Commit 9dfd23d63a015e81f7504be18089a659527b12e2

Authored by Perry Werneck
1 parent a43ac115
Exists in master and in 1 other branch develop

Adding CodeQL workflow.

.github/workflows/codeql-analysis.yml
@@ -1,78 +0,0 @@ @@ -1,78 +0,0 @@
1 -# For most projects, this workflow file will not need changing; you simply need  
2 -# to commit it to your repository.  
3 -#  
4 -# You may wish to alter this file to override the set of languages analyzed,  
5 -# or to provide custom queries or build logic.  
6 -name: "CodeQL"  
7 -  
8 -on:  
9 - push:  
10 - branches: [master]  
11 - pull_request:  
12 - # The branches below must be a subset of the branches above  
13 - branches: [master]  
14 - schedule:  
15 - - cron: '0 17 * * 0'  
16 -  
17 -jobs:  
18 - analyze:  
19 - name: Analyze  
20 - runs-on: ubuntu-latest  
21 -  
22 - strategy:  
23 - fail-fast: false  
24 - matrix:  
25 - # Override automatic language detection by changing the below list  
26 - # Supported options are ['csharp', 'cpp', 'go', 'java', 'javascript', 'python']  
27 - language: ['cpp']  
28 - # Learn more...  
29 - # https://docs.github.com/en/github/finding-security-vulnerabilities-and-errors-in-your-code/configuring-code-scanning#overriding-automatic-language-detection  
30 -  
31 - steps:  
32 - - name: Checkout repository  
33 - uses: actions/checkout@v2  
34 - with:  
35 - # We must fetch at least the immediate parents so that if this is  
36 - # a pull request then we can checkout the head.  
37 - fetch-depth: 2  
38 -  
39 - # If this run was triggered by a pull request event, then checkout  
40 - # the head of the pull request instead of the merge commit.  
41 - # - run: git checkout HEAD^2  
42 - # if: ${{ github.event_name == 'pull_request' }}  
43 -  
44 - # Initializes the CodeQL tools for scanning.  
45 - - name: Initialize CodeQL  
46 - uses: github/codeql-action/init@v1  
47 - with:  
48 - languages: ${{ matrix.language }}  
49 - # If you wish to specify custom queries, you can do so here or in a config file.  
50 - # By default, queries listed here will override any specified in a config file.  
51 - # Prefix the list here with "+" to use these queries and those in the config file.  
52 - # queries: ./path/to/local/query, your-org/your-repo/queries@main  
53 -  
54 - # Autobuild attempts to build any compiled languages (C/C++, C#, or Java).  
55 - # If this step fails, then you should remove it and run the build manually (see below)  
56 - #- name: Autobuild  
57 - # uses: github/codeql-action/autobuild@v1  
58 -  
59 - # ℹ️ Command-line programs to run using the OS shell.  
60 - # 📚 https://git.io/JvXDl  
61 -  
62 - # ✏️ If the Autobuild fails above, remove it and uncomment the following three lines  
63 - # and modify them (or add more) to build your code if your project  
64 - # uses a compiled language  
65 - #- name: Install Dependencies  
66 - #- run: apt-get install gettext libssl-dev libcurl4-openssl-dev  
67 -  
68 - #- run: |  
69 - # make bootstrap  
70 - # make release  
71 - - name: build  
72 - run: |  
73 - sudo apt-get install gettext libssl-dev libcurl4-openssl-dev  
74 - ./autogen.sh  
75 - make Release  
76 -  
77 - - name: Perform CodeQL Analysis  
78 - uses: github/codeql-action/analyze@v1  
.github/workflows/codeql.yml 0 → 100644
@@ -0,0 +1,42 @@ @@ -0,0 +1,42 @@
  1 +---
  2 +name: CodeQL
  3 +on:
  4 + push:
  5 + branches:
  6 + - master
  7 + pull_request:
  8 + branches:
  9 + - master
  10 + schedule:
  11 + - cron: 48 7 * * 1
  12 +jobs:
  13 + analyze:
  14 + name: Analyze
  15 + runs-on: ubuntu-latest
  16 + permissions:
  17 + actions: read
  18 + contents: read
  19 + security-events: write
  20 + strategy:
  21 + fail-fast: false
  22 + matrix:
  23 + language:
  24 + - cpp
  25 + steps:
  26 + - name: Checkout
  27 + uses: actions/checkout@v3
  28 + - name: Install Packages
  29 + run: |
  30 + sudo apt-get update
  31 + sudo apt-get install --yes gettext libssl-dev libcurl4-openssl-dev
  32 + - name: Initialize CodeQL
  33 + uses: github/codeql-action/init@v2
  34 + with:
  35 + languages: ${{ matrix.language }}
  36 + queries: +security-and-quality
  37 + - name: Autobuild
  38 + uses: github/codeql-action/autobuild@v2
  39 + - name: Perform CodeQL Analysis
  40 + uses: github/codeql-action/analyze@v2
  41 + with:
  42 + category: /language:${{ matrix.language }}