返回 CodeWhale
codeql.yml
根目录 / .github / workflows / codeql.yml
1 # CodeQL advanced setup.
2 #
3 # Scans the same languages the repository's default setup scanned (Actions,
4 # JavaScript/TypeScript, Python, Rust) with the same default query suite, but
5 # reads .github/codeql/codeql-config.yml so test paths stay out of alerts.
6 #
7 # Gated off by default. While the repository uses CodeQL "Default" setup,
8 # GitHub rejects SARIF uploads from this workflow ("Code Scanning could not
9 # process the submitted SARIF"), so the analyze job runs only when the
10 # repository variable CODEQL_ADVANCED_SETUP is 'true'. The founder flips it
11 # after switching the repository to "Advanced" setup (Settings -> Code
12 # security -> Code scanning); until then every run skips the job.
13 name: CodeQL
14
15 on:
16 push:
17 branches: [main]
18 pull_request:
19 branches: [main]
20 schedule:
21 # Weekly, Tuesday 04:17 UTC.
22 - cron: '17 4 * * 2'
23 workflow_dispatch:
24
25 permissions: {}
26
27 concurrency:
28 group: codeql-${{ github.ref }}
29 cancel-in-progress: ${{ github.event_name == 'pull_request' }}
30
31 jobs:
32 analyze:
33 name: Analyze (${{ matrix.language }})
34 if: vars.CODEQL_ADVANCED_SETUP == 'true'
35 runs-on: ubuntu-latest
36 timeout-minutes: 120
37 permissions:
38 actions: read
39 contents: read
40 security-events: write
41 strategy:
42 fail-fast: false
43 matrix:
44 include:
45 - language: actions
46 build-mode: none
47 - language: javascript-typescript
48 build-mode: none
49 - language: python
50 build-mode: none
51 - language: rust
52 build-mode: none
53 steps:
54 - uses: actions/checkout@v7
55 with:
56 persist-credentials: false
57
58 - name: Initialize CodeQL
59 uses: github/codeql-action/init@v4
60 with:
61 languages: ${{ matrix.language }}
62 build-mode: ${{ matrix.build-mode }}
63 config-file: ./.github/codeql/codeql-config.yml
64
65 - name: Perform CodeQL analysis
66 uses: github/codeql-action/analyze@v4
67 with:
68 category: /language:${{ matrix.language }}
69
69 lines YAML