Skip to content

chore(deps): update github/codeql-action action to v4.32.6 #657

chore(deps): update github/codeql-action action to v4.32.6

chore(deps): update github/codeql-action action to v4.32.6 #657

name: CodeQL Analysis
on:
push:
branches:
- main
pull_request:
branches:
- main
schedule:
- cron: "37 10 18 * *"
permissions: {}
jobs:
debug:
runs-on: ubuntu-latest
steps:
- name: Dump GitHub context
env:
GITHUB_CONTEXT: ${{ toJSON(github) }}
run: echo "$GITHUB_CONTEXT"
- name: Dump job context
env:
JOB_CONTEXT: ${{ toJSON(job) }}
run: echo "$JOB_CONTEXT"
- name: Dump steps context
env:
STEPS_CONTEXT: ${{ toJSON(steps) }}
run: echo "$STEPS_CONTEXT"
- name: Dump runner context
env:
RUNNER_CONTEXT: ${{ toJSON(runner) }}
run: echo "$RUNNER_CONTEXT"
- name: Dump strategy context
env:
STRATEGY_CONTEXT: ${{ toJSON(strategy) }}
run: echo "$STRATEGY_CONTEXT"
- name: Dump matrix context
env:
MATRIX_CONTEXT: ${{ toJSON(matrix) }}
run: echo "$MATRIX_CONTEXT"
- name: Dump environment variables
run: set
analyze:
name: Analyze
strategy:
fail-fast: false
matrix:
language:
- java-kotlin
- actions
runs-on: ${{ (matrix.language == 'swift' && 'macos-latest') || 'ubuntu-latest' }}
timeout-minutes: ${{ (matrix.language == 'swift' && 120) || 360 }}
permissions:
actions: read
contents: read
security-events: write
steps:
- name: Checkout repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false
- uses: actions/setup-java@be666c2fcd27ec809703dec50e508c2fdc7f6654 # v5.2.0
with:
cache: maven
distribution: temurin
java-version-file: .tool-versions
- name: Initialize CodeQL
uses: github/codeql-action/init@0d579ffd059c29b07949a3cce3983f0780820c98 # v4.32.6
with:
languages: ${{ matrix.language }}
- name: Autobuild
uses: github/codeql-action/autobuild@0d579ffd059c29b07949a3cce3983f0780820c98 # v4.32.6
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@0d579ffd059c29b07949a3cce3983f0780820c98 # v4.32.6
with:
category: "/language:${{matrix.language}}"
- name: Make sure build did not change anything
run: git diff --exit-code
required-status-check:
name: codeql-analysis.required-status-check
needs:
- analyze
# GitHub Actions skips this job when any of the dependents fail. And skips
# are considered success in their weird logic. So we always run it and fail
# ourselves if necessary
if: always()
runs-on: ubuntu-latest
steps:
- run: echo "Use this job as the required status check of this workflow"
- name: Check that all jobs were successful
env:
RESULTS: ${{ toJSON(needs) }}
run: |
echo "$RESULTS" | jq --exit-status 'all(.result == "success")' || exit 1