Skip to content

Commit a57c5b3

Browse files
authored
Add actions scanning and go community pack in codeql-analysis.yml (#664)
Update codeql.yml
1 parent 3983286 commit a57c5b3

File tree

1 file changed

+7
-6
lines changed

1 file changed

+7
-6
lines changed

.github/workflows/codeql.yml

+7-6
Original file line numberDiff line numberDiff line change
@@ -20,20 +20,21 @@ jobs:
2020
strategy:
2121
fail-fast: false
2222
matrix:
23-
language: ["go"]
23+
language: ["go", "actions"]
2424

2525
steps:
2626
- name: Checkout repository
27-
uses: actions/checkout@d632683dd7b4114ad314bca15554477dd762a938 #v4.2.0
27+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 #v4.2.2
2828

29-
# Initializes the CodeQL tools for scanning.
3029
- name: Initialize CodeQL
31-
uses: github/codeql-action/init@5618c9fc1e675841ca52c1c6b1304f5255a905a0 #v2.19.0
30+
uses: github/codeql-action/init@7e3036b9cd87fc26dd06747b7aa4b96c27aaef3a #v2.20.3
3231
with:
3332
languages: ${{ matrix.language }}
33+
queries: security-and-quality
34+
packs: githubsecuritylab/codeql-go-queries
3435

3536
- name: Autobuild
36-
uses: github/codeql-action/autobuild@5618c9fc1e675841ca52c1c6b1304f5255a905a0 #v2.19.0
37+
uses: github/codeql-action/autobuild@7e3036b9cd87fc26dd06747b7aa4b96c27aaef3a #v2.20.3
3738

3839
- name: Perform CodeQL Analysis
39-
uses: github/codeql-action/analyze@5618c9fc1e675841ca52c1c6b1304f5255a905a0 #v2.19.0
40+
uses: github/codeql-action/analyze@7e3036b9cd87fc26dd06747b7aa4b96c27aaef3a #v2.20.3

0 commit comments

Comments
 (0)