Skip to content

Commit 46d955c

Browse files
authored
Merge pull request #2415 from aeisenberg/aeisenberg/update-readme-1
Update README with detailed information
2 parents 215ff9c + bed2a47 commit 46d955c

File tree

2 files changed

+41
-3
lines changed

2 files changed

+41
-3
lines changed

README.md

+40-2
Original file line numberDiff line numberDiff line change
@@ -16,10 +16,48 @@ We recommend using default setup to configure CodeQL analysis for your repositor
1616

1717
You can also configure advanced setup for a repository to find security vulnerabilities in your code using a highly customizable code scanning configuration. For more information, see "[Configuring advanced setup for code scanning](https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/configuring-advanced-setup-for-code-scanning)" and "[Customizing your advanced setup for code scanning](https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/customizing-your-advanced-setup-for-code-scanning)."
1818

19-
### Permissions
19+
### Actions
20+
21+
This repository contains several actions that enable you to analyze code in your repository using CodeQL and upload the analysis to GitHub Code Scanning. Actions in this repository also allow you to upload to GitHub analyses generated by any SARIF-producing SAST tool.
22+
23+
Actions for CodeQL analyses:
24+
25+
- `init`: Sets up CodeQL for analysis. For information about input parameters, see the [init action definition](https://github.com/github/codeql-action/blob/main/init/action.yml).
26+
- `analyze`: Finalizes the CodeQL database, runs the analysis, and uploads the results to Code Scanning. For information about input parameters, see the [analyze action definition](https://github.com/github/codeql-action/blob/main/analyze/action.yml).
27+
28+
Actions for uploading analyses generated by third-party tools:
29+
30+
- `upload-sarif`: Uploads a SARIF file to Code Scanning. If you are using the `analyze` action, there is no reason to use this action as well. For information about input parameters, see the [upload-sarif action definition](https://github.com/github/codeql-action/blob/main/upload-sarif/action.yml).
31+
32+
Actions with special purposes and unlikely to be used directly:
33+
34+
- `autobuild`: Attempts to automatically build the code. Only used for analyzing languages that require a build. Use the `build-mode: autobuild` input in the `init` action instead. For information about input parameters, see the [autobuild action definition](https://github.com/github/codeql-action/blob/main/autobuild/action.yml).
35+
- `resolve-environment`: [Experimental] Attempts to infer a build environment suitable for automatic builds. For information about input parameters, see the [resolve-environment action definition](https://github.com/github/codeql-action/blob/main/resolve-environment/action.yml).
36+
- `start-proxy`: [Experimental] Start the HTTP proxy server. Internal use only and will change without notice. For information about input parameters, see the [start-proxy action definition](https://github.com/github/codeql-action/blob/main/start-proxy/action.yml).
37+
38+
### Workflow Permissions
2039

2140
All advanced setup code scanning workflows must have the `security-events: write` permission. Workflows in private repositories must additionally have the `contents: read` permission. For more information, see "[Assigning permissions to jobs](https://docs.github.com/en/actions/using-jobs/assigning-permissions-to-jobs)."
2241

42+
### Build Modes
43+
44+
The CodeQL Action supports different build modes for analyzing the source code. The available build modes are:
45+
46+
- `none`: The database will be created without building the source code. Available for all interpreted languages and some compiled languages.
47+
- `autobuild`: The database will be created by attempting to automatically build the source code. Available for all compiled languages.
48+
- `manual`: The database will be created by building the source code using a manually specified build command. To use this build mode, specify manual build steps in your workflow between the `init` and `analyze` steps. Available for all compiled languages.
49+
50+
#### Which build mode should I use?
51+
52+
Interpreted languages must use `none` for the build mode.
53+
54+
For compiled languages:
55+
56+
- `manual` build mode will typically produce the most precise results, but it is more difficult to set up and will cause the analysis to take slightly more time to run.
57+
- `autobuild` build mode is simpler to set up, but will only work for projects with generic build steps that can be guessed by the heuristics of the autobuild scripts. If `autobuild` fails, then you must switch to `manual` or `none`. If `autobuild` succeeds, then the results and run time will be the same as `manual` mode.
58+
- `none` build mode is also simpler to set up and is slightly faster to run, but there is a possibility that some alerts will be missed. This may happen if your repository does any code generation during compilation or if there are any dependencies downloaded from registries that the workflow does not have access to. `none` is not yet supported by C/C++, Swift, Go, or Kotlin.
59+
60+
2361
## Supported versions of the CodeQL Action
2462

2563
The following versions of the CodeQL Action are currently supported:
@@ -45,7 +83,7 @@ We typically release new minor versions of the CodeQL Action and Bundle when a n
4583
| `v2.22.1` | `2.14.6` | Enterprise Server 3.11 | Supports CodeQL Action v3, but did not ship with CodeQL Action v3. For more information, see "[Code scanning: deprecation of CodeQL Action v2](https://github.blog/changelog/2024-01-12-code-scanning-deprecation-of-codeql-action-v2/#users-of-github-enterprise-server-311)." |
4684
| `v2.20.3` | `2.13.5` | Enterprise Server 3.10 | Does not support CodeQL Action v3. |
4785

48-
CodeQL Action v2 will stop receiving updates when GHES 3.11 is deprecated.
86+
CodeQL Action v2 will stop receiving updates when GHES 3.11 is deprecated.
4987

5088
See the full list of GHES release and deprecation dates at [GitHub Enterprise Server releases](https://docs.github.com/en/enterprise-server/admin/all-releases#releases-of-github-enterprise-server).
5189

autobuild/action.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
name: 'CodeQL: Autobuild'
2-
description: 'Attempt to automatically build code'
2+
description: 'Attempt to automatically build the code. Only used for analyzing languages that require a build. Use the `build-mode: autobuild` input in the `init` action instead.'
33
author: 'GitHub'
44
inputs:
55
token:

0 commit comments

Comments
 (0)