--- # vi: ts=2 sw=2 et: # SPDX-License-Identifier: LGPL-2.1-or-later # name: "CodeQL" on: pull_request: branches: - main - v[0-9]+-stable paths: - '**/meson.build' - '.github/**/codeql*' - 'src/**' - 'test/**' - 'tools/**' push: branches: - main - v[0-9]+-stable permissions: contents: read jobs: analyze: name: Analyze if: github.repository != 'systemd/systemd-security' runs-on: ubuntu-22.04 concurrency: group: ${{ github.workflow }}-${{ matrix.language }}-${{ github.ref }} cancel-in-progress: true permissions: actions: read security-events: write strategy: fail-fast: false matrix: language: ['cpp', 'python'] steps: - name: Checkout repository uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 - name: Initialize CodeQL uses: github/codeql-action/init@00e563ead9f72a8461b24876bee2d0c2e8bd2ee8 with: languages: ${{ matrix.language }} config-file: ./.github/codeql-config.yml - run: sudo -E .github/workflows/unit_tests.sh SETUP - name: Autobuild uses: github/codeql-action/autobuild@00e563ead9f72a8461b24876bee2d0c2e8bd2ee8 - name: Perform CodeQL Analysis uses: github/codeql-action/analyze@00e563ead9f72a8461b24876bee2d0c2e8bd2ee8