File tree Expand file tree Collapse file tree 1 file changed +8
-16
lines changed Expand file tree Collapse file tree 1 file changed +8
-16
lines changed Original file line number Diff line number Diff line change @@ -19,38 +19,30 @@ jobs:
19
19
steps :
20
20
- uses : actions/checkout@v3
21
21
22
- - name : Install CodeQL CLI
23
- env :
24
- GITHUB_TOKEN : ${{ secrets.GITHUB_TOKEN }}
25
- run : |
26
- gh extensions install github/gh-codeql
27
- gh codeql download
22
+ - name : Setup CodeQL
23
+ uses : ./.github/actions/fetch-codeql
24
+ with :
25
+ channel : release
28
26
29
27
- name : Install ATM model pack
30
- env :
31
- GITHUB_TOKEN : ${{ secrets.GITHUB_TOKEN }}
32
28
run : |
33
29
set -exu
34
30
35
31
# Install ATM model pack
36
- gh codeql pack install ${ATM_MODEL_PACK}
32
+ codeql pack install ${ATM_MODEL_PACK}
37
33
38
34
# Retrieve model checksum
39
- model_checksum=$(gh codeql resolve extensions ${ATM_MODEL_PACK}/${QUERY_SUITE} | jq -r '.models[0].checksum')
35
+ model_checksum=$(codeql resolve extensions ${ATM_MODEL_PACK}/${QUERY_SUITE} | jq -r '.models[0].checksum')
40
36
41
37
# Trust the model so that we can use it in the ATM boosted queries
42
38
mkdir -p "$HOME/.config/codeql"
43
39
echo "--insecurely-execute-ml-model-checksums ${model_checksum}" >> "$HOME/.config/codeql/config"
44
40
45
41
- name : Create test DB
46
- env :
47
- GITHUB_TOKEN : ${{ secrets.GITHUB_TOKEN }}
48
42
run : |
49
- gh codeql database create ${RUNNER_TEMP}/${DB_PATH} --source-root config/atm/ --language javascript
43
+ codeql database create ${RUNNER_TEMP}/${DB_PATH} --source-root config/atm/ --language javascript
50
44
51
45
- name : Run ATM query suite
52
- env :
53
- GITHUB_TOKEN : ${{ secrets.GITHUB_TOKEN }}
54
46
run : |
55
- gh codeql database run-queries -vv -- ${RUNNER_TEMP}/${DB_PATH} ${ATM_MODEL_PACK}/${QUERY_SUITE}
47
+ codeql database run-queries -vv -- ${RUNNER_TEMP}/${DB_PATH} ${ATM_MODEL_PACK}/${QUERY_SUITE}
56
48
You can’t perform that action at this time.
0 commit comments