diff options
| author | Ha Thach <[email protected]> | 2023-11-30 11:56:52 +0700 |
|---|---|---|
| committer | GitHub <[email protected]> | 2023-11-30 11:56:52 +0700 |
| commit | 338ff2daba63fc60835934efc374c818f7c5980c (patch) | |
| tree | 3ae0a1857cfd90198cc58159af828d639997159f /.github/workflows/fail_on_error.py | |
| parent | 0877a486cb26197ad2c031f61c1c285f29b85369 (diff) | |
| parent | 66b9bd52d685eb7995f7d770ee01095966c2d880 (diff) | |
Merge pull request #2351 from IVOES/master
Add CodeQL Workflow for Code Security Analysis
Diffstat (limited to '.github/workflows/fail_on_error.py')
| -rwxr-xr-x | .github/workflows/fail_on_error.py | 34 |
1 files changed, 34 insertions, 0 deletions
diff --git a/.github/workflows/fail_on_error.py b/.github/workflows/fail_on_error.py new file mode 100755 index 000000000..29791742b --- /dev/null +++ b/.github/workflows/fail_on_error.py @@ -0,0 +1,34 @@ +#!/usr/bin/env python3 + +import json +import sys + +# Return whether SARIF file contains error-level results +def codeql_sarif_contain_error(filename): + with open(filename, 'r') as f: + s = json.load(f) + + for run in s.get('runs', []): + rules_metadata = run['tool']['driver']['rules'] + if not rules_metadata: + rules_metadata = run['tool']['extensions'][0]['rules'] + + for res in run.get('results', []): + if 'ruleIndex' in res: + rule_index = res['ruleIndex'] + elif 'rule' in res and 'index' in res['rule']: + rule_index = res['rule']['index'] + else: + continue + try: + rule_level = rules_metadata[rule_index]['defaultConfiguration']['level'] + except IndexError as e: + print(e, rule_index, len(rules_metadata)) + else: + if rule_level == 'error': + return True + return False + +if __name__ == "__main__": + if codeql_sarif_contain_error(sys.argv[1]): + sys.exit(1) |
