-
Notifications
You must be signed in to change notification settings - Fork 1
31 lines (29 loc) · 1.15 KB
/
Copy pathcodeql.yml
File metadata and controls
31 lines (29 loc) · 1.15 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
name: CodeQL
# Static security analysis. NOTE: uploading results to the Security tab requires a
# PUBLIC repo (or GitHub Advanced Security). The job below is guarded on repo
# visibility, so while the repo is private it is SKIPPED (neutral, not red) and it
# self-activates the moment the repo is made public — no edit needed at flip time.
on:
pull_request:
push:
branches: [main]
schedule:
- cron: '0 6 * * 1' # Mondays 06:00 UTC
jobs:
analyze:
name: analyze (javascript-typescript)
if: github.event.repository.visibility == 'public'
runs-on: ubuntu-latest
permissions:
security-events: write
actions: read
contents: read
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: github/codeql-action/init@f205ea1c3313d32999d8d6a48b4f6530d4437b38 # v4.37.4
with:
languages: javascript-typescript
- uses: github/codeql-action/autobuild@f205ea1c3313d32999d8d6a48b4f6530d4437b38 # v4.37.4
- uses: github/codeql-action/analyze@f205ea1c3313d32999d8d6a48b4f6530d4437b38 # v4.37.4
with:
category: '/language:javascript-typescript'