Repository navigation
Switch auto-updating to Sparkle, with a staging rehearsal and hand-wr… #702
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: codeql | |
| on: | |
| push: | |
| branches: [main] | |
| paths-ignore: ["docs/**"] | |
| pull_request: | |
| branches: [main] | |
| paths-ignore: ["docs/**"] | |
| schedule: | |
| # Weekly re-scan so newly-published CodeQL queries run against main even | |
| # during quiet periods. Monday 07:00 UTC. | |
| - cron: "0 7 * * 1" | |
| workflow_dispatch: # manual run (e.g. to validate the swift scan on a branch) | |
| concurrency: | |
| group: codeql-${{ github.ref }} | |
| cancel-in-progress: true | |
| permissions: | |
| contents: read | |
| jobs: | |
| # GitHub Actions workflow analysis — cheap (Linux, no build). Runs on every | |
| # trigger, PRs included, so workflow-injection issues are caught pre-merge. | |
| actions: | |
| name: Analyze (actions) | |
| runs-on: ubuntu-latest | |
| permissions: | |
| security-events: write # upload SARIF results to code scanning | |
| actions: read # required to read workflow runs on private repos | |
| contents: read # checkout | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Initialize CodeQL | |
| uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4 | |
| with: | |
| languages: actions | |
| build-mode: none | |
| - name: Perform CodeQL Analysis | |
| uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4 | |
| with: | |
| category: "/language:actions" | |
| # Swift analysis — expensive (a full macOS build). Skipped on PRs: check.yml | |
| # already gates every PR with a macOS build, so running a second one here just | |
| # to trace it doubles the per-PR cost. Instead it runs on push to main, the | |
| # weekly schedule, and manual dispatch — so main + the schedule still scan all | |
| # the Swift code, just off the PR critical path. | |
| swift: | |
| name: Analyze (swift) | |
| if: github.event_name != 'pull_request' | |
| runs-on: macos-26 | |
| timeout-minutes: 60 | |
| env: | |
| DERIVED: ${{ github.workspace }}/DerivedData-codeql | |
| permissions: | |
| security-events: write | |
| actions: read | |
| contents: read | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| # Cache the resolved SwiftPM checkouts so we don't re-clone the SDKs' | |
| # full git history on every run. Keyed on the pinned Package.resolved, so a | |
| # dependency bump busts the cache. restore-keys lets an older cache seed a | |
| # partial hit when the pins change. | |
| - name: Cache SwiftPM checkouts | |
| uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6 | |
| with: | |
| path: ${{ env.DERIVED }}/SourcePackages | |
| key: spm-${{ runner.os }}-${{ hashFiles('App/Blurt/Blurt.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/Package.resolved') }} | |
| restore-keys: | | |
| spm-${{ runner.os }}- | |
| # Resolve dependencies BEFORE codeql init, so the git clones run natively | |
| # (arm64) and untraced. CodeQL's Swift tracer runs the build as an x86_64 | |
| # (Rosetta) process, which makes dependency resolution — the slow part — | |
| # crawl. CodeQL only needs to trace the compile, not the resolve, so we do | |
| # the resolve here into the shared DerivedData path the build reuses. | |
| - name: Resolve packages (native, untraced) | |
| working-directory: App/Blurt | |
| run: | | |
| xcodebuild \ | |
| -project Blurt.xcodeproj \ | |
| -scheme Blurt \ | |
| -derivedDataPath "$DERIVED" \ | |
| -resolvePackageDependencies | |
| - name: Initialize CodeQL | |
| uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4 | |
| with: | |
| languages: swift | |
| build-mode: manual | |
| # build-mode: manual — build the committed Blurt.xcodeproj directly (no | |
| # xcodegen: it's checked in and drift-checked by the `check` workflow). | |
| # Generic destination (no arch pin) so the build produces a universal binary | |
| # (arm64 + x86_64). CI runners are arm64 only, so the x86_64 slice is not | |
| # tested here — community testing / manual verification on Intel hardware. | |
| # -derivedDataPath reuses the packages resolved above. Codesigning is off: | |
| # the Developer ID cert only lives on the maintainer's machine. | |
| - name: Build Swift | |
| working-directory: App/Blurt | |
| run: | | |
| xcodebuild \ | |
| -project Blurt.xcodeproj \ | |
| -scheme Blurt \ | |
| -configuration Debug \ | |
| -destination 'generic/platform=macOS' \ | |
| -derivedDataPath "$DERIVED" \ | |
| CODE_SIGN_IDENTITY="-" \ | |
| CODE_SIGNING_REQUIRED=NO \ | |
| CODE_SIGNING_ALLOWED=NO \ | |
| build | |
| - name: Perform CodeQL Analysis | |
| uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4 | |
| with: | |
| category: "/language:swift" |