Skip to content

Commit 326f794

Browse files
authored
chore(ci): merge in codeql.yml and mark as requirement for ci-success (#331)
avoids separate notifications / mark as condition for success
1 parent f5c9c8a commit 326f794

File tree

2 files changed

+29
-49
lines changed

2 files changed

+29
-49
lines changed

.github/workflows/ci.yml

Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -147,6 +147,34 @@ jobs:
147147
permissions:
148148
contents: read
149149

150+
codeql:
151+
name: Analyze (${{ matrix.language }})
152+
runs-on: ubuntu-latest
153+
permissions:
154+
security-events: write
155+
actions: read
156+
contents: read
157+
strategy:
158+
fail-fast: false
159+
matrix:
160+
include:
161+
- language: actions
162+
build-mode: none
163+
steps:
164+
- name: Checkout repository
165+
uses: actions/checkout@v5
166+
with:
167+
persist-credentials: false
168+
- name: Initialize CodeQL
169+
uses: github/codeql-action/init@v3
170+
with:
171+
languages: ${{ matrix.language }}
172+
build-mode: ${{ matrix.build-mode }}
173+
- name: Perform CodeQL Analysis
174+
uses: github/codeql-action/analyze@v3
175+
with:
176+
category: "/language:${{matrix.language}}"
177+
150178
ci-success:
151179
runs-on: ubuntu-latest
152180
if: always()
@@ -159,6 +187,7 @@ jobs:
159187
- docs
160188
- fmt
161189
- deny
190+
- codeql
162191
timeout-minutes: 30
163192
steps:
164193
- name: Decide whether the needed jobs succeeded or failed

.github/workflows/codeql.yml

Lines changed: 0 additions & 49 deletions
This file was deleted.

0 commit comments

Comments
 (0)