Skip to content

build(deps): bump github/codeql-action/init from 4.38.1 to 4.38.2 #87

build(deps): bump github/codeql-action/init from 4.38.1 to 4.38.2

build(deps): bump github/codeql-action/init from 4.38.1 to 4.38.2 #87

Workflow file for this run

name: CodeQL
# CodeQL *default* setup never produced an analysis for pull requests from
# forks, so the `code_scanning` rule on `main` was unsatisfiable for external
# contributions and every one of them needed an admin override to merge (#69).
# A workflow in the repository does run for fork pull requests, so this
# advanced setup gives the required check to contributors and maintainers
# alike. Default setup is disabled; re-enabling it would make these uploads
# conflict.
on:
push:
branches: ["main"]
pull_request:
schedule:
# Keep the weekly sweep default setup used to run, so newly published
# queries reach `main` without waiting for the next push.
- cron: "27 4 * * 1"
permissions:
contents: read
concurrency:
group: codeql-${{ github.ref }}
# Superseded pull request runs are disposable; scheduled and `main` runs are
# the ones alerts are attributed to, so let those finish.
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
jobs:
analyze:
name: CodeQL (${{ matrix.language }})
runs-on: ubuntu-latest
permissions:
# Upload SARIF results to the code scanning API.
security-events: write
contents: read
actions: read
strategy:
fail-fast: false
matrix:
include:
# `none` keeps every analysis source-based, so no system packages, no
# gpui git checkout, and no full build per pull request.
- language: actions
build-mode: none
- language: javascript-typescript
build-mode: none
- language: rust
build-mode: none
steps:
- name: Checkout
uses: actions/checkout@v7
- name: Initialize CodeQL
uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}
# Matches the suite default setup was configured with.
queries: security-extended
- name: Analyze
uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1
with:
category: "/language:${{ matrix.language }}"