Spaces:
Runtime error
Runtime error
| name: CodeQL | |
| # OWNER ACTION REQUIRED before enabling auto-triggers: advanced CodeQL conflicts with | |
| # GitHub "default setup" β the analyze step fails with "CodeQL analyses from advanced | |
| # configurations cannot be processed when the default setup is enabled". Switch repo | |
| # Settings β Code security β CodeQL from Default to Advanced, THEN restore the | |
| # push/pull_request/schedule triggers below. Until then this only runs on manual dispatch | |
| # so it never produces a red check on PRs. (The codeqlAlerts ratchet keeps working via the | |
| # default setup's alerts in the meantime.) | |
| on: | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| jobs: | |
| analyze: | |
| name: Analyze (javascript-typescript) | |
| runs-on: ubuntu-latest | |
| permissions: | |
| security-events: write | |
| actions: read | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| with: | |
| persist-credentials: false | |
| - uses: github/codeql-action/init@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2 | |
| with: | |
| languages: javascript-typescript | |
| queries: security-extended | |
| - uses: github/codeql-action/analyze@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2 | |
| with: | |
| category: "/language:javascript-typescript" | |