mirror of
https://github.com/HDFGroup/hdf5.git
synced 2026-09-25 04:09:44 +03:00
Bumps the github-actions group with 11 updates: | Package | From | To | | --- | --- | --- | | [lukka/get-cmake](https://github.com/lukka/get-cmake) | `4.4.1` | `4.4.2` | | [actions/setup-java](https://github.com/actions/setup-java) | `5.6.0` | `6.0.0` | | [fortran-lang/setup-fortran](https://github.com/fortran-lang/setup-fortran) | `1.9.2` | `1.10.0` | | [EndBug/add-and-commit](https://github.com/endbug/add-and-commit) | `10.0.0` | `11.1.1` | | [dorny/paths-filter](https://github.com/dorny/paths-filter) | `4.0.2` | `4.0.3` | | [github/codeql-action/init](https://github.com/github/codeql-action) | `4.37.3` | `4.37.9` | | [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.37.3` | `4.37.9` | | [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | `4.37.3` | `4.37.9` | | [vmactions/freebsd-vm](https://github.com/vmactions/freebsd-vm) | `1.5.2` | `1.5.5` | | [vmactions/openbsd-vm](https://github.com/vmactions/openbsd-vm) | `1.4.5` | `1.4.7` | | [softprops/action-gh-release](https://github.com/softprops/action-gh-release) | `3.0.2` | `3.0.3` | Updates `lukka/get-cmake` from 4.4.1 to 4.4.2 - [Release notes](https://github.com/lukka/get-cmake/releases) - [Changelog](https://github.com/lukka/get-cmake/blob/main/RELEASE_PROCESS.md) - [Commits](https://github.com/lukka/get-cmake/compare/4a7d025fc60f00db0c7b44ebf783d19b52444830...fffaaafeea488556c2c12dad60690008bc1caacb) Updates `actions/setup-java` from 5.6.0 to 6.0.0 - [Release notes](https://github.com/actions/setup-java/releases) - [Commits](https://github.com/actions/setup-java/compare/03ad4de0992f5dab5e18fcb136590ce7c4a0ac95...dd06d9cba3e5552c54d9f8ea23572deb30010f7c) Updates `fortran-lang/setup-fortran` from 1.9.2 to 1.10.0 - [Release notes](https://github.com/fortran-lang/setup-fortran/releases) - [Commits](https://github.com/fortran-lang/setup-fortran/compare/195bac823dc6e05bb7c706311ad4540ffc34d5b9...be037f0a45b1160f139d4ccd0b96f9e9bfd6a682) Updates `EndBug/add-and-commit` from 10.0.0 to 11.1.1 - [Release notes](https://github.com/endbug/add-and-commit/releases) - [Commits](https://github.com/endbug/add-and-commit/compare/290ea2c423ad77ca9c62ae0f5b224379612c0321...cc9c08ba6c8df3b93a8f2db63e89b98368ae2ae8) Updates `dorny/paths-filter` from 4.0.2 to 4.0.3 - [Release notes](https://github.com/dorny/paths-filter/releases) - [Changelog](https://github.com/dorny/paths-filter/blob/master/CHANGELOG.md) - [Commits](https://github.com/dorny/paths-filter/compare/7b450fff21473bca461d4b92ce414b9d0420d706...ceb8a2b8f2d89434be7ff52d3de7ec3738c5cc9d) Updates `github/codeql-action/init` from 4.37.3 to 4.37.9 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81...cdf488f595d80d6e07e03d4674febd5ab45fa938) Updates `github/codeql-action/analyze` from 4.37.3 to 4.37.9 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81...cdf488f595d80d6e07e03d4674febd5ab45fa938) Updates `github/codeql-action/upload-sarif` from 4.37.3 to 4.37.9 - [Release notes](https://github.com/github/codeql-action/releases) - [Commits](https://github.com/github/codeql-action/compare/v4.37.3...v4.37.9) Updates `vmactions/freebsd-vm` from 1.5.2 to 1.5.5 - [Release notes](https://github.com/vmactions/freebsd-vm/releases) - [Commits](https://github.com/vmactions/freebsd-vm/compare/77ed28d336d03fe19a3f4f7266c1d2c4714dd79d...f0552d3b69211736abd97f02ff3d4674c56b73b1) Updates `vmactions/openbsd-vm` from 1.4.5 to 1.4.7 - [Release notes](https://github.com/vmactions/openbsd-vm/releases) - [Commits](https://github.com/vmactions/openbsd-vm/compare/c941015845c0f0c429676840963dc63b226d4f69...86cdc08415d9d0865267e686561e276c52d62530) Updates `softprops/action-gh-release` from 3.0.2 to 3.0.3 - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](https://github.com/softprops/action-gh-release/compare/3d0d9888cb7fd7b750713d6e236d1fcb99157228...efb35369e0ad2afab669f228072c1b0d510eae64) --- updated-dependencies: - dependency-name: lukka/get-cmake dependency-version: 4.4.