@@ -13,12 +13,16 @@ name: "CodeQL"
13
13
14
14
on :
15
15
push :
16
- branches : [ main ]
16
+ branches :
17
+ - main
18
+ - " *-dev"
17
19
pull_request :
18
20
# The branches below must be a subset of the branches above
19
- branches : [ main ]
21
+ branches :
22
+ - main
23
+ - " *-dev"
20
24
schedule :
21
- - cron : ' 34 21 * * 6'
25
+ - cron : " 34 21 * * 6"
22
26
23
27
jobs :
24
28
analyze :
@@ -32,40 +36,40 @@ jobs:
32
36
strategy :
33
37
fail-fast : false
34
38
matrix :
35
- language : [ 'go' ]
39
+ language : ["go" ]
36
40
# CodeQL supports [ 'cpp', 'csharp', 'go', 'java', 'javascript', 'python' ]
37
41
# Learn more:
38
42
# https://docs.github.com/en/free-pro-team@latest/github/finding-security-vulnerabilities-and-errors-in-your-code/configuring-code-scanning#changing-the-languages-that-are-analyzed
39
43
40
44
steps :
41
- - name : Checkout repository
42
- uses : actions/checkout@v3
45
+ - name : Checkout repository
46
+ uses : actions/checkout@v4
43
47
44
- # Initializes the CodeQL tools for scanning.
45
- - name : Initialize CodeQL
46
- uses : github/codeql-action/init@v2
47
- with :
48
- languages : ${{ matrix.language }}
49
- # If you wish to specify custom queries, you can do so here or in a config file.
50
- # By default, queries listed here will override any specified in a config file.
51
- # Prefix the list here with "+" to use these queries and those in the config file.
52
- # queries: ./path/to/local/query, your-org/your-repo/queries@main
48
+ # Initializes the CodeQL tools for scanning.
49
+ - name : Initialize CodeQL
50
+ uses : github/codeql-action/init@v3
51
+ with :
52
+ languages : ${{ matrix.language }}
53
+ # If you wish to specify custom queries, you can do so here or in a config file.
54
+ # By default, queries listed here will override any specified in a config file.
55
+ # Prefix the list here with "+" to use these queries and those in the config file.
56
+ # queries: ./path/to/local/query, your-org/your-repo/queries@main
53
57
54
- # Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
55
- # If this step fails, then you should remove it and run the build manually (see below)
56
- - name : Autobuild
57
- uses : github/codeql-action/autobuild@v2
58
+ # Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
59
+ # If this step fails, then you should remove it and run the build manually (see below)
60
+ - name : Autobuild
61
+ uses : github/codeql-action/autobuild@v3
58
62
59
- # ℹ️ Command-line programs to run using the OS shell.
60
- # 📚 https://git.io/JvXDl
63
+ # ℹ️ Command-line programs to run using the OS shell.
64
+ # 📚 https://git.io/JvXDl
61
65
62
- # ✏️ If the Autobuild fails above, remove it and uncomment the following three lines
63
- # and modify them (or add more) to build your code if your project
64
- # uses a compiled language
66
+ # ✏️ If the Autobuild fails above, remove it and uncomment the following three lines
67
+ # and modify them (or add more) to build your code if your project
68
+ # uses a compiled language
65
69
66
- # - run: |
67
- # make bootstrap
68
- # make release
70
+ # - run: |
71
+ # make bootstrap
72
+ # make release
69
73
70
- - name : Perform CodeQL Analysis
71
- uses : github/codeql-action/analyze@v2
74
+ - name : Perform CodeQL Analysis
75
+ uses : github/codeql-action/analyze@v3
0 commit comments