codeql #15
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # codeql.yml — CodeQL advanced setup, query suite "security-extended". | |
| # Check name: "Analyze (python)". | |
| # | |
| # IMPORTANT (METHOD §7): this workflow only RUNS the analysis and uploads alerts. | |
| # A green "Analyze (python)" means "CodeQL ran", never "nothing serious found". | |
| # The merge content-gate ("block if an alert >= threshold sits in the PR diff") | |
| # is a code_scanning rule of a ruleset — LAYER B — created with `gh api` at | |
| # bootstrap, not a file here. Do NOT enable the default setup as well: advanced | |
| # and default setups are mutually exclusive. | |
| name: codeql | |
| on: | |
| pull_request: | |
| push: | |
| branches: [main] | |
| schedule: | |
| - cron: "0 6 * * 1" # weekly, Monday 06:00 UTC | |
| jobs: | |
| analyze: | |
| name: Analyze | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| security-events: write # required to upload CodeQL results | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| language: ["python"] | |
| steps: | |
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| - uses: github/codeql-action/init@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2 | |
| with: | |
| languages: ${{ matrix.language }} | |
| queries: security-extended | |
| - uses: github/codeql-action/analyze@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2 | |
| with: | |
| category: "/language:${{ matrix.language }}" |