Skip to content

feat: add actions-custom-queries@1.1.2 to central config - #19

Merged
zhongliang02-bot[bot] merged 3 commits into
prodfrom
feat/add-actions-custom-queries-pin
Sep 16, 2026
Merged

zhongliang02-bot[bot] merged 3 commits into
prodfrom
feat/add-actions-custom-queries-pin

Conversation

@zhongliang02-bot

Copy link
Copy Markdown
Contributor

What

Adds the GitHub Actions custom-queries pack to the central config:

 packs:
   javascript:
     - opengovsg/nextjs-custom-queries@1.0.1
     - opengovsg/react-custom-queries@1.0.1
     - opengovsg/javascript-custom-queries@1.0.3
     - opengovsg/nestjs-custom-queries@1.0.0
+  actions:
+    - opengovsg/actions-custom-queries@1.1.2

This is the deployment half of the actions-custom-queries@1.1.2 release (codeql-pack PR #42). The pack was broken org-wide at 1.1.1 (stale codeql/actions-all@0.4.33 lock pin → "database is not compatible with a QL library" → total actions-scan blackout); 1.1.2 fixes it and is now published on GHCR. The pack was pinned nowhere until this PR, so this is a brand-new pin (out of scope for the pack pipeline's auto-reconciler, which only bumps existing pins) — hence a manual add.

E2E evidence (real scan on security-codeql-test-actions, CodeQL CLI 2.27.0)

Run: https://github.com/opengovsg/security-codeql-test-actions/actions/runs/34494667174 — success. (Validated via a throwaway PR that re-pointed that repo's config-file at this branch's commit; PR closed, branch deleted — no lasting change to the test repo.)

Pack resolved from GHCR + loaded + executed (run log):

  • Installed fresh opengovsg/actions-custom-queries@1.1.2 — downloaded from GHCR on a clean runner.
  • [1/20] Loaded … unpinned-global-install.qlx, [2/20] … unfrozen-package-install.qlx, [3/20] … unvetted-package-exec.qlx — 20 queries loaded = 17 built-in + 3 custom.
  • Starting evaluation of …/{unfrozen,unpinned,unvetted}.ql → Evaluation done → Interpreted problem query … — all 3 executed (not installed-and-skipped).

Findings (code-scanning alert set == local re-analysis with identical 1.1.2 source):

Rule Count Where
actions/unfrozen-package-install 2 bad-npm-install.yml:8, bad-yarn-install.yml:8 (known-bad)
actions/unvetted-package-exec 7 bad-npx-exec.yml:8–14 (known-bad)
actions/unpinned-global-install 4 real activesg-nightly/preview workflows
known-good good-npm-ci / good-npx-exec / good-pnpm-frozen 0 silent (no false positives)

Deployment note

⚠️ Do not merge without sign-off. Merging prod is the org-wide deploy — every repo referencing config-file: …@prod picks up the actions pack on its next scan. Branch cut from prod; the diff is exactly the added pin.

@zhongliang02-bot
zhongliang02-bot Bot merged commit 6ea2a0e into prod Sep 16, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant