@@ -24,27 +24,34 @@ jobs:
24
24
- name : Initialize CodeQL
25
25
uses : github/codeql-action/init@v3
26
26
with :
27
- languages : javascript # Adjust based on your project (e.g., python, java, csharp, go)
27
+ languages : javascript # Change to match your repo (e.g., python, java, csharp, go)
28
28
29
29
- name : Run CodeQL Custom Queries
30
30
uses : github/codeql-action/analyze@v3
31
31
with :
32
32
category : " custom-query"
33
33
queries : .github/queries
34
34
35
- - name : Verify SARIF File Exists
36
- run : ls -la .github/results
35
+ # ✅ Debug Step: Check if CodeQL Generated Results
36
+ - name : List files in the workspace
37
+ run : ls -la
37
38
39
+ - name : List files in the results directory
40
+ run : ls -la ./results || echo "Results directory not found!"
41
+
42
+ # ✅ Fix: Correct SARIF File Path for Upload
38
43
- name : Upload CodeQL SARIF Results
39
44
uses : actions/upload-artifact@v4
40
45
with :
41
46
name : codeql-custom-results
42
- path : .github /results/security-results .sarif
47
+ path : ./results/* .sarif # Ensure we are looking for SARIF files in the correct location
43
48
49
+ # ✅ Upload SARIF to GitHub Security Alerts
44
50
- name : Upload SARIF to GitHub Security Tab
45
51
uses : github/codeql-action/upload-sarif@v3
46
52
with :
47
- sarif_file : .github/results/results/security-results.sarif
53
+ sarif_file : ./results/*.sarif # Ensure correct path
54
+
48
55
49
56
50
57
0 commit comments