File tree Expand file tree Collapse file tree 1 file changed +8
-8
lines changed Expand file tree Collapse file tree 1 file changed +8
-8
lines changed Original file line number Diff line number Diff line change 1
1
name : ATM Check Queries Run
2
2
3
3
env :
4
- DB_PATH : test_db
5
4
QUERY_PACK : javascript/ql/experimental/adaptivethreatmodeling/src
6
5
QUERY_SUITE : codeql-suites/javascript-atm-code-scanning.qls
7
6
@@ -27,22 +26,23 @@ jobs:
27
26
- name : Install ATM model
28
27
run : |
29
28
set -exu
30
-
31
- # Install dependencies of ATM query pack
32
- codeql pack install ${QUERY_PACK}
29
+
30
+ # Install dependencies of ATM query pack, i.e. the ATM model
31
+ codeql pack install " ${QUERY_PACK}"
33
32
34
33
# Retrieve model checksum
35
- model_checksum=$(codeql resolve extensions ${QUERY_PACK}/${QUERY_SUITE} | jq -r '.models[0].checksum')
34
+ model_checksum=$(codeql resolve extensions " ${QUERY_PACK}/${QUERY_SUITE}" | jq -r '.models[0].checksum')
36
35
37
36
# Trust the model so that we can use it in the ATM boosted queries
38
37
mkdir -p "$HOME/.config/codeql"
39
38
echo "--insecurely-execute-ml-model-checksums ${model_checksum}" >> "$HOME/.config/codeql/config"
40
39
41
40
- name : Create test DB
42
41
run : |
43
- codeql database create ${RUNNER_TEMP}/${DB_PATH} --source-root config/atm/ --language javascript
42
+ DB_PATH="${RUNNER_TEMP}/db"
43
+ codeql database create "${DB_PATH}" --source-root config/atm --language javascript
44
+ echo "DB_PATH=${DB_PATH}" >> "${GITHUB_ENV}"
44
45
45
46
- name : Run ATM query suite
46
47
run : |
47
- codeql database run-queries -vv -- ${RUNNER_TEMP}/${DB_PATH} ${QUERY_PACK}/${QUERY_SUITE}
48
-
48
+ codeql database run-queries -vv -- "${DB_PATH}" "${QUERY_PACK}/${QUERY_SUITE}"
You can’t perform that action at this time.
0 commit comments