codeql.yml 913 B

1234567891011121314151617181920212223242526272829303132333435363738394041424344
  1. name: "CodeQL"
  2. on:
  3. push:
  4. branches:
  5. - main
  6. - v4-dev
  7. - "!dependabot/**"
  8. pull_request:
  9. branches:
  10. - main
  11. - v4-dev
  12. - "!dependabot/**"
  13. schedule:
  14. - cron: "0 2 * * 4"
  15. workflow_dispatch:
  16. jobs:
  17. analyze:
  18. name: Analyze
  19. runs-on: ubuntu-latest
  20. permissions:
  21. security-events: write
  22. steps:
  23. - name: Checkout repository
  24. uses: actions/checkout@v4
  25. with:
  26. persist-credentials: false
  27. - name: Initialize CodeQL
  28. uses: github/codeql-action/init@v3
  29. with:
  30. config-file: ./.github/codeql/codeql-config.yml
  31. languages: "javascript"
  32. queries: +security-and-quality
  33. - name: Autobuild
  34. uses: github/codeql-action/autobuild@v3
  35. - name: Perform CodeQL Analysis
  36. uses: github/codeql-action/analyze@v3
  37. with:
  38. category: "/language:javascript"