🎖️GitЯра🎖️
.github/workflows/codeql.yml 9d7af544a45447be56c6447a8482eceec581067a (9d7af544) Text, 4.97 KB
T8b949e# For most projects, this workflow file will not need changing; you simply need
T8b949e# to commit it to your repository.
T8b949e#
T8b949e# You may wish to alter this file to override the set of languages analyzed,
T8b949e# or to provide custom queries or build logic.
T8b949e#
T8b949e# ******** NOTE ********
T8b949e# We have attempted to detect the languages in your repository. Please check
T8b949e# the `language` matrix defined below to confirm you have the correct set of
T8b949e# supported CodeQL languages.
T8b949e#
Tff7b72nameTb4b4b4: Ta5d6ff"Ta5d6ffCodeQLTe6edf3 Ta5d6ffAdvancedTa5d6ff"
Tff7b72onTb4b4b4:
T8b949e# push:
T8b949e# branches: [ "main" ]
T8b949e# pull_request:
T8b949e# branches: [ "main" ]
Tff7b72scheduleTb4b4b4:
Tb4b4b4- Tff7b72cronTb4b4b4: Ta5d6ff'Ta5d6ff0Te6edf3 Ta5d6ff0Te6edf3 Ta5d6ff*Te6edf3 Ta5d6ff*Te6edf3 Ta5d6ff0Ta5d6ff'
Tff7b72workflow_dispatchTb4b4b4:
Tff7b72jobsTb4b4b4:
Tff7b72analyzeTb4b4b4:
Tff7b72nameTb4b4b4: Ta5d6ffAnalyzeTa5d6ff Ta5d6ff(${{Ta5d6ff Ta5d6ffmatrix.languageTa5d6ff Ta5d6ff}})
T8b949e# Runner size impacts CodeQL analysis time. To learn more, please see:
T8b949e# - https://gh.io/recommended-hardware-resources-for-running-codeql
T8b949e# - https://gh.io/supported-runners-and-hardware-resources
T8b949e# - https://gh.io/using-larger-runners (GitHub.com only)
T8b949e# Consider using larger runners or machines with greater resources for possible analysis time improvements.
Tff7b72runs-onTb4b4b4: Ta5d6ff${{Ta5d6ff Ta5d6ff(matrix.languageTa5d6ff Ta5d6ff==Ta5d6ff Ta5d6ff'swift'Ta5d6ff Ta5d6ff&&Ta5d6ff Ta5d6ff'macos-latest')Ta5d6ff Ta5d6ff||Ta5d6ff Ta5d6ff'ubuntu-latest'Ta5d6ff Ta5d6ff}}
Tff7b72ifTb4b4b4: Ta5d6ffgithub.repositoryTa5d6ff Ta5d6ff==Ta5d6ff Ta5d6ff'meshtastic/Meshtastic-Android'
Tff7b72permissionsTb4b4b4:
T8b949e# required for all workflows
Tff7b72security-eventsTb4b4b4: Ta5d6ffwrite
T8b949e# required to fetch internal or private CodeQL packs
Tff7b72packagesTb4b4b4: Ta5d6ffread
T8b949e# only required for workflows in private repositories
Tff7b72actionsTb4b4b4: Ta5d6ffread
Tff7b72contentsTb4b4b4: Ta5d6ffread
Tff7b72strategyTb4b4b4:
Tff7b72fail-fastTb4b4b4: Ta5d6fffalse
Tff7b72matrixTb4b4b4:
Tff7b72includeTb4b4b4:
Tb4b4b4- Tff7b72languageTb4b4b4: Ta5d6ffactions
Tff7b72build-modeTb4b4b4: Ta5d6ffnone
Tb4b4b4- Tff7b72languageTb4b4b4: Ta5d6ffjava-kotlin
Tff7b72build-modeTb4b4b4: Ta5d6ffautobuild
T8b949e# CodeQL supports the following values keywords for 'language': 'actions', 'c-cpp', 'csharp', 'go', 'java-kotlin', 'javascript-typescript', 'python', 'ruby', 'swift'
T8b949e# Use `c-cpp` to analyze code written in C, C++ or both
T8b949e# Use 'java-kotlin' to analyze code written in Java, Kotlin or both
T8b949e# Use 'javascript-typescript' to analyze code written in JavaScript, TypeScript or both
T8b949e# To learn more about changing the languages that are analyzed or customizing the build mode for your analysis,
T8b949e# see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/customizing-your-advanced-setup-for-code-scanning.