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/setup-java dependency-version: 6.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: fortran-lang/setup-fortran dependency-version: 1.10.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: EndBug/add-and-commit dependency-version: 11.1.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: dorny/paths-filter dependency-version: 4.0.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action/init dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action/analyze dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: vmactions/freebsd-vm dependency-version: 1.5.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: vmactions/openbsd-vm dependency-version: 1.4.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: softprops/action-gh-release dependency-version: 3.0.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
263 lines
10 KiB
YAML
263 lines
10 KiB
YAML
name: "CodeQL"
|
|
|
|
on:
|
|
push:
|
|
branches: [ "develop" ]
|
|
pull_request:
|
|
branches: [ "develop" ]
|
|
schedule:
|
|
- cron: "16 7 * * 0"
|
|
workflow_dispatch: # Allow manual triggering
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
check-changes:
|
|
name: Check for code changes
|
|
runs-on: ubuntu-latest
|
|
outputs:
|
|
has_code_changes: ${{ steps.filter.outputs.code }}
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Check for code changes
|
|
uses: dorny/paths-filter@ceb8a2b8f2d89434be7ff52d3de7ec3738c5cc9d # v4.0.3
|
|
id: filter
|
|
with:
|
|
filters: |
|
|
code:
|
|
- '**/*.c'
|
|
- '**/*.h'
|
|
- '**/*.cpp'
|
|
- '**/*.hpp'
|
|
- '**/CMakeLists.txt'
|
|
- '**/*.cmake'
|
|
|
|
analyze:
|
|
name: Analyze
|
|
needs: check-changes
|
|
if: >-
|
|
needs.check-changes.outputs.has_code_changes == 'true' ||
|
|
github.event_name == 'schedule' ||
|
|
github.event_name == 'workflow_dispatch'
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
actions: read
|
|
contents: read
|
|
security-events: write
|
|
|
|
strategy:
|
|
fail-fast: false
|
|
|
|
steps:
|
|
- name: Install Dependencies (Linux)
|
|
run: |
|
|
sudo apt-get update
|
|
sudo apt-get install -y \
|
|
openmpi-bin openmpi-common mpi-default-dev \
|
|
zlib1g-dev libaec-dev
|
|
|
|
# Set env vars
|
|
echo "CC=mpicc" >> $GITHUB_ENV
|
|
echo "FC=mpif90" >> $GITHUB_ENV
|
|
echo "F77=mpif90" >> $GITHUB_ENV
|
|
|
|
- name: Checkout
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Configure HDF5
|
|
run: |
|
|
mkdir build; cd build
|
|
cmake -G "Unix Makefiles" \
|
|
-DCMAKE_INSTALL_PREFIX=$PWD/hdf5 \
|
|
-DCMAKE_BUILD_TYPE=Debug \
|
|
-DHDF5_ENABLE_PARALLEL:BOOL=ON \
|
|
-DHDF5_ENABLE_SUBFILING_VFD:BOOL=ON \
|
|
-DHDF5_BUILD_TOOLS:BOOL=ON \
|
|
-DBUILD_SHARED_LIBS:BOOL=ON \
|
|
-DBUILD_STATIC_LIBS:BOOL=OFF \
|
|
-DHDF5_BUILD_FORTRAN:BOOL=OFF \
|
|
-DHDF5_BUILD_JAVA:BOOL=OFF \
|
|
-DBUILD_TESTING:BOOL=OFF \
|
|
-DHDF5_BUILD_EXAMPLES:BOOL=OFF \
|
|
-DHDF5_ENABLE_ZLIB_SUPPORT:BOOL=ON \
|
|
-DZLIB_INCLUDE_DIR=/usr/include \
|
|
-DZLIB_LIBRARY=/usr/lib/x86_64-linux-gnu/libz.so \
|
|
..
