openclaw/.github/workflows/codeql-macos-critical-security.yml
Peter Steinberger f78f51359d
chore(deps): refresh dependencies with seven-day cutoff (#149908)
* chore(deps): refresh dependencies with seven-day cutoff

Advance eligible application, native, release, and development dependencies
published by 2026-09-09T06:51:52Z. Audit new registry resolutions and native
artifact hashes, preserving existing security pins and compatibility holds.

Adapt MCP Apps 2 tool discovery and host context, retain Clack cancellation
handling, and align the updater fixture with its runtime assembly owner.
Synchronize native artifact checks, operational docs, and tooling pins.

Validation includes frozen installation, full build, CLI rebuild, typechecks,
lint, 96 npm package locks, dependency audits, focused runtime and native
proofs, and independent review. Exact-head hosted CI is required before land.

* fix(deps): preserve scroll ownership and synchronize toolchain contracts

* fix(cli): preserve generic wizard option values after Clack update

* docs(lobster): clarify credentials for embedded remote calls

* test(cli): use Clack cancellation sentinel in prompt fixtures

* fix(ios): avoid opening audio input during relay cancellation

* test: reuse dependency update fixtures within line limits

* fix(crabbox): retain the previous trusted pnpm pin

* test(gateway): synchronize task access churn with page selection

* test(macos): isolate the challenge timeout transport fixture

* fix(macos): preserve hidden windows through deminiaturization

* fix(macos): exclude hidden dashboards from window selection
2026-09-16 09:06:40 -07:00

153 lines
5 KiB
YAML

name: CodeQL macOS Critical Security
on:
workflow_dispatch:
schedule:
- cron: "0 8 * * 1"
concurrency:
group: codeql-macos-critical-security-${{ github.workflow }}-${{ github.event_name == 'workflow_dispatch' && format('manual-{0}', github.run_id) || format('ref-{0}', github.ref) }}
cancel-in-progress: false
env:
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true"
permissions:
actions: read
contents: read
security-events: write
jobs:
prepare-mermaid:
name: Prepare Mermaid assets
runs-on: ubuntu-24.04
timeout-minutes: 10
permissions:
contents: read
outputs:
artifact-id: ${{ steps.upload.outputs.artifact-id }}
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 1
persist-credentials: false
ref: ${{ github.sha }}
submodules: false
- name: Setup Node environment
uses: ./.github/actions/setup-node-env
with:
cache-mode: restore
install-bun: "false"
install-deps: "false"
- name: Install Mermaid renderer dependencies
env:
CI: "true"
run: >-
pnpm install --frozen-lockfile --prefer-offline --optional
--filter '@openclaw/mermaid-renderer...'
--config.ignore-scripts=false
--config.engine-strict=false
--config.enable-pre-post-scripts=true
--config.side-effects-cache=true
- name: Prepare Apple Mermaid assets
run: node scripts/prepare-apple-mermaid.mjs
- name: Upload Mermaid assets
id: upload
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: codeql-macos-mermaid-${{ github.run_id }}-${{ github.run_attempt }}
path: apps/shared/OpenClawKit/Sources/OpenClawChatUI/Resources/Mermaid
if-no-files-found: error
retention-days: 1
macos:
name: Critical Security (macOS)
needs: prepare-mermaid
runs-on: macos-26-intel
timeout-minutes: 90
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 1
persist-credentials: false
ref: ${{ github.sha }}
submodules: false
- name: Select Xcode
run: |
set -euo pipefail
sudo xcode-select -s /Applications/Xcode_26.6.app/Contents/Developer
xcodebuild -version
xcode_version="$(xcodebuild -version | awk 'NR == 1 { print $2 }')"
if [[ "$xcode_version" != 26.6* ]]; then
echo "error: expected Xcode 26.6, got $xcode_version" >&2
exit 1
fi
swift --version
- name: Download Mermaid assets
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
with:
artifact-ids: ${{ needs.prepare-mermaid.outputs.artifact-id }}
path: apps/shared/OpenClawKit/Sources/OpenClawChatUI/Resources/Mermaid
- name: Initialize CodeQL
uses: github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9
with:
languages: swift
build-mode: manual
config-file: ./.github/codeql/codeql-macos-critical-security.yml
- name: Build macOS for CodeQL
# Preserve ARM-only application paths in CodeQL coverage on the Intel host.
run: swift build --package-path apps/macos --product OpenClaw --arch arm64 --disable-index-store -debug-info-format none
- name: Analyze
id: analyze
uses: github/codeql-action/analyze@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9
with:
output: sarif-results
upload: failure-only
category: "/codeql-critical-security/macos"
- name: Remove dependency build results
env:
SARIF_OUTPUT: sarif-results
run: |
set -euo pipefail
shopt -s nullglob
if [ ! -d "$SARIF_OUTPUT" ]; then
echo "SARIF output directory not found: $SARIF_OUTPUT" >&2
exit 1
fi
mkdir -p sarif-results-filtered
files=("$SARIF_OUTPUT"/*.sarif)
if [ "${#files[@]}" -eq 0 ]; then
echo "No SARIF files found in $SARIF_OUTPUT" >&2
exit 1
fi
for file in "${files[@]}"; do
jq '
def in_dependency_build:
((.locations // []) | length > 0)
and all(.locations[]; (.physicalLocation.artifactLocation.uri? // "") | test("^apps/macos/\\.build/"));
.runs |= map(.results = ((.results // []) | map(select(in_dependency_build | not))))
' "$file" > "sarif-results-filtered/$(basename "$file")"
done
- name: Upload filtered SARIF
uses: github/codeql-action/upload-sarif@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9
with:
sarif_file: sarif-results-filtered
category: "/codeql-critical-security/macos"