1
- # For most projects, this workflow file will not need changing; you simply need
2
- # to commit it to your repository.
3
- #
4
- # You may wish to alter this file to override the set of languages analyzed,
5
- # or to provide custom queries or build logic.
6
- #
7
- # ******** NOTE ********
8
- # We have attempted to detect the languages in your repository. Please check
9
- # the `language` matrix defined below to confirm you have the correct set of
10
- # supported CodeQL languages.
11
- #
12
- name : " CodeQL"
1
+ name : CodeQL analysis
13
2
14
3
on :
15
4
push :
16
- branches : [ main, master ]
5
+ branches : [ main ]
17
6
pull_request :
18
- # The branches below must be a subset of the branches above
19
7
branches : [ main ]
20
8
schedule :
21
- - cron : ' 31 9 * * 0'
9
+ - cron : ' 0 3 * * 0'
22
10
23
11
jobs :
24
- analyze :
25
- name : Analyze
26
- runs-on : ubuntu-latest
27
- permissions :
28
- actions : read
29
- contents : read
30
- security-events : write
31
-
32
- strategy :
33
- fail-fast : false
34
- matrix :
35
- language : [ 'javascript' ]
36
- # CodeQL supports [ 'cpp', 'csharp', 'go', 'java', 'javascript', 'python', 'ruby' ]
37
- # Learn more about CodeQL language support at https://git.io/codeql-language-support
38
-
39
- steps :
40
- - name : Checkout repository
41
- uses : actions/checkout@v3
42
-
43
- # Initializes the CodeQL tools for scanning.
44
- - name : Initialize CodeQL
45
- uses : github/codeql-action/init@v1
46
- with :
47
- languages : ${{ matrix.language }}
48
- # If you wish to specify custom queries, you can do so here or in a config file.
49
- # By default, queries listed here will override any specified in a config file.
50
- # Prefix the list here with "+" to use these queries and those in the config file.
51
- # queries: ./path/to/local/query, your-org/your-repo/queries@main
52
-
53
- # Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
54
- # If this step fails, then you should remove it and run the build manually (see below)
55
- - name : Autobuild
56
- uses : github/codeql-action/autobuild@v1
57
-
58
- # ℹ️ Command-line programs to run using the OS shell.
59
- # 📚 https://git.io/JvXDl
60
-
61
- # ✏️ If the Autobuild fails above, remove it and uncomment the following three lines
62
- # and modify them (or add more) to build your code if your project
63
- # uses a compiled language
64
-
65
- # - run: |
66
- # make bootstrap
67
- # make release
68
-
69
- - name : Perform CodeQL Analysis
70
- uses : github/codeql-action/analyze@v1
12
+ call-codeQL-analysis :
13
+ name : CodeQL analysis
14
+ uses : actions/reusable-workflows/.github/workflows/codeql-analysis.yml@main
0 commit comments