Skip to content

Commit

Permalink
Create codeql-analysis.yml (#1795)
Browse files Browse the repository at this point in the history
<!-- If this is your first pull request: sign the CLA with this GitHub
app: https://cla-assistant.io/renovatebot/renovate -->
<!-- Make sure the `Allow edits and access to secrets by maintainers`
checkbox is checked on this pull request. -->
<!-- Please read
https://github.com/renovatebot/renovate/blob/main/.github/contributing.md
before you create your pull request.-->

## Changes

<!-- Describe what behavior is changed by this PR. -->

## Context

<!-- Describe why you're making these changes if it's not already
explained in a corresponding issue. -->
<!-- If you're closing an existing issue with this pull request, use the
keyword Closes #issue_number. -->
<!-- If you're referencing an issue with this pull request, put it in a
Markdown list like this: - #issue_number. -->

## Documentation (please check one with an [x])

- [ ] I have updated the documentation, or
- [ ] No documentation update is required

## How I've tested my work (please select one)

I have verified these changes via:

- [ ] Code inspection only, or
- [ ] Newly added/modified unit tests, or
- [ ] No unit tests but ran on a real repository, or
- [ ] Both unit tests + ran on a real repository

<!-- Do you have any suggestions about this PR template? Edit it here:
https://github.com/renovatebot/renovate/edit/main/.github/pull_request_template.md
-->

<!-- Please do not force push to your PR's branch after you have created
your PR, as doing so forces us to review the whole PR again. This makes
it harder for us to review your work because we don't know what has
changed. -->
<!-- PRs will always be squashed by us when we merge your work. Commit
as many times as you need in this branch. -->
  • Loading branch information
FabianaCampanari authored Oct 18, 2024
2 parents 50f57b5 + b2e1db2 commit 18ca244
Showing 1 changed file with 42 additions and 0 deletions.
42 changes: 42 additions & 0 deletions .github/workflows/codeql-analysis.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
name: 'Code scanning'

on:
push:
branches: [main]
pull_request:
branches: [main]
types:
- opened
- synchronize
- reopened
- ready_for_review
schedule:
- cron: '0 13 * * 1'

concurrency:
group: ${{ github.workflow }}-${{ github.event.number || github.ref }}
cancel-in-progress: true

permissions:
contents: read

jobs:
CodeQL-Build:
runs-on: ubuntu-latest
if: github.event.pull_request.draft != true
permissions:
security-events: write
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Delete fixtures to suppress false positives
run: |
find ./lib -type d -name '__fixtures__' -exec rm -rf {} \; || true
- name: Initialize CodeQL
uses: github/codeql-action/init@v3
with:
languages: javascript
- name: Autobuild
uses: github/codeql-action/autobuild@v3
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v3

0 comments on commit 18ca244

Please sign in to comment.