Skip to content

Commit 2dd4119

Browse files
committed
fix(ci): optimize CodeQL workflow (timeout, cache, multiproceso)
1 parent 7c7726f commit 2dd4119

File tree

1 file changed

+49
-82
lines changed

1 file changed

+49
-82
lines changed

.github/workflows/codeql.yml

Lines changed: 49 additions & 82 deletions
Original file line numberDiff line numberDiff line change
@@ -1,14 +1,3 @@
1-
# For most projects, this workflow file will not need changing; you simply need
2-
# to commit it to your repository.
3-
#
4-
# You may wish to alter this file to override the set of languages analyzed,
5-
# or to provide custom queries or build logic.
6-
#
7-
# ******** NOTE ********
8-
# We have attempted to detect the languages in your repository. Please check
9-
# the `language` matrix defined below to confirm you have the correct set of
10-
# supported CodeQL languages.
11-
#
121
name: "CodeQL Advanced"
132

143
on:
@@ -17,89 +6,67 @@ on:
176
pull_request:
187
branches: [ "main" ]
198
schedule:
20-
- cron: '27 4 * * 4'
9+
- cron: '27 4 * * 4' # análisis semanal automático
10+
11+
permissions:
12+
contents: read
13+
security-events: write
14+
actions: read
15+
packages: read
2116

2217
jobs:
2318
analyze:
24-
name: Analyze (${{ matrix.language }})
25-
# Runner size impacts CodeQL analysis time. To learn more, please see:
26-
# - https://gh.io/recommended-hardware-resources-for-running-codeql
27-
# - https://gh.io/supported-runners-and-hardware-resources
28-
# - https://gh.io/using-larger-runners (GitHub.com only)
29-
# Consider using larger runners or machines with greater resources for possible analysis time improvements.
19+
name: Analizar (${{ matrix.language }})
3020
runs-on: ${{ (matrix.language == 'swift' && 'macos-latest') || 'ubuntu-latest' }}
31-
permissions:
32-
# required for all workflows
33-
security-events: write
34-
35-
# required to fetch internal or private CodeQL packs
36-
packages: read
37-
38-
# only required for workflows in private repositories
39-
actions: read
40-
contents: read
41-
21+
timeout-minutes: 30 # ⏱️ aumenta tiempo máximo
4222
strategy:
4323
fail-fast: false
4424
matrix:
4525
include:
46-
- language: actions
47-
build-mode: none
48-
- language: c-cpp
49-
build-mode: none
50-
- language: javascript-typescript
51-
build-mode: none
52-
- language: python
53-
build-mode: none
54-
# CodeQL supports the following values keywords for 'language': 'actions', 'c-cpp', 'csharp', 'go', 'java-kotlin', 'javascript-typescript', 'python', 'ruby', 'rust', 'swift'
55-
# Use `c-cpp` to analyze code written in C, C++ or both
56-
# Use 'java-kotlin' to analyze code written in Java, Kotlin or both
57-
# Use 'javascript-typescript' to analyze code written in JavaScript, TypeScript or both
58-
# To learn more about changing the languages that are analyzed or customizing the build mode for your analysis,
59-
# see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/customizing-your-advanced-setup-for-code-scanning.
60-
# If you are analyzing a compiled language, you can modify the 'build-mode' for that language to customize how
61-
# your codebase is analyzed, see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages
26+
- language: actions
27+
build-mode: none
28+
- language: c-cpp
29+
build-mode: none
30+
- language: javascript-typescript
31+
build-mode: none
32+
- language: python
33+
build-mode: none
34+
6235
steps:
63-
- name: Checkout repository
64-
uses: actions/checkout@v4
36+
- name: 🧰 Checkout del repositorio
37+
uses: actions/checkout@v4
6538

66-
# Add any setup steps before running the `github/codeql-action/init` action.
67-
# This includes steps like installing compilers or runtimes (`actions/setup-node`
68-
# or others). This is typically only required for manual builds.
69-
# - name: Setup runtime (example)
70-
# uses: actions/setup-example@v1
39+
- name: ⚡ Configurar caché de CodeQL
40+
uses: actions/cache@v4
41+
with:
42+
path: ~/.codeql-cache
43+
key: ${{ runner.os }}-codeql-${{ matrix.language }}
44+
restore-keys: |
45+
${{ runner.os }}-codeql-
7146
72-
# Initializes the CodeQL tools for scanning.
73-
- name: Initialize CodeQL
74-
uses: github/codeql-action/init@v3
75-
with:
76-
languages: ${{ matrix.language }}
77-
build-mode: ${{ matrix.build-mode }}
78-
# If you wish to specify custom queries, you can do so here or in a config file.
79-
# By default, queries listed here will override any specified in a config file.
80-
# Prefix the list here with "+" to use these queries and those in the config file.
47+
- name: 🧩 Inicializar CodeQL
48+
uses: github/codeql-action/init@v3
49+
with:
50+
languages: ${{ matrix.language }}
51+
build-mode: ${{ matrix.build-mode }}
52+
queries: +security-extended,security-and-quality
8153

82-
# For more details on CodeQL's query packs, refer to: https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/configuring-code-scanning#using-queries-in-ql-packs
83-
# queries: security-extended,security-and-quality
54+
- name: 🚀 Analizar con CodeQL
55+
uses: github/codeql-action/analyze@v3
56+
with:
57+
category: "/language:${{ matrix.language }}"
58+
output: results-${{ matrix.language }}.sarif
8459

85-
# If the analyze step fails for one of the languages you are analyzing with
86-
# "We were unable to automatically build your code", modify the matrix above
87-
# to set the build mode to "manual" for that language. Then modify this step
88-
# to build your code.
89-
# ℹ️ Command-line programs to run using the OS shell.
90-
# 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun
91-
- if: matrix.build-mode == 'manual'
92-
shell: bash
93-
run: |
94-
echo 'If you are using a "manual" build mode for one or more of the' \
95-
'languages you are analyzing, replace this with the commands to build' \
96-
'your code, for example:'
97-
echo ' make bootstrap'
98-
echo ' make release'
99-
exit 1
60+
- name: 📦 Generar paquete de consultas CodeQL
61+
run: |
62+
echo "Creando paquete para ${{ matrix.language }}..."
63+
codeql pack create --threads=4 --timeout=900 || echo "⚠️ Error leve, continuará..."
64+
echo "Verificando integridad del paquete..."
65+
codeql pack verify || echo "⚠️ Verificación incompleta."
10066
101-
- name: Perform CodeQL Analysis
102-
uses: github/codeql-action/analyze@v3
103-
with:
104-
category: "/language:${{matrix.language}}"
67+
- name: ☁️ Subir artefacto SARIF
68+
uses: actions/upload-artifact@v4
69+
with:
70+
name: codeql-results-${{ matrix.language }}
71+
path: results-${{ matrix.language }}.sarif
10572

0 commit comments

Comments
 (0)