diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml new file mode 100644 index 00000000..112f3cf1 --- /dev/null +++ b/.github/workflows/codeql.yml @@ -0,0 +1,56 @@ +name: "CodeQL" + +on: + push: + branches: [ "main" ] + pull_request: + branches: [ "main" ] + schedule: + - cron: '20 14 * * 5' + +# Least privilege: the analyze job needs to read the repo, read packages and +# write security events (SARIF upload). Nothing else is touched. +permissions: + contents: read + +jobs: + analyze: + name: Analyze (java-kotlin) + runs-on: ubuntu-latest + timeout-minutes: 90 + permissions: + contents: read + security-events: write + packages: read + + steps: + - name: Checkout repository + uses: actions/checkout@v5 + + - name: Set up JDK 17 + uses: actions/setup-java@v5 + with: + java-version: '17' + distribution: 'temurin' + cache: gradle + + - name: Initialize CodeQL + uses: github/codeql-action/init@v4 + with: + languages: java-kotlin + build-mode: manual + dependency-caching: true + + # Manual build mode on purpose. CodeQL's autobuild runs `./gradlew clean + # assemble`, which minifies every release variant — all 13 library + # modules plus the app and benchlab run R8 concurrently in the Gradle + # daemon and exhaust the runner heap (OutOfMemoryError). Debug variants + # skip R8, so building them is enough for CodeQL to extract the + # Java/Kotlin sources while staying well within memory limits. + - name: Build with Gradle (debug variants, no R8) + run: ./gradlew --no-daemon assembleDebug + + - name: Perform CodeQL Analysis + uses: github/codeql-action/analyze@v4 + with: + category: "/language:java-kotlin" diff --git a/.github/workflows/r8.yml b/.github/workflows/r8.yml index 3835f662..a5223dcd 100644 --- a/.github/workflows/r8.yml +++ b/.github/workflows/r8.yml @@ -10,7 +10,8 @@ permissions: contents: read env: - GRADLE_OPTS: "-Dorg.gradle.jvmargs=-Xmx4g" + # Keep in sync with gradle.properties — GRADLE_OPTS overrides it. + GRADLE_OPTS: "-Dorg.gradle.jvmargs=-Xmx8g" jobs: release-build: diff --git a/gradle.properties b/gradle.properties index 56005370..50406455 100644 --- a/gradle.properties +++ b/gradle.properties @@ -2,7 +2,18 @@ appdimens.version=3.1.8 # Memory and JVM -org.gradle.jvmargs=-Xmx4g -XX:+UseParallelGC -Dfile.encoding=UTF-8 --enable-native-access=ALL-UNNAMED +# -Xmx8g: a full `assemble` runs R8 (minifyReleaseWithR8) for every release +# variant — all 13 library modules plus the app and benchlab apps — and AGP +# runs those R8 passes in-process inside the Gradle daemon. 4g was enough for +# single-module builds but exhausts the heap on the full multi-module assemble +# (OutOfMemoryError during CodeQL autobuild's `clean assemble`). 8g fits the +# 16 GB ubuntu-latest runner alongside the Kotlin daemon and aapt2. +org.gradle.jvmargs=-Xmx8g -XX:+UseParallelGC -Dfile.encoding=UTF-8 --enable-native-access=ALL-UNNAMED + +# R8 runs in the daemon and each concurrent minify pass can peak at ~1.5-2 GB, +# so 13+ parallel R8 passes would exhaust even an 8g heap on machines with many +# cores. Cap workers to keep the full `assemble` deterministic on CI and local. +org.gradle.workers.max=4 # Parallel and Cache (Velocidade de Build) org.gradle.parallel=true