mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-08-09 08:42:15 +03:00
32 lines
1.3 KiB
YAML
32 lines
1.3 KiB
YAML
name: CodeQL
|
|
# OWNER ACTION REQUIRED before enabling auto-triggers: advanced CodeQL conflicts with
|
|
# GitHub "default setup" — the analyze step fails with "CodeQL analyses from advanced
|
|
# configurations cannot be processed when the default setup is enabled". Switch repo
|
|
# Settings → Code security → CodeQL from Default to Advanced, THEN restore the
|
|
# push/pull_request/schedule triggers below. Until then this only runs on manual dispatch
|
|
# so it never produces a red check on PRs. (The codeqlAlerts ratchet keeps working via the
|
|
# default setup's alerts in the meantime.)
|
|
on:
|
|
workflow_dispatch:
|
|
permissions:
|
|
contents: read
|
|
jobs:
|
|
analyze:
|
|
name: Analyze (javascript-typescript)
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
security-events: write
|
|
actions: read
|
|
contents: read
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
- uses: github/codeql-action/init@f205ea1c3313d32999d8d6a48b4f6530d4437b38 # v4.37.4
|
|
with:
|
|
languages: javascript-typescript
|
|
queries: security-extended
|
|
- uses: github/codeql-action/analyze@f205ea1c3313d32999d8d6a48b4f6530d4437b38 # v4.37.4
|
|
with:
|
|
category: "/language:javascript-typescript"
|