mirror of
				https://github.com/docker/login-action.git
				synced 2025-10-31 10:10:09 +08:00 
			
		
		
		
	introduce CodeQL to enable SAST scanning
Signed-off-by: CrazyMax <crazy-max@users.noreply.github.com> Signed-off-by: temenuzhka-thede <temenuzhka.thede@docker.com> Co-authored-by: CrazyMax <crazy-max@users.noreply.github.com>
This commit is contained in:
		
							parent
							
								
									b4bedf8053
								
							
						
					
					
						commit
						b96c2c0282
					
				
							
								
								
									
										47
									
								
								.github/workflows/codeql.yml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							
							
						
						
									
										47
									
								
								.github/workflows/codeql.yml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							| @ -0,0 +1,47 @@ | ||||
| name: codeql | ||||
| 
 | ||||
| on: | ||||
|   push: | ||||
|     branches: | ||||
|       - 'master' | ||||
|       - 'releases/v*' | ||||
|     paths: | ||||
|       - '.github/workflows/codeql.yml' | ||||
|       - 'dist/**' | ||||
|       - 'src/**' | ||||
|   pull_request: | ||||
|     paths: | ||||
|       - '.github/workflows/codeql.yml' | ||||
|       - 'dist/**' | ||||
|       - 'src/**' | ||||
| 
 | ||||
| permissions: | ||||
|   actions: read | ||||
|   contents: read | ||||
|   security-events: write | ||||
| 
 | ||||
| jobs: | ||||
|   analyze: | ||||
|     runs-on: ubuntu-latest | ||||
|     strategy: | ||||
|       fail-fast: false | ||||
|       matrix: | ||||
|         language: | ||||
|           - javascript-typescript | ||||
|     steps: | ||||
|       - | ||||
|         name: Checkout | ||||
|         uses: actions/checkout@v4 | ||||
|       - | ||||
|         name: Initialize CodeQL | ||||
|         uses: github/codeql-action/init@v2 | ||||
|         with: | ||||
|           languages: ${{ matrix.language }} | ||||
|       - | ||||
|         name: Autobuild | ||||
|         uses: github/codeql-action/autobuild@v2 | ||||
|       - | ||||
|         name: Perform CodeQL Analysis | ||||
|         uses: github/codeql-action/analyze@v2 | ||||
|         with: | ||||
|           category: "/language:${{matrix.language}}" | ||||
		Loading…
	
		Reference in New Issue
	
	Block a user
	 temenuzhka-thede
						temenuzhka-thede