@v7
with:
python-version: ${{ matrix.python-version }}
# Pinned like the packages it installs; the action applies it as an
# exact `pip==` requirement.
pip-version: '26.2.1'
cache: 'pip'
# Named explicitly: the default pattern matches `requirements.txt`,
# which is not the file the workflow installs, so the key would not
# change when a pinned version does.
cache-dependency-path: 'frontend/requirements_frozen.txt'
- name: Install OS Deps
run: |
sudo apt-get update && \
Expand All @@ -42,7 +50,6 @@ jobs:
sudo sysctl -p
- name: Install Python dependencies
run: |
python -m pip install --upgrade pip
pip install -r requirements_frozen.txt
pip install -e python/rst_code_example_pipeline
- name: Test Sphinx Widget Parser Plugin
Expand Down
9 changes: 8 additions & 1 deletion .github/workflows/typescript-tests.js.yml
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,14 @@ jobs:
uses: actions/setup-python@v7
with:
python-version: ${{ matrix.python-version }}
# Pinned like the packages it installs; the action applies it as an
# exact `pip==` requirement.
pip-version: '26.2.1'
cache: 'pip'
# Named explicitly: the default pattern matches `requirements.txt`,
# which is not the file the workflow installs, so the key would not
# change when a pinned version does.
cache-dependency-path: 'frontend/requirements_frozen.txt'
- uses: actions/checkout@v7
- name: Enable Corepack
run: corepack enable
Expand All @@ -54,7 +62,6 @@ jobs:
run: pnpm install --frozen-lockfile
- name: Install Python dependencies
run: |
python -m pip install --upgrade pip
pip install -r requirements_frozen.txt
pip install -e python/rst_code_example_pipeline
- name: Build HTML test pages
Expand Down
Loading