|
|
|
|
- name: Initialize CodeQL
|
|
uses: github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9
|
|
with:
|
|
languages: c-cpp
|
|
build-mode: manual
|
|
queries: +security-and-quality
|
|
|
|
# Excluded rules justification:
|
|
#
|
|
# ── Global exclusions (legitimate across the entire codebase) ──
|
|
#
|
|
# Security false positives:
|
|
# - cpp/toctou-race-condition: HDF5 file operations inherently involve
|
|
# check-then-act patterns that cannot be avoided in a file I/O library.
|
|
# - cpp/type-confusion: HDF5 object header messages use a void* dispatch
|
|
# pattern where H5O_shared_t is embedded as the first member of message
|
|
# structs (C "base class" idiom). Runtime type guards prevent invalid casts.
|
|
# H5TSpool thread arg is always passed as the correct type.
|
|
# - cpp/non-constant-format, cpp/uncontrolled-format-string,
|
|
# cpp/tainted-format-string: All flagged sites are intentional
|
|
# format-string-as-template patterns:
|
|
# h5tools_str.c uses configurable output formats (e.g., OPT(info->fmt_float, "%g")),
|
|
# h5repart.c and sio_engine.c use family file naming templates with %d,
|
|
# H5FDmulti.c uses API-configured member name templates with %s.
|
|
# These are bounded by snprintf, guarded by H5_WARN_FORMAT_NONLITERAL_OFF,
|
|
# and the format strings originate from application code, not untrusted input.
|
|
#
|
|
# Code style rules (non-security, no severity rating):
|
|
# These are structural patterns inherent to HDF5's C codebase and
|
|
# do not represent security vulnerabilities.
|
|
# - cpp/short-global-name: HDF5 uses short prefixed names (H5F_, H5D_, etc.)
|
|
# as an intentional namespace convention throughout the public API.
|
|
# - cpp/long-switch: Large switch statements are the standard C pattern for
|
|
# dispatching on HDF5 type enums, VOL callbacks, and tool options.
|
|
# - cpp/guarded-free: HDF5 consistently uses NULL-guarded free patterns
|
|
# as a defensive coding convention.
|
|
# - cpp/commented-out-code: Legacy code preserved intentionally for
|
|
# reference during ongoing development.
|
|
# - cpp/use-of-goto: HDF5 uses goto for centralized cleanup (HGOTO_ERROR /
|
|
# HGOTO_DONE macros), a well-established C resource management pattern.
|
|
#
|
|
# ── Tools-only exclusions (enforced for core library via filter-sarif) ──
|
|
#
|
|
# The following rules are excluded only for CLI tools and benchmarks
|
|
# via path-scoped filter-sarif patterns (see filter-sarif step below),
|
|
# but remain ENFORCED for the core library (src/, hl/src/):
|
|
#
|
|
# - cpp/path-injection: CLI tools (h5dump, h5repack, h5import, h5jam,
|
|
# h5ls, h5perf) accept file paths from command-line arguments by design.
|
|
# Kept enforced for src/ to surface env-var path usage in VFDs
|
|
# (e.g., H5FDsubfiling, H5FDioc) for review.
|
|
# - cpp/uncontrolled-allocation-size: CLI tools and benchmarks intentionally
|
|
# accept allocation sizes from command-line arguments (block size, dataset
|
|
# dimensions). Kept enforced for src/ to catch library allocation issues.
|
|
# - cpp/world-writable-file-creation: CLI tools create files using fopen()
|
|
# which defaults to 0666 & ~umask. Kept enforced for src/ to review
|
|
# library file creation (VFD logging, cache logging).
|
|
#
|
|
config: |
|
|
query-filters:
|
|
- exclude:
|
|
id: cpp/toctou-race-condition
|
|
- exclude:
|
|
id: cpp/type-confusion
|
|
- exclude:
|
|
id: cpp/non-constant-format
