test: enumerate the 38 __proto__ dispatch-registry entries (#504) #1562
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: "CodeQL" | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| # The branches below must be a subset of the branches above | |
| branches: [main] | |
| schedule: | |
| - cron: '0 2 * * 6' | |
| # Only pull-request runs may be superseded -- see the note in unit-tests.yml. A | |
| # ref-keyed group drops a *pending* run when a newer one joins it, which for a | |
| # security scan means a commit reaching main with no analysis on record. | |
| concurrency: | |
| group: codeql-${{ github.event_name == 'pull_request' && github.ref || github.run_id }} | |
| cancel-in-progress: ${{ github.event_name == 'pull_request' }} | |
| jobs: | |
| # This workflow used to call ./.github/workflows/unit-tests.yml and gate | |
| # `analyze` behind it. That re-ran the entire unit and integration matrix | |
| # against a commit the Unit Tests workflow is already testing, and it bought | |
| # nothing: CodeQL reads the source, so its findings do not depend on the test | |
| # suite passing. Worse, it meant a failing test suppressed the security | |
| # analysis for that commit. Static analysis now runs on its own. | |
| analyze: | |
| name: Analyze | |
| runs-on: ubuntu-latest | |
| permissions: | |
| actions: read | |
| contents: read | |
| security-events: write | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v7 | |
| # Initializes the CodeQL tools for scanning. | |
| - name: Initialize CodeQL | |
| uses: github/codeql-action/init@v4 | |
| # Override language selection by uncommenting this and choosing your languages | |
| # with: | |
| # languages: go, javascript, csharp, python, cpp, java | |
| # Autobuild attempts to build any compiled languages (C/C++, C#, or Java). | |
| # If this step fails, then you should remove it and run the build manually (see below) | |
| - name: Autobuild | |
| uses: github/codeql-action/autobuild@v4 | |
| # ℹ️ Command-line programs to run using the OS shell. | |
| # 📚 https://git.io/JvXDl | |
| # ✏️ If the Autobuild fails above, remove it and uncomment the following three lines | |
| # and modify them (or add more) to build your code if your project | |
| # uses a compiled language | |
| #- run: | | |
| # make bootstrap | |
| # make release | |
| - name: Perform CodeQL Analysis | |
| uses: github/codeql-action/analyze@v4 |