name: CodeQL on: merge_group: pull_request: types: - opened - synchronize push: branches: - master schedule: - cron: '37 10 * * 2' permissions: actions: read contents: read security-events: write concurrency: group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} cancel-in-progress: ${{ github.ref != 'refs/heads/master' }} jobs: analyze: name: Check for Vulnerabilities runs-on: ubuntu-latest strategy: fail-fast: false matrix: language: [javascript] steps: - if: github.actor == 'dependabot[bot]' || github.event_name == 'merge_group' run: exit 0 # Skip unnecessary test runs for dependabot and merge queues. Artifically flag as successful, as this is a required check for branch protection. - name: Checkout uses: actions/checkout@v4 - name: Initialize CodeQL uses: github/codeql-action/init@v2 with: languages: ${{ matrix.language }} queries: +security-and-quality - name: Autobuild uses: github/codeql-action/autobuild@v2 - name: Perform CodeQL Analysis uses: github/codeql-action/analyze@v2 with: category: '/language:${{ matrix.language }}'