Repository navigation
Expand file tree
/
Copy pathaction.yml
More file actions
140 lines (130 loc) · 5.67 KB
/
Copy pathaction.yml
File metadata and controls
140 lines (130 loc) · 5.67 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
# Consumer-facing action, published from this directory to a standalone action repository.
name: AI Scan
description: Run AI Scan on the current repository to detect and report security vulnerabilities.
inputs:
token:
description: GitHub token used for Copilot requests and code scanning access.
required: false
default: ${{ github.token }}
copilot-token:
description: GitHub token used for Copilot requests only. Overrides token.
required: false
default: ''
copilot-integration-id:
description: GitHub Copilot integration ID used for Copilot requests.
required: false
default: ''
tools:
description: >
Path to a locally built AI Scan tools archive, or a release tag on the
action's own repository (defaults to `latest`) to download that asset
from. Any value that resolves to an existing file is used as-is;
everything else is treated as a tag.
required: false
default: latest
source-root:
description: Path of the root source code directory, relative to $GITHUB_WORKSPACE.
required: false
default: .
baseline-ref:
description: Git ref of the baseline to compare against.
required: false
default: ${{ github.ref }}
runs:
using: composite
steps:
- id: resolve
shell: bash
env:
TOOLS: ${{ inputs.tools }}
RELEASE_REPO: ${{ github.action_repository }}
GH_TOKEN: ${{ inputs.token }}
run: |
if [[ -f "${TOOLS}" ]]; then
echo "tools: using local tarball ${TOOLS}"
tarball="${TOOLS}"
else
echo "tools: ${TOOLS} is not a file"
tarball_basename=ai-scan.tar.xz
tarball="${RUNNER_TEMP}/${tarball_basename}"
authenticated_download=false
# Releases of github/ai-scan-action are downloaded anonymously, so no
# token is sent. Any other action repository downloads its releases
# with authentication, using the action's token.
if [[ "${RELEASE_REPO}" != "github/ai-scan-action" ]]; then
authenticated_download=true
fi
if [[ "${authenticated_download}" == "true" ]]; then
echo "tools: downloading the release from ${RELEASE_REPO} with authentication using gh"
if [[ "${TOOLS}" == "latest" ]]; then
GH_HOST=github.com gh release download \
--repo "${RELEASE_REPO}" \
--pattern "${tarball_basename}" \
--output "${tarball}"
else
GH_HOST=github.com gh release download "${TOOLS}" \
--repo "${RELEASE_REPO}" \
--pattern "${tarball_basename}" \
--output "${tarball}"
fi
else
echo "tools: downloading the release from ${RELEASE_REPO} using curl"
if [[ "${TOOLS}" == "latest" ]]; then
url="https://github.com/${RELEASE_REPO}/releases/latest/download/${tarball_basename}"
else
url="https://github.com/${RELEASE_REPO}/releases/download/${TOOLS}/${tarball_basename}"
fi
curl --fail --silent --show-error --location --retry 3 --output "${tarball}" "${url}"
fi
fi
if ! bun_version="$(tar -xJOf "${tarball}" ./ai-scan-bun-version)"; then
echo "::error::AI Scan archive ${tarball} does not contain a readable ai-scan-bun-version stamp"
exit 1
fi
if [[ ! "${bun_version}" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
echo "::error::AI Scan archive ${tarball} contains an invalid Bun version: ${bun_version}"
exit 1
fi
{
echo "tarball=${tarball}"
echo "bun-version=${bun_version}"
} >>"${GITHUB_OUTPUT}"
- name: Set up Node.js for Copilot CLI
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 22
# AI Scan ships as a JavaScript bundle rather than a self-contained
# executable, so the runtime it needs is downloaded here from Bun's own
# upstream instead of being redistributed inside our release asset.
#
# The archive records the Bun version that built the bundle. Resolve that
# version before setup so independently released tools assets remain
# compatible with action versions already in use.
- name: Set up Bun for AI Scan
uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0
with:
bun-version: ${{ steps.resolve.outputs.bun-version }}
- name: Run AI Scan
shell: bash
env:
# The runner exports the repository, ref, SHA, and workspace.
# The action forwards credentials plus its source-root and
# baseline-ref inputs; run.sh maps the Copilot-specific values
# to the environment expected by AI Scan and the Copilot SDK.
GITHUB_TOKEN: ${{ inputs.token }}
ARGUS_COPILOT_TOKEN: ${{ inputs.copilot-token }}
ARGUS_COPILOT_INTEGRATION_ID: ${{ inputs.copilot-integration-id }}
ARGUS_TARBALL: ${{ steps.resolve.outputs.tarball }}
ARGUS_SOURCE_ROOT: ${{ inputs.source-root }}
ARGUS_BASELINE_REF: ${{ inputs.baseline-ref }}
# `GITHUB_ACTION_PATH` and `RUNNER_TEMP` are exported by the
# runner, so they need no forwarding; only `ARGUS_TARBALL` — a
# step output rather than an ambient value — does.
run: bash "${GITHUB_ACTION_PATH}/run.sh" "${RUNNER_TEMP}" "${ARGUS_TARBALL}"
- name: Upload raw AI Scan findings
if: always() && runner.debug == '1'
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: argus-core-raw-output
path: ${{ runner.temp }}/argus-output
if-no-files-found: warn