Added CodeQL. (#5)

This commit is contained in:
Keanu Timmermans 2020-08-20 16:35:35 +02:00 committed by GitHub
parent eed1438fb2
commit 4a6754d21e
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
2 changed files with 47 additions and 0 deletions

6
.github/codeql/codeql-config.yml vendored Normal file
View File

@ -0,0 +1,6 @@
name: "CodeQL Config"
queries:
- uses: security-and-quality
paths:
- dist

41
.github/workflows/codeql-analysis.yml vendored Normal file
View File

@ -0,0 +1,41 @@
name: "CodeQL"
on:
push:
branches: [typescript]
pull_request:
branches: [typescript]
schedule:
- cron: '0 5 * * 1'
jobs:
analyze:
name: Analyze
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v2
with:
fetch-depth: 2
- run: git checkout HEAD^2
if: ${{ github.event_name == 'pull_request' }}
- name: Setup Node.JS
uses: actions/setup-node@v2-beta
with:
node-version: '12'
- run: npm ci
- name: Build codebase
run: npm run build
- name: Initialize CodeQL
uses: github/codeql-action/init@v1
with:
config-file: ./.github/codeql/codeql-config.yml
languages: javascript
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v1