From ebcd27e1b395ff7a46907e642ed2ddda9c1ab2fb Mon Sep 17 00:00:00 2001 From: shati-patel <42641846+shati-patel@users.noreply.github.com> Date: Fri, 28 May 2021 10:14:21 +0100 Subject: [PATCH] Placeholder codeql workflow (wip) --- .github/workflows/codeql-analysis.yml | 55 +++++++++++++++++++++++++++ 1 file changed, 55 insertions(+) create mode 100644 .github/workflows/codeql-analysis.yml diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml new file mode 100644 index 00000000000..7e35e2d5ac4 --- /dev/null +++ b/.github/workflows/codeql-analysis.yml @@ -0,0 +1,55 @@ +name: "CodeQL action" + +on: + push: + branches: [main] + pull_request: + branches: [main] + schedule: + - cron: "15 0 * * 2" + workflow_dispatch: + +jobs: + prepare: + runs-on: ubuntu-latest + steps: + - name: Checkout repository + uses: actions/checkout@v2 + + - uses: actions/cache@v2 + with: + path: | + ~/.cargo/registry + ~/.cargo/git + target + key: ${{ runner.os }}-qltest-cargo-${{ hashFiles('**/Cargo.lock') }} + + - name: Build Extractor + run: ./create-extractor-pack.sh +# TODO + +# analyze: +# name: Analyze +# runs-on: ubuntu-latest +# permissions: +# actions: read +# contents: read +# security-events: write +# +# strategy: +# fail-fast: false +# matrix: +# language: ["ql"] +# +# steps: +# - name: Initialize CodeQL +# uses: github/codeql-action/init@v1 +# with: +# languages: ${{ matrix.language }} +# tools: extractor-pack +# +# - name: Autobuild +# uses: github/codeql-action/autobuild@v1 +# +# - name: Perform CodeQL Analysis +# uses: github/codeql-action/analyze@v1