--- # vi: ts=2 sw=2 et: # SPDX-License-Identifier: LGPL-2.1-or-later # name: "CodeQL" on: pull_request: branches: - main - v[0-9]+-stable paths: - '**/meson.build' - '.github/**/codeql*' - 'src/**' - 'test/**' - 'tools/**' push: branches: - main - v[0-9]+-stable permissions: contents: read jobs: analyze: name: Analyze if: github.repository != 'systemd/systemd-security' runs-on: ubuntu-22.04 concurrency: group: ${{ github.workflow }}-${{ matrix.language }}-${{ github.ref }} cancel-in-progress: true permissions: actions: read security-events: write strategy: fail-fast: false matrix: language: ['cpp', 'python'] steps: - name: Checkout repository uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 - name: Initialize CodeQL uses: github/codeql-action/init@407ffafae6a767df3e0230c3df91b6443ae8df75 with: languages: ${{ matrix.language }} config-file: ./.github/codeql-config.yml - run: sudo -E .github/workflows/unit_tests.sh SETUP - name: Autobuild uses: github/codeql-action/autobuild@407ffafae6a767df3e0230c3df91b6443ae8df75 - name: Perform CodeQL Analysis uses: github/codeql-action/analyze@407ffafae6a767df3e0230c3df91b6443ae8df75