-
Notifications
You must be signed in to change notification settings - Fork 70
97 lines (85 loc) · 3.19 KB
/
sdl-compliance-pipeline.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
name: CodeQL Analysis
on:
push:
branches: ["main", "releases/**"]
paths-ignore:
- "*.md"
- "**/docs"
pull_request:
branches: ["main", "releases/**"]
paths-ignore:
- "*.md"
- "**/docs"
jobs:
sdl_compliance:
name: Running SDL Compliance Policy checks (CodeQL)
runs-on: windows-latest
permissions:
actions: read
contents: read
security-events: write
strategy:
matrix:
include:
- language: "cpp"
build-mode: manual # Or autobuild
build-config: Release
build-platform: x64
env:
BuildConfiguration: Release
SolutionPath: 'LogMonitor\LogMonitor.sln'
CodeQLResultsDir: "../codeql-results"
BOOST_ROOT: "C:\\local\\boost_1_85_0"
BOOST_INCLUDE: "$env:BOOST_ROOT\\include"
BOOST_LIB: "$env:BOOST_ROOT\\lib"
steps:
- name: Checkout code
uses: actions/checkout@v4
with:
fetch-depth: 2
- name: Add msbuild to PATH
uses: microsoft/setup-msbuild@v2
with:
msbuild-architecture: ${{ matrix.build-platform }}
- name: Check solution path
run: |
if (-not (Test-Path -Path "${{ env.SolutionPath }}" -ErrorAction Continue)) {
Throw "Invalid solution path: ${{ env.SolutionPath }}"
}
Write-Host "Current dir: $PWD"
Write-Host "Solution path: ${{ env.SolutionPath }}"
Get-ChildItem "${{ env.SolutionPath }}" -ErrorAction Continue
# Check if local directory exists; if not, create it
- name: Ensure Boost Directory Exists
shell: pwsh
run: |
if (-not (Test-Path -Path "C:\local")) {
New-Item -ItemType Directory -Path "C:\local"
Write-Host "Created directory: C:\local"
}
if (-not (Test-Path -Path "${{ env.BOOST_ROOT }}")) {
New-Item -ItemType Directory -Path "${{ env.BOOST_ROOT }}"
Write-Host "Created directory: ${{ env.BOOST_ROOT }}"
}
# Download and Install Boost Library
- name: Install Boost Library (Prebuilt for Visual Studio)
shell: pwsh
run: |
Invoke-WebRequest -Uri https://boostorg.jfrog.io/artifactory/main/release/1.85.0/binaries/boost_1_85_0-msvc-14.3-64.exe -OutFile boost_installer.exe
Start-Process .\boost_installer.exe -ArgumentList "/S /D=${{ env.BOOST_ROOT }}" -NoNewWindow -Wait
Remove-Item boost_installer.exe -Force # Clean up the installer
- name: Initialize CodeQL
uses: github/codeql-action/init@v3
with:
languages: ${{ matrix.language }}
queries: security-and-quality
build-mode: ${{ matrix.build-mode }}
- name: Build LogMonitor
run: |
msbuild.exe "${{ env.SolutionPath }}" /t:clean
msbuild.exe "${{ env.SolutionPath }}" /p:platform="${{ matrix.build-platform }}" /p:configuration="${{ env.BuildConfiguration }}" /p:IncludePath="${{ env.BOOST_INCLUDE }}" /p:LibraryPath="${{ env.BOOST_LIB }}"
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v3
with:
output: ${{ env.CodeQLResultsDir }}
upload: "always"