mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-07-31 04:12:10 +03:00
- zizmor ratchet (151→139, no regression): SHA-pin every action ref ADDED this cycle — codeql/dast-smoke/semgrep (3 new workflows) + trivy-action (docker-publish) + actions/cache (nightly-mutation). Pre-existing tag refs keep the repo convention. - test-masking: add config/quality/test-masking-allowlist.json + allowlist support in check-test-masking.mjs (exempts ONLY the net-assert-reduction signal; tautology/skip/ deletion still fire). Allowlists 2 verified-legitimate reductions: appearance-widget-settings-schema (#4033 removed showTokenSaverOnEndpoint field) and dashboard-shell-tabs (#3973 tabs→redirect refactor, asserts replaced). +4 gate tests.
32 lines
1.3 KiB
YAML
32 lines
1.3 KiB
YAML
name: CodeQL
|
|
# OWNER ACTION REQUIRED before enabling auto-triggers: advanced CodeQL conflicts with
|
|
# GitHub "default setup" — the analyze step fails with "CodeQL analyses from advanced
|
|
# configurations cannot be processed when the default setup is enabled". Switch repo
|
|
# Settings → Code security → CodeQL from Default to Advanced, THEN restore the
|
|
# push/pull_request/schedule triggers below. Until then this only runs on manual dispatch
|
|
# so it never produces a red check on PRs. (The codeqlAlerts ratchet keeps working via the
|
|
# default setup's alerts in the meantime.)
|
|
on:
|
|
workflow_dispatch:
|
|
permissions:
|
|
contents: read
|
|
jobs:
|
|
analyze:
|
|
name: Analyze (javascript-typescript)
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
security-events: write
|
|
actions: read
|
|
contents: read
|
|
steps:
|
|
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
|
|
with:
|
|
persist-credentials: false
|
|
- uses: github/codeql-action/init@dd903d2e4f5405488e5ef1422510ee31c8b32357 # v3
|
|
with:
|
|
languages: javascript-typescript
|
|
queries: security-extended
|
|
- uses: github/codeql-action/analyze@dd903d2e4f5405488e5ef1422510ee31c8b32357 # v3
|
|
with:
|
|
category: "/language:javascript-typescript"
|