Skip to content

Periodic CodeQL

Periodic CodeQL #6

Workflow file for this run

name: "Periodic CodeQL"
on:
schedule:
# Weekly scan so newly-disclosed query packs catch existing code.
- cron: "27 4 * * 1"
# Allow manual runs from the Actions tab in the GitHub UI.
workflow_dispatch:
permissions:
contents: read
jobs:
analyze:
name: Analyze (${{ matrix.language }})
runs-on: ubuntu-latest
permissions:
# Required to upload results to the GitHub code scanning dashboard.
security-events: write
# Required to read the repository contents.
contents: read
actions: read
strategy:
fail-fast: false
matrix:
include:
- language: csharp
build-mode: none
steps:
- name: Checkout repository
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- name: Initialize CodeQL
uses: github/codeql-action/init@54f647b7e1bb85c95cddabcd46b0c578ec92bc1a # v4.36.3
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}
# Run the standard plus security-extended query suite for deeper coverage.
queries: security-extended
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@54f647b7e1bb85c95cddabcd46b0c578ec92bc1a # v4.36.3
with:
category: "/language:${{ matrix.language }}"