-
Notifications
You must be signed in to change notification settings - Fork 1
59 lines (52 loc) · 1.85 KB
/
Copy pathcodeql.yml
File metadata and controls
59 lines (52 loc) · 1.85 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
name: CodeQL
# Replaces the repo's "Default setup" so query-pack config lives in
# version control. Default setup is auto-disabled by GitHub as soon
# as this file exists on the default branch.
on:
push:
branches: [main]
pull_request:
branches: [main]
schedule:
# Daily 06:00 UTC — staggered from morphe-build (05:15)
# to avoid runner contention.
- cron: '0 6 * * *'
# Workflow-level default. The `analyze` job below declares a
# wider set (`actions: read`, `security-events: write`) per-job.
permissions:
contents: read
# Cancel any in-flight run for the same ref when a new commit lands.
# CodeQL is heavier than CI (DB build + analysis per language matrix
# entry) so cancelling superseded runs keeps the queue moving.
concurrency:
group: codeql-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
analyze:
name: Analyze (${{ matrix.language }})
runs-on: ubuntu-latest
timeout-minutes: 15
permissions:
actions: read
contents: read
security-events: write
strategy:
fail-fast: false
matrix:
# `javascript-typescript` covers both `javascript` and `typescript`
# analyses — matches what default setup enabled for this repo.
language: [actions, javascript-typescript]
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Initialize CodeQL
uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
languages: ${{ matrix.language }}
queries: security-and-quality
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
category: "/language:${{ matrix.language }}"