aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorrugk <[email protected]>2021-01-26 16:37:53 +0100
committerGitHub <[email protected]>2021-01-26 16:37:53 +0100
commit156155663d0d2234d019fdd192ab0d508044f9af (patch)
tree5d473ec7b1baaae2669200b42b76dc8cf5744924
parentb38ebc503ea0843a5930b684eba5cbbdc057c90d (diff)
downloadprivatebin-codeql.tar.gz
privatebin-codeql.tar.bz2
privatebin-codeql.zip
Create codeql-analysis.ymlcodeql
Only supports JS for now. I've removed the build step, because welł… our JS is already "built".
-rw-r--r--.github/workflows/codeql-analysis.yml49
1 files changed, 49 insertions, 0 deletions
diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml
new file mode 100644
index 00000000..7a0b263a
--- /dev/null
+++ b/.github/workflows/codeql-analysis.yml
@@ -0,0 +1,49 @@
+# For most projects, this workflow file will not need changing; you simply need
+# to commit it to your repository.
+#
+# You may wish to alter this file to override the set of languages analyzed,
+# or to provide custom queries or build logic.
+#
+# ******** NOTE ********
+# Currently can only check JS.
+#
+name: "CodeQL"
+
+on:
+ push:
+ branches: [ master ]
+ pull_request:
+ # The branches below must be a subset of the branches above
+ branches: [ master ]
+ schedule:
+ - cron: '28 22 * * 5'
+
+jobs:
+ analyze:
+ name: Analyze
+ runs-on: ubuntu-latest
+
+ strategy:
+ fail-fast: false
+ matrix:
+ language: [ 'javascript' ]
+ # CodeQL supports [ 'cpp', 'csharp', 'go', 'java', 'javascript', 'python' ]
+ # Learn more:
+ # https://docs.github.com/en/[email protected]/github/finding-security-vulnerabilities-and-errors-in-your-code/configuring-code-scanning#changing-the-languages-that-are-analyzed
+
+ steps:
+ - name: Checkout repository
+ uses: actions/[email protected]
+
+ # Initializes the CodeQL tools for scanning.
+ - name: Initialize CodeQL
+ uses: github/codeql-action/ini[email protected]
+ with:
+ languages: ${{ matrix.language }}
+ # If you wish to specify custom queries, you can do so here or in a config file.
+ # By default, queries listed here will override any specified in a config file.
+ # Prefix the list here with "+" to use these queries and those in the config file.
+ # queries: ./path/to/local/query, your-org/your-repo/[email protected]
+
+ - name: Perform CodeQL Analysis
+ uses: github/codeql-action/[email protected]