diff --git a/.github/codeql/codeql-config.yml b/.github/codeql/codeql-config.yml new file mode 100644 index 0000000000..53e2d01ed7 --- /dev/null +++ b/.github/codeql/codeql-config.yml @@ -0,0 +1,6 @@ +name: Otari CodeQL + +paths-ignore: + # Both files are generated, so a fix here is lost on the next regeneration. + - 'web/src/client/schema.ts' + - 'web/src/routeTree.gen.ts' diff --git a/.github/workflows/otari-codeql.yml b/.github/workflows/otari-codeql.yml new file mode 100644 index 0000000000..053e035585 --- /dev/null +++ b/.github/workflows/otari-codeql.yml @@ -0,0 +1,53 @@ +name: Otari CodeQL + +# No path filter here, unlike the other workflows. +# A filter would let some pull requests skip the scan entirely. +on: + push: + branches: [ main ] + pull_request: + branches: [ main ] + schedule: + # Runs at 04:17 UTC every Monday. + # GitHub delays runs scheduled on the hour, so this one is not at 04:00. + - cron: '17 4 * * 1' + workflow_dispatch: + +concurrency: + # Cancel superseded PR scans, but let main and scheduled runs finish. + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: ${{ github.event_name == 'pull_request' }} + +permissions: + contents: read + +jobs: + analyze: + name: Analyze (${{ matrix.language }}) + runs-on: ubuntu-latest + + permissions: + security-events: write + + strategy: + fail-fast: false + matrix: + # javascript-typescript is one language, not two. + language: [ actions, javascript-typescript, python ] + + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + - name: Initialize CodeQL + uses: github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 + with: + languages: ${{ matrix.language }} + build-mode: none + config-file: .github/codeql/codeql-config.yml + + - name: Analyze + uses: github/codeql-action/analyze@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 + with: + category: '/language:${{ matrix.language }}'