|
|
- exclude:
|
|
id: cpp/uncontrolled-format-string
|
|
- exclude:
|
|
id: cpp/tainted-format-string
|
|
- exclude:
|
|
id: cpp/short-global-name
|
|
- exclude:
|
|
id: cpp/long-switch
|
|
- exclude:
|
|
id: cpp/guarded-free
|
|
- exclude:
|
|
id: cpp/commented-out-code
|
|
- exclude:
|
|
id: cpp/use-of-goto
|
|
|
|
- name: Build
|
|
run: |
|
|
cd build
|
|
cmake --build . --config Debug
|
|
shell: bash
|
|
|
|
- name: Perform CodeQL Analysis
|
|
uses: github/codeql-action/analyze@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9
|
|
with:
|
|
category: "/language:c-cpp"
|
|
output: sarif-results
|
|
upload: failure-only
|
|
|
|
- name: filter-sarif
|
|
uses: advanced-security/filter-sarif@2da736ff05ef065cb2894ac6892e47b5eac2c3c0 # v1.1
|
|
with:
|
|
# Path-scoped exclusions:
|
|
# - Test directories are excluded entirely (no security value in test harnesses).
|
|
# - Tools-only rules: cpp/path-injection, cpp/uncontrolled-allocation-size,
|
|
# and cpp/world-writable-file-creation are excluded for CLI tools and
|
|
# benchmarks but remain enforced for the core library (src/, hl/src/).
|
|
patterns: |
|
|
-**/test/**
|
|
-**/testpar/**
|
|
-**/tools/test/**
|
|
-tools/**:cpp/path-injection
|
|
-tools/**:cpp/uncontrolled-allocation-size
|
|
-tools/**:cpp/world-writable-file-creation
|
|
-hl/tools/**:cpp/path-injection
|
|
-hl/tools/**:cpp/uncontrolled-allocation-size
|
|
-hl/tools/**:cpp/world-writable-file-creation
|
|
input: sarif-results/cpp.sarif
|
|
output: sarif-results/cpp.sarif
|
|
|
|
- name: Upload SARIF
|
|
uses: github/codeql-action/upload-sarif@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9
|
|
with:
|
|
sarif_file: sarif-results/cpp.sarif
|
|
|
|
# Gate job: always runs even when 'analyze' is skipped (e.g., text-only PRs).
|
|
# Use "CodeQL / codeql-complete" as the required status check instead of "CodeQL / Analyze".
|
|
# When analysis is skipped, uploads an empty SARIF so the "Require code scanning
|
|
# results" branch protection rule is satisfied.
|
|
codeql-complete:
|
|
name: codeql-complete
|
|
if: always()
|
|
needs: [check-changes, analyze]
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
security-events: write
|
|
steps:
|
|
- name: Check analyze result
|
|
run: |
|
|
check_result="${{ needs.check-changes.result }}"
|
|
analyze_result="${{ needs.analyze.result }}"
|
|
|
|
if [ "$check_result" != "success" ]; then
|
|
echo "check-changes job failed with result: $check_result"
|
|
exit 1
|
|
fi
|
|
|
|
if [ "$analyze_result" = "success" ] || [ "$analyze_result" = "skipped" ]; then
|
|
echo "CodeQL analysis passed or was skipped (text-only change)."
|
|
else
|
|
echo "CodeQL analysis failed with result: $analyze_result"
|
|
exit 1
|
|
fi
|
|
|
|
- name: Create empty SARIF file
|
|
if: needs.analyze.result == 'skipped' && github.event_name == 'pull_request'
|
|
run: |
|
|
cat <<'EOF' > "${{ github.workspace }}/empty.sarif"
|
|
{
|
|
"version": "2.1.0",
|
|
"$schema": "https://json.schemastore.org/sarif-2.1.0.json",
|
|
"runs": [{
|
|
"tool": { "driver": { "name": "CodeQL", "rules": [] } },
|
|
"results": []
|
|
}]
|
|
}
|
|
EOF
|
|
|
|
- name: Upload empty SARIF for skipped analysis
|
|
if: needs.analyze.result == 'skipped' && github.event_name == 'pull_request'
|
|
uses: github/codeql-action/upload-sarif@a0c73122a6231d3a72b4b04036548af1cd2487c9
|
|
with:
|
|
sarif_file: ${{ github.workspace }}/empty.sarif
|
|
category: "/language:c-cpp"
|