1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950 |
- name: codeql
- on:
- # Trigger the workflow on push or pull requests, but only for the
- # master branch
- push:
- branches:
- - master
- - '*/ci'
- pull_request:
- branches:
- - master
- schedule:
- - cron: '0 0 * * 4'
- permissions:
- security-events: write
- jobs:
- codeql:
- runs-on: ubuntu-latest
- steps:
- - name: Checkout repository
- uses: actions/checkout@v2
- # Initializes the CodeQL tools for scanning.
- - name: Initialize CodeQL
- uses: github/codeql-action/init@v1
- with:
- languages: cpp
- queries: security-extended
- # Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
- # If this step fails, then you should remove it and run the build manually (see below)
- - name: Autobuild
- uses: github/codeql-action/autobuild@v1
- # ℹ️ Command-line programs to run using the OS shell.
- # 📚 https://git.io/JvXDl
- # ✏️ If the Autobuild fails above, remove it and uncomment the following three lines
- # and modify them (or add more) to build your code if your project
- # uses a compiled language
- #- run: |
- # make bootstrap
- # make release
- - name: Perform CodeQL Analysis
- uses: github/codeql-action/analyze@v1
|