Skip to content

Commit 79cefe4

Browse files
committed
Docs: update Actions customization doc to cover JSON extensions
1 parent 7aa4afb commit 79cefe4

1 file changed

Lines changed: 56 additions & 20 deletions

File tree

‎docs/codeql/codeql-language-guides/customizing-library-models-for-actions.rst‎

Lines changed: 56 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,29 @@ Customizing library models for GitHub Actions
77

88
GitHub Actions analysis can be customized by adding library models in data extension files.
99

10-
A data extension for GitHub Actions is a YAML file of the form:
10+
A data extension for GitHub Actions can be written using either JSON or YAML. The JSON format takes the following form:
11+
12+
.. code-block:: json
13+
14+
{
15+
"extensions": [
16+
{
17+
"addsTo": {
18+
"pack": "codeql/actions-all",
19+
"extensible": "<name of extensible predicate>"
20+
},
21+
"data": [
22+
["tuple", 1],
23+
["tuple", 2]
24+
// ...
25+
]
26+
}
27+
]
28+
}
29+
30+
Files in the JSON format must use the ``.json`` file extension. Single-line (``//``) and multi-line (``/* ... */``) comments are supported as a non-standard JSON extension.
31+
32+
A YAML file has the following form:
1133

1234
.. code-block:: yaml
1335
@@ -16,8 +38,8 @@ A data extension for GitHub Actions is a YAML file of the form:
1638
pack: codeql/actions-all
1739
extensible: <name of extensible predicate>
1840
data:
19-
- <tuple1>
20-
- <tuple2>
41+
- ["tuple", 1]
42+
- ["tuple", 2]
2143
- ...
2244
2345
The CodeQL library for GitHub Actions exposes the following extensible predicates:
@@ -57,16 +79,23 @@ If there is an Action publisher that you trust, you can include the owner name/o
5779

5880
To allow any Action from the publisher ``octodemo``, such as ``octodemo/3rd-party-action``, follow these steps:
5981

60-
1. Create a data extension file ``/models/trusted-owner.model.yml`` with the following content:
82+
1. Create a data extension file ``/models/trusted-owner.model.json`` with the following content:
6183

62-
.. code-block:: yaml
84+
.. code-block:: json
6385
64-
extensions:
65-
- addsTo:
66-
pack: codeql/actions-all
67-
extensible: trustedActionsOwnerDataModel
68-
data:
69-
- ["octodemo"]
86+
{
87+
"extensions": [
88+
{
89+
"addsTo": {
90+
"pack": "codeql/actions-all",
91+
"extensible": "trustedActionsOwnerDataModel"
92+
},
93+
"data": [
94+
["octodemo"]
95+
]
96+
}
97+
]
98+
}
7099
71100
2. Create a model pack file ``/codeql-pack.yml`` with the following content:
72101

@@ -78,7 +107,7 @@ To allow any Action from the publisher ``octodemo``, such as ``octodemo/3rd-part
78107
extensionTargets:
79108
codeql/actions-all: '*'
80109
dataExtensions:
81-
- models/**/*.yml
110+
- models/**/*.json
82111
83112
3. Ensure that the model pack is included in your CodeQL analysis.
84113

@@ -91,14 +120,21 @@ GitHub's own organizations (``actions``, ``github`` and ``advanced-security``) a
91120

92121
To distrust the first-party ``github`` owner, add a data extension file with the following content:
93122

94-
.. code-block:: yaml
95-
96-
extensions:
97-
- addsTo:
98-
pack: codeql/actions-all
99-
extensible: trustedActionsOwnerDataModel
100-
data:
101-
- ["!github"]
123+
.. code-block:: json
124+
125+
{
126+
"extensions": [
127+
{
128+
"addsTo": {
129+
"pack": "codeql/actions-all",
130+
"extensible": "trustedActionsOwnerDataModel"
131+
},
132+
"data": [
133+
["!github"]
134+
]
135+
}
136+
]
137+
}
102138
103139
With this in place, the query will once again report unpinned tags for Actions published by ``github``.
104140

0 commit comments

Comments
 (0)