diff options
Diffstat (limited to '.github/workflows/codeql-analysis.yml')
-rw-r--r-- | .github/workflows/codeql-analysis.yml | 73 |
1 files changed, 73 insertions, 0 deletions
diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml new file mode 100644 index 00000000..0317c8c0 --- /dev/null +++ b/.github/workflows/codeql-analysis.yml | |||
@@ -0,0 +1,73 @@ | |||
1 | --- | ||
2 | # For most projects, this workflow file will not need changing; you simply need | ||
3 | # to commit it to your repository. | ||
4 | # | ||
5 | # You may wish to alter this file to override the set of languages analyzed, | ||
6 | # or to provide custom queries or build logic. | ||
7 | # | ||
8 | # ******** NOTE ******** | ||
9 | # We have attempted to detect the languages in your repository. Please check | ||
10 | # the `language` matrix defined below to confirm you have the correct set of | ||
11 | # supported CodeQL languages. | ||
12 | # | ||
13 | name: "CodeQL" | ||
14 | |||
15 | on: | ||
16 | push: | ||
17 | branches: [master] | ||
18 | pull_request: | ||
19 | # The branches below must be a subset of the branches above | ||
20 | branches: [master] | ||
21 | schedule: | ||
22 | - cron: '15 18 * * 0' | ||
23 | |||
24 | jobs: | ||
25 | analyze: | ||
26 | name: Analyze | ||
27 | runs-on: ubuntu-latest | ||
28 | permissions: | ||
29 | actions: read | ||
30 | contents: read | ||
31 | security-events: write | ||
32 | |||
33 | strategy: | ||
34 | fail-fast: false | ||
35 | matrix: | ||
36 | language: ['cpp'] | ||
37 | # CodeQL supports [ 'cpp', 'csharp', 'go', 'java', 'javascript', 'python' ] | ||
38 | # Learn more: | ||
39 | # https://docs.github.com/en/free-pro-team@latest/github/finding-security-vulnerabilities-and-errors-in-your-code/configuring-code-scanning#changing-the-languages-that-are-analyzed | ||
40 | |||
41 | steps: | ||
42 | - name: Checkout repository | ||
43 | uses: actions/checkout@v4 | ||
44 | |||
45 | # Initializes the CodeQL tools for scanning. | ||
46 | - name: Initialize CodeQL | ||
47 | uses: github/codeql-action/init@v2 | ||
48 | with: | ||
49 | languages: ${{ matrix.language }} | ||
50 | # If you wish to specify custom queries, you can do so here or in a config file. | ||
51 | # By default, queries listed here will override any specified in a config file. | ||
52 | # Prefix the list here with "+" to use these queries and those in the config file. | ||
53 | # queries: ./path/to/local/query, your-org/your-repo/queries@main | ||
54 | |||
55 | - name: Install packages | ||
56 | run: | | ||
57 | sudo apt update | ||
58 | sudo apt-get install -y --no-install-recommends m4 gettext automake autoconf make build-essential | ||
59 | sudo apt-get install -y --no-install-recommends perl autotools-dev libdbi-dev libldap2-dev libpq-dev \ | ||
60 | libmysqlclient-dev libradcli-dev libkrb5-dev libdbi0-dev \ | ||
61 | libdbd-sqlite3 libssl-dev libcurl4-openssl-dev liburiparser-dev | ||
62 | |||
63 | - name: Configure build | ||
64 | run: | | ||
65 | ./tools/setup | ||
66 | ./configure --enable-libtap | ||
67 | |||
68 | - name: Build | ||
69 | run: | | ||
70 | make | ||
71 | |||
72 | - name: Perform CodeQL Analysis | ||
73 | uses: github/codeql-action/analyze@v2 | ||