From 63319afdd7c53d68f9acbc2866837ed28a5809c8 Mon Sep 17 00:00:00 2001 From: Nathan Shively-Sanders <293473+sandersn@users.noreply.github.com> Date: Mon, 28 Nov 2022 13:24:23 -0800 Subject: [PATCH 1/2] add codeql --- .github/codeql/codeql-configuration.yml | 4 +++ .github/workflows/codeql.yml | 33 +++++++++++++++++++++++++ 2 files changed, 37 insertions(+) create mode 100644 .github/codeql/codeql-configuration.yml create mode 100644 .github/workflows/codeql.yml diff --git a/.github/codeql/codeql-configuration.yml b/.github/codeql/codeql-configuration.yml new file mode 100644 index 0000000..402799f --- /dev/null +++ b/.github/codeql/codeql-configuration.yml @@ -0,0 +1,4 @@ +name : CodeQL Configuration + +paths: + - './src' diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml new file mode 100644 index 0000000..d908534 --- /dev/null +++ b/.github/workflows/codeql.yml @@ -0,0 +1,33 @@ +# copied from microsoft/TypeScript and simplified slightly; see that file for boilerplate commentary +# (which was likely copied from github/codeql-action) +name: "Code scanning - action" + +on: + push: + pull_request: + schedule: + - cron: '0 19 * * 0' + +jobs: + CodeQL-Build: + + runs-on: ubuntu-latest + + steps: + - name: Checkout repository + uses: actions/checkout@v3 + with: + # We must fetch at least the immediate parents so that if this is + # a pull request then we can checkout the head. + fetch-depth: 2 + + - name: Initialize CodeQL + uses: github/codeql-action/init@v2 + with: + config-file: ./.github/codeql/codeql-configuration.yml + + - name: Autobuild + uses: github/codeql-action/autobuild@v2 + + - name: Perform CodeQL Analysis + uses: github/codeql-action/analyze@v2 From 697f4303d14b7c96abefddfb9743f73aab9c8473 Mon Sep 17 00:00:00 2001 From: Nathan Shively-Sanders <293473+sandersn@users.noreply.github.com> Date: Tue, 29 Nov 2022 09:26:08 -0800 Subject: [PATCH 2/2] try paths: . --- .github/codeql/codeql-configuration.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/codeql/codeql-configuration.yml b/.github/codeql/codeql-configuration.yml index 402799f..136ad00 100644 --- a/.github/codeql/codeql-configuration.yml +++ b/.github/codeql/codeql-configuration.yml @@ -1,4 +1,4 @@ name : CodeQL Configuration paths: - - './src' + - '.'