Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
56 changes: 56 additions & 0 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,56 @@
name: "CodeQL"

on:
push:
branches: [ "main" ]
pull_request:
branches: [ "main" ]
schedule:
- cron: '20 14 * * 5'

# Least privilege: the analyze job needs to read the repo, read packages and
# write security events (SARIF upload). Nothing else is touched.
permissions:
contents: read

jobs:
analyze:
name: Analyze (java-kotlin)
runs-on: ubuntu-latest
timeout-minutes: 90
permissions:
contents: read
security-events: write
packages: read

steps:
- name: Checkout repository
uses: actions/checkout@v5

- name: Set up JDK 17
uses: actions/setup-java@v5
with:
java-version: '17'
distribution: 'temurin'
cache: gradle

- name: Initialize CodeQL
uses: github/codeql-action/init@v4
with:
languages: java-kotlin
build-mode: manual
dependency-caching: true

# Manual build mode on purpose. CodeQL's autobuild runs `./gradlew clean
# assemble`, which minifies every release variant — all 13 library
# modules plus the app and benchlab run R8 concurrently in the Gradle
# daemon and exhaust the runner heap (OutOfMemoryError). Debug variants
# skip R8, so building them is enough for CodeQL to extract the
# Java/Kotlin sources while staying well within memory limits.
- name: Build with Gradle (debug variants, no R8)
run: ./gradlew --no-daemon assembleDebug

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v4
with:
category: "/language:java-kotlin"
3 changes: 2 additions & 1 deletion .github/workflows/r8.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,8 @@ permissions:
contents: read

env:
GRADLE_OPTS: "-Dorg.gradle.jvmargs=-Xmx4g"
# Keep in sync with gradle.properties — GRADLE_OPTS overrides it.
GRADLE_OPTS: "-Dorg.gradle.jvmargs=-Xmx8g"

jobs:
release-build:
Expand Down
13 changes: 12 additions & 1 deletion gradle.properties
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,18 @@
appdimens.version=3.1.8

# Memory and JVM
org.gradle.jvmargs=-Xmx4g -XX:+UseParallelGC -Dfile.encoding=UTF-8 --enable-native-access=ALL-UNNAMED
# -Xmx8g: a full `assemble` runs R8 (minifyReleaseWithR8) for every release
# variant — all 13 library modules plus the app and benchlab apps — and AGP
# runs those R8 passes in-process inside the Gradle daemon. 4g was enough for
# single-module builds but exhausts the heap on the full multi-module assemble
# (OutOfMemoryError during CodeQL autobuild's `clean assemble`). 8g fits the
# 16 GB ubuntu-latest runner alongside the Kotlin daemon and aapt2.
org.gradle.jvmargs=-Xmx8g -XX:+UseParallelGC -Dfile.encoding=UTF-8 --enable-native-access=ALL-UNNAMED

# R8 runs in the daemon and each concurrent minify pass can peak at ~1.5-2 GB,
# so 13+ parallel R8 passes would exhaust even an 8g heap on machines with many
# cores. Cap workers to keep the full `assemble` deterministic on CI and local.
org.gradle.workers.max=4

# Parallel and Cache (Velocidade de Build)
org.gradle.parallel=true
Expand Down
Loading