diff options
| author | Eli Schwartz <eschwartz@archlinux.org> | 2022-11-25 01:05:56 -0500 |
|---|---|---|
| committer | Dylan Baker <dylan@pnwbakers.com> | 2022-11-28 12:02:17 -0800 |
| commit | 5022fd30e1a922ad7f2dfc81648d3c73c5f2aa22 (patch) | |
| tree | 7384ceb5a7a07fd76eb91963d3005255fc7f04a9 /.github/workflows | |
| parent | 81d7c24a59bf4a991fe57579aa11a32b32779680 (diff) | |
| download | meson-5022fd30e1a922ad7f2dfc81648d3c73c5f2aa22.tar.gz | |
Add github's CodeQL scanner to CI.
lgtm.com was acquired by github. It is deprecated and on its way out,
because they've integrated the functionality itself into github. Take a
look at what its official replacement can do.
This does run as yet another Actions slot, which is already fairly
excessive, but the average runtime seems about 5 minutes so that's not
too bad...
Diffstat (limited to '.github/workflows')
| -rw-r--r-- | .github/workflows/codeql-analysis.yml | 31 |
1 files changed, 31 insertions, 0 deletions
diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml new file mode 100644 index 000000000..c152647ae --- /dev/null +++ b/.github/workflows/codeql-analysis.yml @@ -0,0 +1,31 @@ +name: "CodeQL" + +on: + push: + branches: [ "master" ] + pull_request: + branches: [ "master" ] + +jobs: + analyze: + # lgtm.com does not run in forks, for good reason + if: github.repository == 'mesonbuild/meson' + name: Analyze + runs-on: ubuntu-latest + permissions: + security-events: write + + steps: + - name: Checkout repository + uses: actions/checkout@v3 + + - name: Initialize CodeQL + uses: github/codeql-action/init@v2 + with: + config-file: .github/codeql/codeql-config.yml + languages: python + # we have none + setup-python-dependencies: false + + - name: Perform CodeQL Analysis + uses: github/codeql-action/analyze@v2 |
