github / github/codeql

Autobuild does not find maven build (pom.xml) files in subdirs

未關閉
#5,331 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
question
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

**Description of the issue**
I have a repo with multiple Java maven projects. The default codeql-analysis.yml file looks like this:
```
jobs:
...
steps:
...
- name: Autobuild
uses: github/codeql-action/autobuild@v1
...
```
Github's advanced security workflow reports that it cannot find a suitable source file to build when pom.xml files are not in the root of the repo: ```ERROR: Could not detect a suitable build command for the source checkout.```

Is that expected?

**Workaround**
I can change it to use the find utility to search for pom.xml files and run the package goal:
```
jobs:
...
steps:
...
- if: matrix.language != 'java'
name: Autobuild
uses: github/codeql-action/autobuild@v1

- if: matrix.language == 'java'
name: Build Java
run: |
find . -name pom.xml -exec mvn -f {} package \;
...
```

**My Ask**
If that is expected, then I'm asking for an enhancement request to the autobuilder to search for pom.xml files.

Either way, I request Github doc be updated to show a solution like above for this, IMO, very common scenario.

Thanks!

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。