# Licensed to the Apache Software Foundation (ASF) under one
# or more contributor license agreements.  See the NOTICE file
# distributed with this work for additional information
# regarding copyright ownership.  The ASF licenses this file
# to you under the Apache License, Version 2.0 (the
# "License"); you may not use this file except in compliance
# with the License.  You may obtain a copy of the License at
#
#   http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing,
# software distributed under the License is distributed on an
# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
# KIND, either express or implied.  See the License for the
# specific language governing permissions and limitations
# under the License.
#
---
name: "CodeQL"

on:  # yamllint disable-line rule:truthy
  push:
    branches: [main]
  schedule:
    - cron: '0 2 * * *'

permissions:
  contents: read
concurrency:
  group: codeql-${{ github.event.pull_request.number || github.ref }}
  cancel-in-progress: true

jobs:
  selective-checks:
    name: Selective checks
    runs-on: ubuntu-20.04
    outputs:
      needs-python-scans: ${{ steps.selective-checks.outputs.needs-python-scans }}
      needs-javascript-scans: ${{ steps.selective-checks.outputs.needs-javascript-scans }}
    steps:
      - name: Checkout repository
        uses: actions/checkout@v3
        with:
          fetch-depth: 2
          persist-credentials: false
      - name: "Install Breeze"
        uses: ./.github/actions/breeze
      - name: Selective checks
        id: selective-checks
        env:
          COMMIT_REF: "${{ github.sha }}"
          VERBOSE: "false"
        run: breeze ci selective-check 2>> ${GITHUB_OUTPUT}

  analyze:
    name: Analyze
    runs-on: ubuntu-20.04
    needs: [selective-checks]
    strategy:
      fail-fast: false
      matrix:
        # Override automatic language detection by changing the below list
        # Supported options are ['csharp', 'cpp', 'go', 'java', 'javascript', 'python']
        language: ['python', 'javascript']
    permissions:
      actions: read
      contents: read
      pull-requests: read
      security-events: write
    steps:
      - name: Checkout repository
        uses: actions/checkout@v3
        with:
          persist-credentials: false
        if: |
          matrix.language == 'python' && needs.selective-checks.outputs.needs-python-scans == 'true' ||
          matrix.language == 'javascript' && needs.selective-checks.outputs.needs-javascript-scans == 'true'

      # Initializes the CodeQL tools for scanning.
      - name: Initialize CodeQL
        uses: github/codeql-action/init@v2
        with:
          languages: ${{ matrix.language }}
          # If you wish to specify custom queries, you can do so here or in a config file.
          # By default, queries listed here will override any specified in a config file.
          # Prefix the list here with "+" to use these queries and those in the config file.
          # queries: ./path/to/local/query, your-org/your-repo/queries@main
        if: |
          matrix.language == 'python' && needs.selective-checks.outputs.needs-python-scans == 'true' ||
          matrix.language == 'javascript' && needs.selective-checks.outputs.needs-javascript-scans == 'true'

      # Autobuild attempts to build any compiled languages  (C/C++, C#, or Java).
      # If this step fails, then you should remove it and run the build manually (see below)
      - name: Autobuild
        uses: github/codeql-action/autobuild@v2
        if: |
          matrix.language == 'python' && needs.selective-checks.outputs.needs-python-scans == 'true' ||
          matrix.language == 'javascript' && needs.selective-checks.outputs.needs-javascript-scans == 'true'

      - name: Perform CodeQL Analysis
        uses: github/codeql-action/analyze@v2
        if: |
          matrix.language == 'python' && needs.selective-checks.outputs.needs-python-scans == 'true' ||
          matrix.language == 'javascript' && needs.selective-checks.outputs.needs-javascript-scans == 'true'