You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 79cefe4
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: docs/codeql/codeql-language-guides/customizing-library-models-for-actions.rst
+56-20Lines changed: 56 additions & 20 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,7 +7,29 @@ Customizing library models for GitHub Actions
7
7
8
8
GitHub Actions analysis can be customized by adding library models in data extension files.
9
9
10
-
A data extension for GitHub Actions is a YAML file of the form:
10
+
A data extension for GitHub Actions can be written using either JSON or YAML. The JSON format takes the following form:
11
+
12
+
.. code-block:: json
13
+
14
+
{
15
+
"extensions": [
16
+
{
17
+
"addsTo": {
18
+
"pack": "codeql/actions-all",
19
+
"extensible": "<name of extensible predicate>"
20
+
},
21
+
"data": [
22
+
["tuple", 1],
23
+
["tuple", 2]
24
+
// ...
25
+
]
26
+
}
27
+
]
28
+
}
29
+
30
+
Files in the JSON format must use the ``.json`` file extension. Single-line (``//``) and multi-line (``/* ... */``) comments are supported as a non-standard JSON extension.
31
+
32
+
A YAML file has the following form:
11
33
12
34
.. code-block:: yaml
13
35
@@ -16,8 +38,8 @@ A data extension for GitHub Actions is a YAML file of the form:
16
38
pack: codeql/actions-all
17
39
extensible: <name of extensible predicate>
18
40
data:
19
-
- <tuple1>
20
-
- <tuple2>
41
+
- ["tuple", 1]
42
+
- ["tuple", 2]
21
43
- ...
22
44
23
45
The CodeQL library for GitHub Actions exposes the following extensible predicates:
@@ -57,16 +79,23 @@ If there is an Action publisher that you trust, you can include the owner name/o
57
79
58
80
To allow any Action from the publisher ``octodemo``, such as ``octodemo/3rd-party-action``, follow these steps:
59
81
60
-
1. Create a data extension file ``/models/trusted-owner.model.yml`` with the following content:
82
+
1. Create a data extension file ``/models/trusted-owner.model.json`` with the following content:
61
83
62
-
.. code-block:: yaml
84
+
.. code-block:: json
63
85
64
-
extensions:
65
-
- addsTo:
66
-
pack: codeql/actions-all
67
-
extensible: trustedActionsOwnerDataModel
68
-
data:
69
-
- ["octodemo"]
86
+
{
87
+
"extensions": [
88
+
{
89
+
"addsTo": {
90
+
"pack": "codeql/actions-all",
91
+
"extensible": "trustedActionsOwnerDataModel"
92
+
},
93
+
"data": [
94
+
["octodemo"]
95
+
]
96
+
}
97
+
]
98
+
}
70
99
71
100
2. Create a model pack file ``/codeql-pack.yml`` with the following content:
72
101
@@ -78,7 +107,7 @@ To allow any Action from the publisher ``octodemo``, such as ``octodemo/3rd-part
78
107
extensionTargets:
79
108
codeql/actions-all: '*'
80
109
dataExtensions:
81
-
- models/**/*.yml
110
+
- models/**/*.json
82
111
83
112
3. Ensure that the model pack is included in your CodeQL analysis.
84
113
@@ -91,14 +120,21 @@ GitHub's own organizations (``actions``, ``github`` and ``advanced-security``) a
91
120
92
121
To distrust the first-party ``github`` owner, add a data extension file with the following content:
93
122
94
-
.. code-block:: yaml
95
-
96
-
extensions:
97
-
- addsTo:
98
-
pack: codeql/actions-all
99
-
extensible: trustedActionsOwnerDataModel
100
-
data:
101
-
- ["!github"]
123
+
.. code-block:: json
124
+
125
+
{
126
+
"extensions": [
127
+
{
128
+
"addsTo": {
129
+
"pack": "codeql/actions-all",
130
+
"extensible": "trustedActionsOwnerDataModel"
131
+
},
132
+
"data": [
133
+
["!github"]
134
+
]
135
+
}
136
+
]
137
+
}
102
138
103
139
With this in place, the query will once again report unpinned tags for Actions published by ``github``.
0 commit comments