diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 7a103ce8a..87d90e6a6 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -1,4 +1,4 @@ -name: CodeQL +name: CodeQL new on: push: @@ -11,7 +11,7 @@ on: jobs: analyze: - name: Analyze + name: Analyze (${{ matrix.language }}) runs-on: ubuntu-latest permissions: actions: read @@ -21,13 +21,20 @@ jobs: strategy: fail-fast: false matrix: - language: [ 'go' ] + include: + - language: actions + build-mode: none + queries: security-extended # can be 'default' (use empty for 'default'), 'security-and-quality', 'security-extended' + - language: go + build-mode: autobuild + queries: '' # will be used 'default' queries steps: - name: Checkout repository uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 - uses: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00 # v6.0.0 + if: matrix.language == 'go' with: go-version-file: 'go.mod' cache: true @@ -37,6 +44,8 @@ jobs: uses: github/codeql-action/init@4e94bd11f71e507f7f87df81788dff88d1dacbfb # v4.31.0 with: languages: ${{ matrix.language }} + build-mode: ${{ matrix['build-mode'] }} + queries: ${{ matrix.queries }} - name: Autobuild uses: github/codeql-action/autobuild@4e94bd11f71e507f7f87df81788dff88d1dacbfb # v4.31.0