Skip to content
This repository was archived by the owner on Apr 7, 2024. It is now read-only.

Commit a84754e

Browse files
authored
build: add CodeQL workflow (#24)
Resolves: #12 Signed-off-by: Lixia (Sylvia) Lei <lixlei@microsoft.com>
1 parent 92ca6c0 commit a84754e

1 file changed

Lines changed: 50 additions & 0 deletions

File tree

.github/workflows/codeql.yml

Lines changed: 50 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,50 @@
1+
# Copyright The ORAS Authors.
2+
# Licensed under the Apache License, Version 2.0 (the "License");
3+
# you may not use this file except in compliance with the License.
4+
# You may obtain a copy of the License at
5+
#
6+
# http://www.apache.org/licenses/LICENSE-2.0
7+
#
8+
# Unless required by applicable law or agreed to in writing, software
9+
# distributed under the License is distributed on an "AS IS" BASIS,
10+
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
11+
# See the License for the specific language governing permissions and
12+
# limitations under the License.
13+
14+
name: "CodeQL"
15+
16+
on:
17+
push:
18+
branches: [ "main" ]
19+
pull_request:
20+
# The branches below must be a subset of the branches above
21+
branches: [ "main" ]
22+
schedule:
23+
- cron: '30 5 * * 6'
24+
25+
jobs:
26+
analyze:
27+
name: Analyze
28+
runs-on: ubuntu-latest
29+
permissions:
30+
actions: read
31+
contents: read
32+
security-events: write
33+
strategy:
34+
matrix:
35+
go-version: ['1.19', '1.20']
36+
fail-fast: false
37+
steps:
38+
- name: Checkout repository
39+
uses: actions/checkout@v3
40+
- name: Set up Go ${{ matrix.go-version }} environment
41+
uses: actions/setup-go@v4
42+
with:
43+
go-version: ${{ matrix.go-version }}
44+
check-latest: true
45+
- name: Initialize CodeQL
46+
uses: github/codeql-action/init@v2
47+
with:
48+
languages: go
49+
- name: Perform CodeQL Analysis
50+
uses: github/codeql-action/analyze@v2

0 commit comments

Comments
 (0)