From b74c7c1ac605ad9cdd8055a0d4d03f80840bc114 Mon Sep 17 00:00:00 2001 From: Peter Wilson Date: Wed, 9 Sep 2026 10:23:38 +0100 Subject: [PATCH] ci: add CodeQL code scanning for Python, TypeScript, and Actions The repository has no static analysis for security defects. CodeQL is free for public repositories and reports findings into the Security tab. Use advanced setup (a workflow file) rather than the settings switch, so the configuration is versioned next to the rest of CI and can exclude generated files. The two committed generated files under web/src are ignored, because a fix applied there is lost on the next regeneration. Scans run on every push to main and every pull request, with no path filter. A filter would let some pull requests merge with no scan at all. Co-Authored-By: Claude Opus 5 (1M context) --- .github/codeql/codeql-config.yml | 6 ++++ .github/workflows/otari-codeql.yml | 53 ++++++++++++++++++++++++++++++ 2 files changed, 59 insertions(+) create mode 100644 .github/codeql/codeql-config.yml create mode 100644 .github/workflows/otari-codeql.yml diff --git a/.github/codeql/codeql-config.yml b/.github/codeql/codeql-config.yml new file mode 100644 index 0000000000..53e2d01ed7 --- /dev/null +++ b/.github/codeql/codeql-config.yml @@ -0,0 +1,6 @@ +name: Otari CodeQL + +paths-ignore: + # Both files are generated, so a fix here is lost on the next regeneration. + - 'web/src/client/schema.ts' + - 'web/src/routeTree.gen.ts' diff --git a/.github/workflows/otari-codeql.yml b/.github/workflows/otari-codeql.yml new file mode 100644 index 0000000000..053e035585 --- /dev/null +++ b/.github/workflows/otari-codeql.yml @@ -0,0 +1,53 @@ +name: Otari CodeQL + +# No path filter here, unlike the other workflows. +# A filter would let some pull requests skip the scan entirely. +on: + push: + branches: [ main ] + pull_request: + branches: [ main ] + schedule: + # Runs at 04:17 UTC every Monday. + # GitHub delays runs scheduled on the hour, so this one is not at 04:00. + - cron: '17 4 * * 1' + workflow_dispatch: + +concurrency: + # Cancel superseded PR scans, but let main and scheduled runs finish. + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: ${{ github.event_name == 'pull_request' }} + +permissions: + contents: read + +jobs: + analyze: + name: Analyze (${{ matrix.language }}) + runs-on: ubuntu-latest + + permissions: + security-events: write + + strategy: + fail-fast: false + matrix: + # javascript-typescript is one language, not two. + language: [ actions, javascript-typescript, python ] + + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + - name: Initialize CodeQL + uses: github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 + with: + languages: ${{ matrix.language }} + build-mode: none + config-file: .github/codeql/codeql-config.yml + + - name: Analyze + uses: github/codeql-action/analyze@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 + with: + category: '/language:${{ matrix.language }}'