Skip to content

Production-readiness pass: security hardening, esbuild bundle, narrowed activation #2

Production-readiness pass: security hardening, esbuild bundle, narrowed activation

Production-readiness pass: security hardening, esbuild bundle, narrowed activation #2

Workflow file for this run

name: CodeQL
# Static analysis for the TypeScript client. Runs on every push to
# main, every PR, and weekly to catch advisories that land between
# code changes. Findings surface under the repo's Security tab.
on:
push:
branches: [main]
pull_request:
branches: [main]
schedule:
- cron: '23 4 * * 1'
permissions:
contents: read
security-events: write
actions: read
jobs:
analyze:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: github/codeql-action/init@v3
with:
languages: javascript-typescript
queries: security-extended
- uses: github/codeql-action/analyze@v3
with:
category: '/language:javascript-typescript'