| 1 | # CodeQL advanced setup. |
| 2 | # |
| 3 | # Scans the same languages the repository's default setup scanned (Actions, |
| 4 | # JavaScript/TypeScript, Python, Rust) with the same default query suite, but |
| 5 | # reads .github/codeql/codeql-config.yml so test paths stay out of alerts. |
| 6 | # |
| 7 | # Gated off by default. While the repository uses CodeQL "Default" setup, |
| 8 | # GitHub rejects SARIF uploads from this workflow ("Code Scanning could not |
| 9 | # process the submitted SARIF"), so the analyze job runs only when the |
| 10 | # repository variable CODEQL_ADVANCED_SETUP is 'true'. The founder flips it |
| 11 | # after switching the repository to "Advanced" setup (Settings -> Code |
| 12 | # security -> Code scanning); until then every run skips the job. |
| 13 | name: CodeQL |
| 14 | |
| 15 | on: |
| 16 | push: |
| 17 | branches: [main] |
| 18 | pull_request: |
| 19 | branches: [main] |
| 20 | schedule: |
| 21 | # Weekly, Tuesday 04:17 UTC. |
| 22 | - cron: '17 4 * * 2' |
| 23 | workflow_dispatch: |
| 24 | |
| 25 | permissions: {} |
| 26 | |
| 27 | concurrency: |
| 28 | group: codeql-${{ github.ref }} |
| 29 | cancel-in-progress: ${{ github.event_name == 'pull_request' }} |
| 30 | |
| 31 | jobs: |
| 32 | analyze: |
| 33 | name: Analyze (${{ matrix.language }}) |
| 34 | if: vars.CODEQL_ADVANCED_SETUP == 'true' |
| 35 | runs-on: ubuntu-latest |
| 36 | timeout-minutes: 120 |
| 37 | permissions: |
| 38 | actions: read |
| 39 | contents: read |
| 40 | security-events: write |
| 41 | strategy: |
| 42 | fail-fast: false |
| 43 | matrix: |
| 44 | include: |
| 45 | - language: actions |
| 46 | build-mode: none |
| 47 | - language: javascript-typescript |
| 48 | build-mode: none |
| 49 | - language: python |
| 50 | build-mode: none |
| 51 | - language: rust |
| 52 | build-mode: none |
| 53 | steps: |
| 54 | - uses: actions/checkout@v7 |
| 55 | with: |
| 56 | persist-credentials: false |
| 57 | |
| 58 | - name: Initialize CodeQL |
| 59 | uses: github/codeql-action/init@v4 |
| 60 | with: |
| 61 | languages: ${{ matrix.language }} |
| 62 | build-mode: ${{ matrix.build-mode }} |
| 63 | config-file: ./.github/codeql/codeql-config.yml |
| 64 | |
| 65 | - name: Perform CodeQL analysis |
| 66 | uses: github/codeql-action/analyze@v4 |
| 67 | with: |
| 68 | category: /language:${{ matrix.language }} |
| 69 |