You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: .github/workflows/codeql.yml
+41-51Lines changed: 41 additions & 51 deletions
Original file line number
Diff line number
Diff line change
@@ -10,15 +10,11 @@
10
10
# supported CodeQL languages.
11
11
#
12
12
name: "CodeQL Advanced"
13
-
14
13
on:
15
14
push:
16
-
branches: [ "main" ]
17
-
pull_request:
18
-
branches: [ "main" ]
15
+
branches: ["main"]
19
16
schedule:
20
17
- cron: '40 4 * * 0'
21
-
22
18
jobs:
23
19
analyze:
24
20
name: Analyze (${{ matrix.language }})
@@ -31,62 +27,56 @@ jobs:
31
27
permissions:
32
28
# required for all workflows
33
29
security-events: write
34
-
35
30
# required to fetch internal or private CodeQL packs
36
31
packages: read
37
-
38
32
# only required for workflows in private repositories
39
33
actions: read
40
34
contents: read
41
-
42
35
strategy:
43
36
fail-fast: false
44
37
matrix:
45
38
include:
46
-
- language: python
47
-
build-mode: none
48
-
# CodeQL supports the following values keywords for 'language': 'c-cpp', 'csharp', 'go', 'java-kotlin', 'javascript-typescript', 'python', 'ruby', 'swift'
49
-
# Use `c-cpp` to analyze code written in C, C++ or both
50
-
# Use 'java-kotlin' to analyze code written in Java, Kotlin or both
51
-
# Use 'javascript-typescript' to analyze code written in JavaScript, TypeScript or both
52
-
# To learn more about changing the languages that are analyzed or customizing the build mode for your analysis,
53
-
# see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/customizing-your-advanced-setup-for-code-scanning.
54
-
# If you are analyzing a compiled language, you can modify the 'build-mode' for that language to customize how
55
-
# your codebase is analyzed, see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages
39
+
- language: python
40
+
build-mode: none
41
+
# CodeQL supports the following values keywords for 'language': 'c-cpp', 'csharp', 'go', 'java-kotlin', 'javascript-typescript', 'python', 'ruby', 'swift'
42
+
# Use `c-cpp` to analyze code written in C, C++ or both
43
+
# Use 'java-kotlin' to analyze code written in Java, Kotlin or both
44
+
# Use 'javascript-typescript' to analyze code written in JavaScript, TypeScript or both
45
+
# To learn more about changing the languages that are analyzed or customizing the build mode for your analysis,
46
+
# see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/customizing-your-advanced-setup-for-code-scanning.
47
+
# If you are analyzing a compiled language, you can modify the 'build-mode' for that language to customize how
48
+
# your codebase is analyzed, see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages
56
49
steps:
57
-
- name: Checkout repository
58
-
uses: actions/checkout@v4
59
-
60
-
# Initializes the CodeQL tools for scanning.
61
-
- name: Initialize CodeQL
62
-
uses: github/codeql-action/init@v3
63
-
with:
64
-
languages: ${{ matrix.language }}
65
-
build-mode: ${{ matrix.build-mode }}
66
-
# If you wish to specify custom queries, you can do so here or in a config file.
67
-
# By default, queries listed here will override any specified in a config file.
68
-
# Prefix the list here with "+" to use these queries and those in the config file.
69
-
50
+
- name: Checkout repository
51
+
uses: actions/checkout@v4
52
+
# Initializes the CodeQL tools for scanning.
53
+
- name: Initialize CodeQL
54
+
uses: github/codeql-action/init@v3
55
+
with:
56
+
languages: ${{ matrix.language }}
57
+
build-mode: ${{ matrix.build-mode }}
58
+
# If you wish to specify custom queries, you can do so here or in a config file.
59
+
# By default, queries listed here will override any specified in a config file.
60
+
# Prefix the list here with "+" to use these queries and those in the config file.
61
+
# If the analyze step fails for one of the languages you are analyzing with
62
+
# "We were unable to automatically build your code", modify the matrix above
63
+
# to set the build mode to "manual" for that language. Then modify this step
64
+
# to build your code.
65
+
# ℹ️ Command-line programs to run using the OS shell.
66
+
# 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun
67
+
- if: matrix.build-mode == 'manual'
70
68
# For more details on CodeQL's query packs, refer to: https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/configuring-code-scanning#using-queries-in-ql-packs
71
69
# queries: security-extended,security-and-quality
72
70
73
-
# If the analyze step fails for one of the languages you are analyzing with
74
-
# "We were unable to automatically build your code", modify the matrix above
75
-
# to set the build mode to "manual" for that language. Then modify this step
76
-
# to build your code.
77
-
# ℹ️ Command-line programs to run using the OS shell.
78
-
# 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun
79
-
- if: matrix.build-mode == 'manual'
80
-
shell: bash
81
-
run: |
82
-
echo 'If you are using a "manual" build mode for one or more of the' \
83
-
'languages you are analyzing, replace this with the commands to build' \
84
-
'your code, for example:'
85
-
echo ' make bootstrap'
86
-
echo ' make release'
87
-
exit 1
88
-
89
-
- name: Perform CodeQL Analysis
90
-
uses: github/codeql-action/analyze@v3
91
-
with:
92
-
category: "/language:${{matrix.language}}"
71
+
shell: bash
72
+
run: |
73
+
echo 'If you are using a "manual" build mode for one or more of the' \
74
+
'languages you are analyzing, replace this with the commands to build' \
0 commit comments