mirror of
				https://github.com/docker/login-action.git
				synced 2025-10-31 01:40:11 +08:00 
			
		
		
		
	Merge pull request #622 from temenuzhka-thede/tthede
Introduce codeql.yml to enable SAST scanning
This commit is contained in:
		
						commit
						495b903b08
					
				
							
								
								
									
										47
									
								
								.github/workflows/codeql.yml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							
							
						
						
									
										47
									
								
								.github/workflows/codeql.yml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							| @ -0,0 +1,47 @@ | |||||||
|  | name: codeql | ||||||
|  | 
 | ||||||
|  | on: | ||||||
|  |   push: | ||||||
|  |     branches: | ||||||
|  |       - 'master' | ||||||
|  |       - 'releases/v*' | ||||||
|  |     paths: | ||||||
|  |       - '.github/workflows/codeql.yml' | ||||||
|  |       - 'dist/**' | ||||||
|  |       - 'src/**' | ||||||
|  |   pull_request: | ||||||
|  |     paths: | ||||||
|  |       - '.github/workflows/codeql.yml' | ||||||
|  |       - 'dist/**' | ||||||
|  |       - 'src/**' | ||||||
|  | 
 | ||||||
|  | permissions: | ||||||
|  |   actions: read | ||||||
|  |   contents: read | ||||||
|  |   security-events: write | ||||||
|  | 
 | ||||||
|  | jobs: | ||||||
|  |   analyze: | ||||||
|  |     runs-on: ubuntu-latest | ||||||
|  |     strategy: | ||||||
|  |       fail-fast: false | ||||||
|  |       matrix: | ||||||
|  |         language: | ||||||
|  |           - javascript-typescript | ||||||
|  |     steps: | ||||||
|  |       - | ||||||
|  |         name: Checkout | ||||||
|  |         uses: actions/checkout@v4 | ||||||
|  |       - | ||||||
|  |         name: Initialize CodeQL | ||||||
|  |         uses: github/codeql-action/init@v2 | ||||||
|  |         with: | ||||||
|  |           languages: ${{ matrix.language }} | ||||||
|  |       - | ||||||
|  |         name: Autobuild | ||||||
|  |         uses: github/codeql-action/autobuild@v2 | ||||||
|  |       - | ||||||
|  |         name: Perform CodeQL Analysis | ||||||
|  |         uses: github/codeql-action/analyze@v2 | ||||||
|  |         with: | ||||||
|  |           category: "/language:${{matrix.language}}" | ||||||
		Loading…
	
		Reference in New Issue
	
	Block a user
	 CrazyMax
						CrazyMax