1
- # For most projects, this workflow file will not need changing; you simply need
2
- # to commit it to your repository.
3
- #
4
- # You may wish to alter this file to override the set of languages analyzed,
5
- # or to provide custom queries or build logic.
6
- #
7
- # ******** NOTE ********
8
- # We have attempted to detect the languages in your repository. Please check
9
- # the `language` matrix defined below to confirm you have the correct set of
10
- # supported CodeQL languages.
11
- #
12
1
name : ' CodeQL'
13
2
14
3
on :
15
4
push :
16
5
branches : ['main']
17
6
pull_request :
18
- # The branches below must be a subset of the branches above
19
7
branches : ['main']
20
8
schedule :
21
9
- cron : ' 0 0 * * 1'
@@ -25,54 +13,4 @@ permissions:
25
13
26
14
jobs :
27
15
analyze :
28
- name : Analyze
29
- runs-on : ubuntu-latest
30
- permissions :
31
- actions : read
32
- contents : read
33
- security-events : write
34
-
35
- strategy :
36
- fail-fast : false
37
- matrix :
38
- language : ['javascript', 'typescript']
39
- # CodeQL supports [ $supported-codeql-languages ]
40
- # Learn more about CodeQL language support at https://aka.ms/codeql-docs/language-support
41
-
42
- steps :
43
- - name : Harden Runner
44
- uses : step-security/harden-runner@ec9f2d5744a09debf3a187a3f4f675c53b671911 # v2.13.0
45
- with :
46
- egress-policy : audit
47
-
48
- - name : Checkout repository
49
- uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
50
-
51
- # Initializes the CodeQL tools for scanning.
52
- - name : Initialize CodeQL
53
- uses : github/codeql-action/init@181d5eefc20863364f96762470ba6f862bdef56b # v3.29.2
54
- with :
55
- languages : ${{ matrix.language }}
56
- # If you wish to specify custom queries, you can do so here or in a config file.
57
- # By default, queries listed here will override any specified in a config file.
58
- # Prefix the list here with "+" to use these queries and those in the config file.
59
-
60
- # Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
61
- # If this step fails, then you should remove it and run the build manually (see below)
62
- - name : Autobuild
63
- uses : github/codeql-action/autobuild@181d5eefc20863364f96762470ba6f862bdef56b # v3.29.2
64
-
65
- # ℹ️ Command-line programs to run using the OS shell.
66
- # 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun
67
-
68
- # If the Autobuild fails above, remove it and uncomment the following three lines.
69
- # modify them (or add more) to build your code if your project, please refer to the EXAMPLE below for guidance.
70
-
71
- # - run: |
72
- # echo "Run, Build Application using script"
73
- # ./location_of_script_within_repo/buildscript.sh
74
-
75
- - name : Perform CodeQL Analysis
76
- uses : github/codeql-action/analyze@181d5eefc20863364f96762470ba6f862bdef56b # v3.29.2
77
- with :
78
- category : ' /language:${{matrix.language}}'
16
+ uses : nodejs/web-team/.github/workflows/codeql.yml
0 commit comments