Skip to content

CodeQL

CodeQL #137

Workflow file for this run

name: "CodeQL"
on:
workflow_dispatch: {}
workflow_call: {}
schedule:
- cron: "17 14 * * 3"
permissions:
contents: read
jobs:
analyze:
name: Scan
runs-on: ubuntu-latest
continue-on-error: true
permissions:
actions: read
contents: read
security-events: write
steps:
- name: Harden Runner
uses: step-security/harden-runner@17d0e2bd7d51742c71671bd19fa12bdc9d40a3d6 # v2.8.1
with:
egress-policy: audit
- name: Checkout repository
uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
- name: Initialize CodeQL
continue-on-error: true
uses: github/codeql-action/init@2e230e8fe0ad3a14a340ad0815ddb96d599d2aff # v3.25.8
with:
config-file: ./.github/codeql/codeql-config.yml
- name: "Gradle Build"
uses: gradle/gradle-build-action@8baac4c8ef753599f92eeb509c246d09d6250fa6 # v3.3.0
id: gradlebuild
continue-on-error: ${{ inputs.experimental }}
with:
cache-read-only: ${{ github.ref != 'refs/heads/main' && github.ref != 'refs/heads/master' && github.ref != 'refs/heads/beta' }}
gradle-version: wrapper
gradle-home-cache-cleanup: true
gradle-home-cache-excludes: |
caches/build-cache-1
caches/keyrings
arguments: |
assemble
-PVERSION=1.0-SNAPSHOT
--scan
--no-daemon
--warning-mode=none
--dependency-verification=lenient
-Pci=true
- name: Perform CodeQL Analysis
continue-on-error: true
uses: github/codeql-action/analyze@2e230e8fe0ad3a14a340ad0815ddb96d599d2aff # v3.25.8