Tamp.CodeQL.V2
0.1.2
Prefix Reserved
dotnet add package Tamp.CodeQL.V2 --version 0.1.2
NuGet\Install-Package Tamp.CodeQL.V2 -Version 0.1.2
<PackageReference Include="Tamp.CodeQL.V2" Version="0.1.2" />
<PackageVersion Include="Tamp.CodeQL.V2" Version="0.1.2" />
<PackageReference Include="Tamp.CodeQL.V2" />
paket add Tamp.CodeQL.V2 --version 0.1.2
#r "nuget: Tamp.CodeQL.V2, 0.1.2"
#:package Tamp.CodeQL.V2@0.1.2
#addin nuget:?package=Tamp.CodeQL.V2&version=0.1.2
#tool nuget:?package=Tamp.CodeQL.V2&version=0.1.2
Tamp.CodeQL
| Package | CodeQL | Status |
|---|---|---|
Tamp.CodeQL.V2 |
2.x | preview |
Requires Tamp.Core ≥ 1.0.3. GitHub PAT typed as Secret and fed
via --github-auth-stdin (NOT argv, so it can't leak to process
listings).
Verbs
| Sub-facade | Verb | Notes |
|---|---|---|
Database |
Create |
Index source. Required: --language, db path. --source-root, --command, --build-mode, --overwrite, --extractor-option. |
Database |
Init |
Start build-tracing session. --begin-tracing. |
Database |
TraceCommand |
Wrap a build command — wrapper emits -- separator before the build argv. |
Database |
Finalize |
Finalize traced DB. --cleanup. |
Database |
Analyze |
Run queries. --format, --output, --sarif-category, --sarif-add-snippets, --download / --no-download. |
Database |
Upgrade |
Schema upgrade. --allow-downgrades. |
Database |
ExportDiagnostics |
Per-file diagnostics SARIF. |
Database |
Bundle |
Package DB for upload. |
GitHub |
UploadResults |
POST SARIF to Code Scanning. Token via Secret. |
Resolve |
Languages / Queries |
Enumerate extractors / queries. |
Pack |
Download / Install |
Fetch and install QL packs. |
Query |
Run |
Single-query mode. |
Version |
codeql version. |
|
Raw |
Escape hatch. |
Common flags (all verbs): --threads, --ram, --verbosity,
--quiet, --no-progress-tracker, --logdir, --common-caches.
Quick example — CI SARIF upload
using Tamp;
using Tamp.CodeQL.V2;
[NuGetPackage("codeql", UseSystemPath = true)]
readonly Tool CodeQL = null!;
[Secret("GitHub token", EnvironmentVariable = "GITHUB_TOKEN")]
readonly Secret GitHubToken = null!;
Target CreateDb => _ => _.Executes(() =>
CodeQL.Database.Create(CodeQL, s => s
.SetDatabasePath("codeql-db")
.SetLanguage("csharp")
.SetSourceRoot(".")
.SetCommand("dotnet build")
.SetOverwrite()
.SetRam(8000)
.SetThreads(0)));
Target Analyze => _ => _
.DependsOn(nameof(CreateDb))
.Executes(() =>
CodeQL.Database.Analyze(CodeQL, s => s
.SetDatabasePath("codeql-db")
.AddQuery("codeql/csharp-queries")
.SetFormat("sarif-latest")
.SetOutput("results.sarif")
.SetSarifCategory("primary")
.SetSarifAddSnippets()));
Target Upload => _ => _
.DependsOn(nameof(Analyze))
.Requires(() => GitHubToken != null)
.Executes(() =>
CodeQL.GitHub.UploadResults(CodeQL, s => s
.SetSarifFile("results.sarif")
.SetRepository("acme/widgets")
.SetRef("refs/heads/main")
.SetCommit(Git.Commit)
.SetGitHubToken(GitHubToken)
.SetWaitForProcessing()
.SetWaitForProcessingTimeout(120)));
Releasing
See MAINTAINERS.md.
Settings authoring style
Examples above use the fluent Set*-chain shape. Every wrapper verb also accepts a new XxxSettings { ... } object-init form — both produce identical CommandPlans. The fluent shape stays canonical in docs and the tamp init template; opt into object-init scaffolding via tamp init --settings-style=init.
See Build Script Authoring → Two authoring styles on the wiki for the side-by-side comparison.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 is compatible. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.