-
Notifications
You must be signed in to change notification settings - Fork 0
27 lines (26 loc) · 1.64 KB
/
Copy pathcodeql.yml
File metadata and controls
27 lines (26 loc) · 1.64 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
# centralized-by: HereLiesAz/workflows
# central-source-path: .github/workflows/codeql.yml
# central-source-sha256: 6649c58e422ab9b7f0b9ffcd8063f5af06360d14d60d48a054e8668342379c1d
# This file intentionally contains no repository secrets.
# central-run-tracker: HereLiesAz/workflows
name: CodeQL Advanced
on:
push:
branches: ["main"]
pull_request:
branches: ["main"]
schedule:
- cron: '39 12 * * 1'
permissions: {}
jobs:
central:
name: Hand-off
runs-on: ubuntu-latest
timeout-minutes: 2
steps:
- name: Point to central result
env:
STATUS_CONTEXT: .github/workflows/codeql.yml
TARGET_SHA: ${{ github.event.pull_request.head.sha || github.sha }}
shell: bash
run: "set -euo pipefail\n# The build runs in HereLiesAz/workflows. Its result is reported on this commit as the\n# commit status named below: pending when the central run starts, then success or\n# failure. This job only points there and ends, so it never holds a runner while the\n# central run waits for one. (Trackers that followed the central run job-by-job held a\n# runner each for the whole build; under the account's concurrent-job limit they\n# starved the very runs they were waiting on: 2026-10-01, illumera waited 3h to start.)\n# No status at all means the gateway intentionally skipped this event.\n{\n echo \"### Runs in HereLiesAz/workflows\"\n echo\n echo \"Result: commit status \\`$STATUS_CONTEXT\\` on \\`$TARGET_SHA\\`.\"\n echo \"Central runs: $GITHUB_SERVER_URL/HereLiesAz/workflows/actions\"\n} >> \"$GITHUB_STEP_SUMMARY\"\necho \"Result is reported as commit status '$STATUS_CONTEXT' on $TARGET_SHA.\"\n"