T8b949e# If you are analyzing a compiled language, you can modify the 'build-mode' for that language to customize how
T8b949e# your codebase is analyzed, see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages
Tff7b72stepsTb4b4b4:
Tb4b4b4- Tff7b72nameTb4b4b4: Ta5d6ffCheckoutTa5d6ff Ta5d6ffrepository
Tff7b72usesTb4b4b4: Ta5d6ffactions/checkout@v6
T8b949e# Add any setup steps before running the `github/codeql-action/init` action.
T8b949e# This includes steps like installing compilers or runtimes (`actions/setup-node`
T8b949e# or others). This is typically only required for manual builds.
T8b949e# - name: Setup runtime (example)
T8b949e# uses: actions/setup-example@v1
Tb4b4b4- Tff7b72nameTb4b4b4: Ta5d6ffJavaTa5d6ff Ta5d6ffSetup
Tff7b72usesTb4b4b4: Ta5d6ffactions/setup-java@v5
Tff7b72withTb4b4b4:
Tff7b72distributionTb4b4b4: Ta5d6ff'Ta5d6fftemurinTa5d6ff' T8b949e# See 'Supported distributions' for available options
Tff7b72java-versionTb4b4b4: Ta5d6ff'Ta5d6ff17Ta5d6ff'
T8b949e# Initializes the CodeQL tools for scanning.
Tb4b4b4- Tff7b72nameTb4b4b4: Ta5d6ffInitializeTa5d6ff Ta5d6ffCodeQL
Tff7b72usesTb4b4b4: Ta5d6ffgithub/codeql-action/init@v4
Tff7b72withTb4b4b4:
Tff7b72languagesTb4b4b4: Ta5d6ff${{Ta5d6ff Ta5d6ffmatrix.languageTa5d6ff Ta5d6ff}}
Tff7b72build-modeTb4b4b4: Ta5d6ff${{Ta5d6ff Ta5d6ffmatrix.build-modeTa5d6ff Ta5d6ff}}
T8b949e# If you wish to specify custom queries, you can do so here or in a config file.
T8b949e# By default, queries listed here will override any specified in a config file.
T8b949e# Prefix the list here with "+" to use these queries and those in the config file.
T8b949e# For more details on CodeQL's query packs, refer to: https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/configuring-code-scanning#using-queries-in-ql-packs
T8b949e# queries: security-extended,security-and-quality
T8b949e# If the analyze step fails for one of the languages you are analyzing with
T8b949e# "We were unable to automatically build your code", modify the matrix above
T8b949e# to set the build mode to "manual" for that language. Then modify this step
T8b949e# to build your code.
T8b949e# ℹ️ Command-line programs to run using the OS shell.
T8b949e# 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun
Tb4b4b4- Tff7b72ifTb4b4b4: Ta5d6ffmatrix.build-modeTa5d6ff Ta5d6ff==Ta5d6ff Ta5d6ff'manual'
Tff7b72shellTb4b4b4: Ta5d6ffbash
Tff7b72runTb4b4b4: Tb4b4b4|
Tff7b72echo 'If you are using a "manual" build mode for one or more of the' \
Tff7b72'languages you are analyzing, replace this with the commands to build' \
Tff7b72'your code, for example:'
Tff7b72echo ' make bootstrap'
Tff7b72echo ' make release'
Tff7b72exit 1
Tb4b4b4- Tff7b72nameTb4b4b4: Ta5d6ffPerformTa5d6ff Ta5d6ffCodeQLTa5d6ff Ta5d6ffAnalysis
Tff7b72usesTb4b4b4: Ta5d6ffgithub/codeql-action/analyze@v4
Tff7b72withTb4b4b4:
Tff7b72categoryTb4b4b4: Ta5d6ff"Ta5d6ff/language:${{matrix.language}}Ta5d6ff"
Served by rngit 1.5.2 - Generated in 0.03s