nordgedanken-github-io

git clone git://archive.git.mtrnord.blog/Nordgedanken/nordgedanken-github-io.git
Log | Files | Refs | README | LICENSE

codeql-analysis.yml (2735B)


      1 # For most projects, this workflow file will not need changing; you simply need
      2 # to commit it to your repository.
      3 #
      4 # You may wish to alter this file to override the set of languages analyzed,
      5 # or to provide custom queries or build logic.
      6 #
      7 # ******** NOTE ********
      8 # We have attempted to detect the languages in your repository. Please check
      9 # the `language` matrix defined below to confirm you have the correct set of
     10 # supported CodeQL languages.
     11 #
     12 name: "CodeQL"
     13 
     14 on:
     15   push:
     16     branches: [ "master" ]
     17   pull_request:
     18     # The branches below must be a subset of the branches above
     19     branches: [ "master" ]
     20   schedule:
     21     - cron: '37 2 * * 1'
     22 
     23 jobs:
     24   analyze:
     25     name: Analyze
     26     runs-on: ubuntu-latest
     27     permissions:
     28       actions: read
     29       contents: read
     30       security-events: write
     31 
     32     strategy:
     33       fail-fast: false
     34       matrix:
     35         language: [ 'javascript' ]
     36         # CodeQL supports [ 'cpp', 'csharp', 'go', 'java', 'javascript', 'python', 'ruby' ]
     37         # Learn more about CodeQL language support at https://aka.ms/codeql-docs/language-support
     38 
     39     steps:
     40     - name: Checkout repository
     41       uses: actions/checkout@v3
     42 
     43     # Initializes the CodeQL tools for scanning.
     44     - name: Initialize CodeQL
     45       uses: github/codeql-action/init@v2
     46       with:
     47         languages: ${{ matrix.language }}
     48         # If you wish to specify custom queries, you can do so here or in a config file.
     49         # By default, queries listed here will override any specified in a config file.
     50         # Prefix the list here with "+" to use these queries and those in the config file.
     51         
     52         # Details on CodeQL's query packs refer to : https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/configuring-code-scanning#using-queries-in-ql-packs
     53         # queries: security-extended,security-and-quality
     54 
     55         
     56     # Autobuild attempts to build any compiled languages  (C/C++, C#, or Java).
     57     # If this step fails, then you should remove it and run the build manually (see below)
     58     - name: Autobuild
     59       uses: github/codeql-action/autobuild@v2
     60 
     61     # â„šī¸ Command-line programs to run using the OS shell.
     62     # 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun
     63 
     64     #   If the Autobuild fails above, remove it and uncomment the following three lines. 
     65     #   modify them (or add more) to build your code if your project, please refer to the EXAMPLE below for guidance.
     66 
     67     # - run: |
     68     #   echo "Run, Build Application using script"
     69     #   ./location_of_script_within_repo/buildscript.sh
     70 
     71     - name: Perform CodeQL Analysis
     72       uses: github/codeql-action/analyze@v2