7
7
# The branches below must be a subset of the branches above
8
8
branches : [master]
9
9
schedule :
10
- - cron : ' 0 6 * * 4'
10
+ - cron : " 0 6 * * 4"
11
11
12
12
permissions :
13
13
contents : read
14
14
15
15
jobs :
16
16
analyze :
17
17
permissions :
18
- actions : read # for github/codeql-action/init to get workflow details
19
- contents : read # for actions/checkout to fetch code
20
- security-events : write # for github/codeql-action/autobuild to send a status report
18
+ actions : read # for github/codeql-action/init to get workflow details
19
+ contents : read # for actions/checkout to fetch code
20
+ security-events : write # for github/codeql-action/autobuild to send a status report
21
21
name : Analyze
22
22
runs-on : ubuntu-latest
23
23
@@ -26,48 +26,48 @@ jobs:
26
26
matrix :
27
27
# Override automatic language detection by changing the below list
28
28
# Supported options are ['csharp', 'cpp', 'go', 'java', 'javascript', 'python']
29
- language : [' python' ]
29
+ language : [" python" ]
30
30
# Learn more...
31
31
# https://docs.github.com/en/github/finding-security-vulnerabilities-and-errors-in-your-code/configuring-code-scanning#overriding-automatic-language-detection
32
32
33
33
steps :
34
- - name : Checkout repository
35
- uses : actions/checkout@v4
36
- with :
37
- # We must fetch at least the immediate parents so that if this is
38
- # a pull request then we can checkout the head.
39
- fetch-depth : 2
34
+ - name : Checkout repository
35
+ uses : actions/checkout@v4
36
+ with :
37
+ # We must fetch at least the immediate parents so that if this is
38
+ # a pull request then we can checkout the head.
39
+ fetch-depth : 2
40
40
41
- # If this run was triggered by a pull request event, then checkout
42
- # the head of the pull request instead of the merge commit.
43
- - run : git checkout HEAD^2
44
- if : ${{ github.event_name == 'pull_request' }}
41
+ # If this run was triggered by a pull request event, then checkout
42
+ # the head of the pull request instead of the merge commit.
43
+ - run : git checkout HEAD^2
44
+ if : ${{ github.event_name == 'pull_request' }}
45
45
46
- # Initializes the CodeQL tools for scanning.
47
- - name : Initialize CodeQL
48
- uses : github/codeql-action/init@v3
49
- with :
50
- languages : ${{ matrix.language }}
51
- # If you wish to specify custom queries, you can do so here or in a config file.
52
- # By default, queries listed here will override any specified in a config file.
53
- # Prefix the list here with "+" to use these queries and those in the config file.
54
- # queries: ./path/to/local/query, your-org/your-repo/queries@main
46
+ # Initializes the CodeQL tools for scanning.
47
+ - name : Initialize CodeQL
48
+ uses : github/codeql-action/init@v3
49
+ with :
50
+ languages : ${{ matrix.language }}
51
+ # If you wish to specify custom queries, you can do so here or in a config file.
52
+ # By default, queries listed here will override any specified in a config file.
53
+ # Prefix the list here with "+" to use these queries and those in the config file.
54
+ # queries: ./path/to/local/query, your-org/your-repo/queries@main
55
55
56
- # Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
57
- # If this step fails, then you should remove it and run the build manually (see below)
58
- - name : Autobuild
59
- uses : github/codeql-action/autobuild@v3
56
+ # Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
57
+ # If this step fails, then you should remove it and run the build manually (see below)
58
+ - name : Autobuild
59
+ uses : github/codeql-action/autobuild@v3
60
60
61
- # ℹ️ Command-line programs to run using the OS shell.
62
- # 📚 https://git.io/JvXDl
61
+ # ℹ️ Command-line programs to run using the OS shell.
62
+ # 📚 https://git.io/JvXDl
63
63
64
- # ✏️ If the Autobuild fails above, remove it and uncomment the following three lines
65
- # and modify them (or add more) to build your code if your project
66
- # uses a compiled language
64
+ # ✏️ If the Autobuild fails above, remove it and uncomment the following three lines
65
+ # and modify them (or add more) to build your code if your project
66
+ # uses a compiled language
67
67
68
- # - run: |
69
- # make bootstrap
70
- # make release
68
+ # - run: |
69
+ # make bootstrap
70
+ # make release
71
71
72
- - name : Perform CodeQL Analysis
73
- uses : github/codeql-action/analyze@v3
72
+ - name : Perform CodeQL Analysis
73
+ uses : github/codeql-action/analyze@v3
0 commit comments