diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 36b306e470..02b49db9cf 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -1,41 +1,41 @@ - name: "CodeQL" +name: "CodeQL" # When to run the analysis on: - pull_request: - branches: [ "main" ] # Run on PRs to main - schedule: - - cron: '17 10 * * 1' # Weekly scan for new vulnerabilities + pull_request: + branches: ["main"] # Run on PRs to main + schedule: + - cron: "17 10 * * 1" # Weekly scan for new vulnerabilities jobs: - analyze: - name: Analyze - runs-on: ubuntu-latest - # Permissions needed by CodeQL - permissions: - actions: read # Read workflow - contents: read # Read code - security-events: write # Write security alerts + analyze: + name: Analyze + runs-on: ubuntu-latest + # Permissions needed by CodeQL + permissions: + actions: read # Read workflow + contents: read # Read code + security-events: write # Write security alerts - strategy: - fail-fast: false - matrix: - # Tell CodeQL what type of code to analyze - language: [ 'javascript-typescript' ] + strategy: + fail-fast: false + matrix: + # Tell CodeQL what type of code to analyze + language: ["javascript-typescript"] - steps: - # Get the code - - name: Checkout repository - uses: actions/checkout@v4 + steps: + # Get the code + - name: Checkout repository + uses: actions/checkout@v4 - # Set up CodeQL tools - - name: Initialize CodeQL - uses: github/codeql-action/init@v3 - with: - languages: ${{ matrix.language }} + # Set up CodeQL tools + - name: Initialize CodeQL + uses: github/codeql-action/init@v3 + with: + languages: ${{ matrix.language }} - # Run the actual analysis - - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@v3 - with: - category: "/language:${{matrix.language}}" \ No newline at end of file + # Run the actual analysis + - name: Perform CodeQL Analysis + uses: github/codeql-action/analyze@v3 + with: + category: "/language:${{matrix.language}}"