summaryrefslogtreecommitdiff
path: root/.github/workflows/fail_on_error.py
diff options
context:
space:
mode:
authorHa Thach <[email protected]>2023-11-30 11:56:52 +0700
committerGitHub <[email protected]>2023-11-30 11:56:52 +0700
commit338ff2daba63fc60835934efc374c818f7c5980c (patch)
tree3ae0a1857cfd90198cc58159af828d639997159f /.github/workflows/fail_on_error.py
parent0877a486cb26197ad2c031f61c1c285f29b85369 (diff)
parent66b9bd52d685eb7995f7d770ee01095966c2d880 (diff)
Merge pull request #2351 from IVOES/master
Add CodeQL Workflow for Code Security Analysis
Diffstat (limited to '.github/workflows/fail_on_error.py')
-rwxr-xr-x.github/workflows/fail_on_error.py34
1 files changed, 34 insertions, 0 deletions
diff --git a/.github/workflows/fail_on_error.py b/.github/workflows/fail_on_error.py
new file mode 100755
index 000000000..29791742b
--- /dev/null
+++ b/.github/workflows/fail_on_error.py
@@ -0,0 +1,34 @@
+#!/usr/bin/env python3
+
+import json
+import sys
+
+# Return whether SARIF file contains error-level results
+def codeql_sarif_contain_error(filename):
+ with open(filename, 'r') as f:
+ s = json.load(f)
+
+ for run in s.get('runs', []):
+ rules_metadata = run['tool']['driver']['rules']
+ if not rules_metadata:
+ rules_metadata = run['tool']['extensions'][0]['rules']
+
+ for res in run.get('results', []):
+ if 'ruleIndex' in res:
+ rule_index = res['ruleIndex']
+ elif 'rule' in res and 'index' in res['rule']:
+ rule_index = res['rule']['index']
+ else:
+ continue
+ try:
+ rule_level = rules_metadata[rule_index]['defaultConfiguration']['level']
+ except IndexError as e:
+ print(e, rule_index, len(rules_metadata))
+ else:
+ if rule_level == 'error':
+ return True
+ return False
+
+if __name__ == "__main__":
+ if codeql_sarif_contain_error(sys.argv[1]):
+ sys.exit(1)