Skip to content

[FEATURE] Add CodeQL.yml #5

@FrilLab

Description

@FrilLab

Problem

Resolve security issues caused by incorrect code

Proposed Solution

Add codeql.yml

Set up 'Advanced Security -> CodeQL analysis'

On 'Rules -> Require code scanning results'

Alternatives Considered

No response

Additional Context

name: CodeQL

on:
push:
branches:
- main

pull_request:
branches:
- main

permissions:
contents: read
security-events: write

jobs:
analyze:
name: Analyze


runs-on: ubuntu-latest

strategy:
  fail-fast: false

  matrix:
    language:
      - java-kotlin
      - javascript-typescript

steps:
  - name: Checkout Repository
    uses: actions/checkout@v4

  - name: Initialize CodeQL
    uses: github/codeql-action/init@v3
    with:
      languages: ${{ matrix.language }}

  - name: Autobuild
    uses: github/codeql-action/autobuild@v3

  - name: Perform Analysis
    uses: github/codeql-action/analyze@v3

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions