1- # For most projects, this workflow file will not need changing; you simply need
2- # to commit it to your repository.
3- #
4- # You may wish to alter this file to override the set of languages analyzed,
5- # or to provide custom queries or build logic.
6- #
7- # ******** NOTE ********
8- # We have attempted to detect the languages in your repository. Please check
9- # the `language` matrix defined below to confirm you have the correct set of
10- # supported CodeQL languages.
11- #
121name : " CodeQL"
132
143on :
154 push :
165 branches : [ master ]
176 pull_request :
18- # The branches below must be a subset of the branches above
197 branches : [ master ]
208 schedule :
219 - cron : ' 29 8 * * 5'
2412 analyze :
2513 name : Analyze
2614 runs-on : ubuntu-latest
15+ timeout-minutes : 360
2716 permissions :
2817 actions : read
2918 contents : read
@@ -32,40 +21,22 @@ jobs:
3221 strategy :
3322 fail-fast : false
3423 matrix :
35- language : [ 'javascript' ]
36- # CodeQL supports [ 'cpp', 'csharp', 'go', 'java', 'javascript', 'python' ]
37- # Learn more:
38- # https://docs.github.com/en/free-pro-team@latest/github/finding-security-vulnerabilities-and-errors-in-your-code/configuring-code-scanning#changing-the-languages-that-are-analyzed
24+ language : [ 'javascript-typescript' ]
3925
4026 steps :
4127 - name : Checkout repository
42- uses : actions/checkout@v2
28+ uses : actions/checkout@v4
4329
44- # Initializes the CodeQL tools for scanning.
4530 - name : Initialize CodeQL
46- uses : github/codeql-action/init@v1
31+ uses : github/codeql-action/init@v3
4732 with :
4833 languages : ${{ matrix.language }}
49- # If you wish to specify custom queries, you can do so here or in a config file.
50- # By default, queries listed here will override any specified in a config file.
51- # Prefix the list here with "+" to use these queries and those in the config file.
52- # queries: ./path/to/local/query, your-org/your-repo/queries@main
34+ queries : security-extended,security-and-quality
5335
54- # Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
55- # If this step fails, then you should remove it and run the build manually (see below)
5636 - name : Autobuild
57- uses : github/codeql-action/autobuild@v1
58-
59- # ℹ️ Command-line programs to run using the OS shell.
60- # 📚 https://git.io/JvXDl
61-
62- # ✏️ If the Autobuild fails above, remove it and uncomment the following three lines
63- # and modify them (or add more) to build your code if your project
64- # uses a compiled language
65-
66- # - run: |
67- # make bootstrap
68- # make release
37+ uses : github/codeql-action/autobuild@v3
6938
7039 - name : Perform CodeQL Analysis
71- uses : github/codeql-action/analyze@v1
40+ uses : github/codeql-action/analyze@v3
41+ with :
42+ category : " /language:${{matrix.language}}"
0 commit comments